<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" href="http://vigilance.fr/rss/2/2"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/">
  <channel rdf:about="https://vigilance.fr/?action=76923369&amp;langue=2">
    <title>Vigil@nce - public vulnerabilities</title>
    <link>http://vigilance.fr/?langue=2</link>
    <description>This RSS feed tracks public vulnerabilities of Vigil@nce. These information are published with a time delay. Our subscribers can read our bulletins without this time delay.</description>
    <dc:language>en-US</dc:language>
    <dc:publisher>Vigil@nce</dc:publisher>
    <dc:creator>Orange Business Services Vigil@nce</dc:creator>
    <dc:rights>Copyright 1999-2012 Orange Business Services Vigil@nce</dc:rights>
    <dc:date>2012-05-18T06:22:00Z</dc:date>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>2000-01-01T00:00:00Z</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li resource="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/XnView-multiple-vulnerabilities-11376"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/PHP-two-vulnerabilities-11572"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/libvorbis-memory-corruption-11375"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Samba-changing-the-owner-of-files-via-RPC-LSA-11571"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Citrix-XenServer-Web-Self-Service-multiple-vulnerabilities-11373"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/libpng-buffer-overflow-via-png-decompress-chunk-11371"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Adobe-Shockwave-Player-several-vulnerabilities-11369"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Microsoft-NET-Silverlight-code-execution-11367"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Microsoft-Visio-Viewer-2010-code-execution-11366"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Unified-MeetingPlace-detecting-if-a-directory-exists-11615"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Net-SNMP-denial-of-service-via-extend-11570"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Oracle-Database-data-capture-via-TNS-Listener-Registration-11569"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Python-incorrect-decoding-of-UTF-16-11568"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Unified-IP-Phones-changing-the-configuration-11590"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Asterisk-three-vulnerabilities-11565"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Clearswift-Email-Web-Gateway-denial-of-service-via-iWork-11347"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/XnView-buffer-overflow-via-JPEG2000-11346"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/SPIP-six-vulnerabilities-11563"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/JasPer-buffer-overflow-via-Quantization-11345"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-ASA-denial-of-service-via-ESMTP-11575"/>
      </rdf:Seq>
    </items>
  </channel>
  <item rdf:about="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management">
    <title>Vigil@nce - Software vulnerabilities patches</title>
    <link>http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management</link>
    <description>Each administrator can customize the list of products for which he wants to receive vulnerability alerts.</description>
    <dc:type>0</dc:type>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-17T12:00:00Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/XnView-multiple-vulnerabilities-11376">
    <title>Vigil@nce - XnView: multiple vulnerabilities, analyzed on 17/02/2012</title>
    <link>http://vigilance.fr/vulnerability/XnView-multiple-vulnerabilities-11376</link>
    <description>An attacker can invite the victim to open a malicious image with XnView, in order to stop it or to execute code.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11376</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-17T09:25:31Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/PHP-two-vulnerabilities-11572">
    <title>Vigil@nce - PHP: two vulnerabilities, analyzed on 02/05/2012</title>
    <link>http://vigilance.fr/vulnerability/PHP-two-vulnerabilities-11572</link>
    <description>An attacker can use two vulnerabilities of PHP, in order to read or create files.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11572</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-17T08:30:55Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/libvorbis-memory-corruption-11375">
    <title>Vigil@nce - libvorbis: memory corruption, analyzed on 17/02/2012</title>
    <link>http://vigilance.fr/vulnerability/libvorbis-memory-corruption-11375</link>
    <description>An attacker can invite the victim to open a malicious Ogg Vorbis document with an application linked to libvorbis, in order to corrupt the memory, which stops the application, or leads to code execution.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11375</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-17T08:00:39Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Samba-changing-the-owner-of-files-via-RPC-LSA-11571">
    <title>Vigil@nce - Samba: changing the owner of files via RPC LSA, analyzed on 02/05/2012</title>
    <link>http://vigilance.fr/vulnerability/Samba-changing-the-owner-of-files-via-RPC-LSA-11571</link>
    <description>An authenticated user can take ownership of files of other users, which are provided via Samba.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11571</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-17T07:19:16Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Citrix-XenServer-Web-Self-Service-multiple-vulnerabilities-11373">
    <title>Vigil@nce - Citrix XenServer Web Self Service: multiple vulnerabilities, analyzed on 16/02/2012</title>
    <link>http://vigilance.fr/vulnerability/Citrix-XenServer-Web-Self-Service-multiple-vulnerabilities-11373</link>
    <description>An attacker can use several vulnerabilities of the Web Self Service component of Citrix XenServer.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11373</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-16T09:35:05Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/libpng-buffer-overflow-via-png-decompress-chunk-11371">
    <title>Vigil@nce - libpng: buffer overflow via png_decompress_chunk, analyzed on 16/02/2012</title>
    <link>http://vigilance.fr/vulnerability/libpng-buffer-overflow-via-png-decompress-chunk-11371</link>
    <description>An attacker can invite the victim to open a malicious PNG image with an application linked to libpng, in order to create an overflow, which stops the application, or leads to code execution.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11371</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-16T08:46:05Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Adobe-Shockwave-Player-several-vulnerabilities-11369">
    <title>Vigil@nce - Adobe Shockwave Player: several vulnerabilities, analyzed on 15/02/2012</title>
    <link>http://vigilance.fr/vulnerability/Adobe-Shockwave-Player-several-vulnerabilities-11369</link>
    <description>Several Adobe Shockwave Player vulnerabilities can be used by an attacker to execute code or to create a denial of service.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11369</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-15T07:15:02Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Microsoft-NET-Silverlight-code-execution-11367">
    <title>Vigil@nce - Microsoft .NET, Silverlight: code execution, analyzed on 15/02/2012</title>
    <link>http://vigilance.fr/vulnerability/Microsoft-NET-Silverlight-code-execution-11367</link>
    <description>An attacker can invite the victim to display a malicious site or to install a malicious ASP.NET application, in order to execute code on his computer.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11367</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-15T05:27:47Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Microsoft-Visio-Viewer-2010-code-execution-11366">
    <title>Vigil@nce - Microsoft Visio Viewer 2010: code execution, analyzed on 15/02/2012</title>
    <link>http://vigilance.fr/vulnerability/Microsoft-Visio-Viewer-2010-code-execution-11366</link>
    <description>An attacker can invite the victim to open a malicious document with Microsoft Visio Viewer 2010, in order to execute code on his computer.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11366</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-15T05:20:56Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Unified-MeetingPlace-detecting-if-a-directory-exists-11615">
    <title>Vigil@nce - Cisco Unified MeetingPlace: detecting if a directory exists, analyzed on 10/05/2012</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Unified-MeetingPlace-detecting-if-a-directory-exists-11615</link>
    <description>An attacker can use a vulnerability of Cisco Unified MeetingPlace, in order to detect if a directory exists.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-11615</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-13T13:05:17Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Net-SNMP-denial-of-service-via-extend-11570">
    <title>Vigil@nce - Net-SNMP: denial of service via extend, analyzed on 26/04/2012</title>
    <link>http://vigilance.fr/vulnerability/Net-SNMP-denial-of-service-via-extend-11570</link>
    <description>When Net-SNMP is configured with extends, an attacker can use an invalid OID, in order to stop the service.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11570</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-11T11:45:20Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Oracle-Database-data-capture-via-TNS-Listener-Registration-11569">
    <title>Vigil@nce - Oracle Database: data capture via TNS Listener Registration, analyzed on 26/04/2012</title>
    <link>http://vigilance.fr/vulnerability/Oracle-Database-data-capture-via-TNS-Listener-Registration-11569</link>
    <description>An attacker can register a malicious database instance from the TNS Listener, in order to capture exchanges between clients and the legitimate database.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11569</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-11T09:04:52Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Python-incorrect-decoding-of-UTF-16-11568">
    <title>Vigil@nce - Python: incorrect decoding of UTF-16, analyzed on 25/04/2012</title>
    <link>http://vigilance.fr/vulnerability/Python-incorrect-decoding-of-UTF-16-11568</link>
    <description>When a Python application decodes UTF-16 data containing errors, a desynchronization occurs, which leads to a memory read or corruption.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11568</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-10T13:20:41Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Unified-IP-Phones-changing-the-configuration-11590">
    <title>Vigil@nce - Cisco Unified IP Phones: changing the configuration, analyzed on 07/05/2012</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Unified-IP-Phones-changing-the-configuration-11590</link>
    <description>When a Cisco Unified IP Phone downloads its configuration, a local attacker can force it to download a malicious configuration.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-11590</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-10T12:21:37Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Asterisk-three-vulnerabilities-11565">
    <title>Vigil@nce - Asterisk: three vulnerabilities, analyzed on 24/04/2012</title>
    <link>http://vigilance.fr/vulnerability/Asterisk-three-vulnerabilities-11565</link>
    <description>An attacker can use three vulnerabilities of Asterisk, in order to create a denial of service or to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11565</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-09T12:08:22Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Clearswift-Email-Web-Gateway-denial-of-service-via-iWork-11347">
    <title>Vigil@nce - Clearswift Email, Web Gateway: denial of service via iWork, analyzed on 08/02/2012</title>
    <link>http://vigilance.fr/vulnerability/Clearswift-Email-Web-Gateway-denial-of-service-via-iWork-11347</link>
    <description>An attacker can use an iWork document containing an empty Zip64 header, in order to create an infinite loop in Clearswift products.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11347</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-08T12:56:05Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/XnView-buffer-overflow-via-JPEG2000-11346">
    <title>Vigil@nce - XnView: buffer overflow via JPEG2000, analyzed on 08/02/2012</title>
    <link>http://vigilance.fr/vulnerability/XnView-buffer-overflow-via-JPEG2000-11346</link>
    <description>An attacker can invite the victim to open a malicious JPEG2000 image with XnView, in order to stop it or to execute code.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11346</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-08T08:44:55Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/SPIP-six-vulnerabilities-11563">
    <title>Vigil@nce - SPIP: six vulnerabilities, analyzed on 23/04/2012</title>
    <link>http://vigilance.fr/vulnerability/SPIP-six-vulnerabilities-11563</link>
    <description>An attacker can use six vulnerabilities of SPIP, in order to elevate his privileges, to obtain information, or to create a Cross Site Scripting.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-11563</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-08T08:44:14Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/JasPer-buffer-overflow-via-Quantization-11345">
    <title>Vigil@nce - JasPer: buffer overflow via Quantization, analyzed on 08/02/2012</title>
    <link>http://vigilance.fr/vulnerability/JasPer-buffer-overflow-via-Quantization-11345</link>
    <description>An attacker can create a JPEG 2000 image, and invite the victim to open it with an application linked to JasPer, in order to create a buffer overflow, which leads to a denial of service or to code execution.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-11345</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-08T08:25:19Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-ASA-denial-of-service-via-ESMTP-11575">
    <title>Vigil@nce - Cisco ASA: denial of service via ESMTP, analyzed on 03/05/2012</title>
    <link>http://vigilance.fr/vulnerability/Cisco-ASA-denial-of-service-via-ESMTP-11575</link>
    <description>An attacker can use a special sequence of ESMTP commands, during the session closure, which overloads Cisco ASA.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-11575</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2012-05-06T09:31:16Z</dc:date>
  </item>
</rdf:RDF>

