<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" href="http://vigilance.fr/rss/2/2"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/">
  <channel rdf:about="https://vigilance.fr/?action=76923369&amp;langue=2">
    <title>Vigil@nce - public vulnerabilities</title>
    <link>http://vigilance.fr/?langue=2</link>
    <description>This RSS feed tracks public vulnerabilities of Vigil@nce. These information are published with a time delay. Our subscribers can read our bulletins without this time delay.</description>
    <dc:language>en-US</dc:language>
    <dc:publisher>Vigil@nce</dc:publisher>
    <dc:creator>Orange Business Services Vigil@nce</dc:creator>
    <dc:rights>Copyright 1999-2013 Orange Business Services Vigil@nce</dc:rights>
    <dc:date>2013-05-24T03:01:01Z</dc:date>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>2000-01-01T00:00:00Z</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li resource="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/VMware-ESX-ESXi-vCenter-memory-corruption-via-NFC-12448"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-Live-Comment-Preview-12765"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Login-With-Ajax-12764"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Calendar-12763"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-WP-Photo-Album-Plus-12761"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/QEMU-Guest-Agent-privilege-escalation-via-permissions-12759"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/IBM-Eclipse-Help-System-source-code-reading-via-iehs-war-12758"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-file-reading-via-CLI-12757"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/EMC-VNX-Celerra-Control-Station-privilege-escalation-via-nasadmin-12841"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/RSA-SecurID-obsolete-algorithm-12840"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/EMC-Avamar-Client-incorrect-validation-of-certificate-12753"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/EMC-Avamar-file-reading-via-File-Restore-12752"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/EMC-NetWorker-privilege-escalation-via-nsrpush-12751"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/WordPress-information-disclosure-via-Advanced-XML-Reader-12750"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Xen-denial-of-service-via-VT-d-MSI-12749"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-IOS-XR-denial-of-service-via-SNMP-12748"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Prime-Central-for-Hosted-Collaboration-Solution-multiple-vulnerabilities-12746"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Prime-Secure-ACS-privilege-escalation-12745"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2p-write-pdf-page-12744"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2-process-jpeg-strip-12743"/>
      </rdf:Seq>
    </items>
  </channel>
  <item rdf:about="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management">
    <title>Vigil@nce - Applications vulnerabilities patches</title>
    <link>http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management</link>
    <description>The Vigil@nce vulnerability database contains several thousand vulnerabilities.</description>
    <dc:type>0</dc:type>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-23T12:00:00Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/VMware-ESX-ESXi-vCenter-memory-corruption-via-NFC-12448">
    <title>Vigil@nce - VMware ESX, ESXi, vCenter: memory corruption via NFC, analyzed on 22/02/2013</title>
    <link>http://vigilance.fr/vulnerability/VMware-ESX-ESXi-vCenter-memory-corruption-via-NFC-12448</link>
    <description>An attacker can alter NFC data between the client and VMware ESX/ESXi/vCenter, in order to corrupt the memory, which can lead to code execution.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-12448</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T11:09:37Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-Live-Comment-Preview-12765">
    <title>Vigil@nce - WordPress: Cross Site Scripting of Live Comment Preview, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-Live-Comment-Preview-12765</link>
    <description>An attacker can trigger a Cross Site Scripting in Live Comment Preview of WordPress, in order to execute JavaScript code in the context of the web site.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12765</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T08:42:21Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Login-With-Ajax-12764">
    <title>Vigil@nce - WordPress: Cross Site Request Forgery of Login With Ajax, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Login-With-Ajax-12764</link>
    <description>An attacker can trigger a Cross Site Request Forgery in Login With Ajax of WordPress, in order to force the victim to perform operations.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12764</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T08:36:13Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Calendar-12763">
    <title>Vigil@nce - WordPress: Cross Site Request Forgery of Calendar, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/WordPress-Cross-Site-Request-Forgery-of-Calendar-12763</link>
    <description>An attacker can trigger a Cross Site Request Forgery in Calendar of WordPress, in order to force the victim to perform operations.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12763</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T08:28:56Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-WP-Photo-Album-Plus-12761">
    <title>Vigil@nce - WordPress: Cross Site Scripting of WP Photo Album Plus, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/WordPress-Cross-Site-Scripting-of-WP-Photo-Album-Plus-12761</link>
    <description>An attacker can trigger a Cross Site Scripting in WP Photo Album Plus of WordPress, in order to execute JavaScript code in the context of the web site.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12761</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T08:03:49Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/QEMU-Guest-Agent-privilege-escalation-via-permissions-12759">
    <title>Vigil@nce - QEMU Guest Agent: privilege escalation via permissions, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/QEMU-Guest-Agent-privilege-escalation-via-permissions-12759</link>
    <description>An attacker, who is located in a guest system, can alter a file of the QEMU Guest Agent, in order to escalate his privileges in his guest system.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12759</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-22T06:44:45Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/IBM-Eclipse-Help-System-source-code-reading-via-iehs-war-12758">
    <title>Vigil@nce - IBM Eclipse Help System: source code reading via iehs.war, analyzed on 06/05/2013</title>
    <link>http://vigilance.fr/vulnerability/IBM-Eclipse-Help-System-source-code-reading-via-iehs-war-12758</link>
    <description>An attacker can use iehs.war, which is used in several IBM products, in order to read the source code of web pages.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12758</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-21T09:30:53Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-file-reading-via-CLI-12757">
    <title>Vigil@nce - Cisco Unified Communications Manager: file reading via CLI, analyzed on 06/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-file-reading-via-CLI-12757</link>
    <description>An attacker, who is authenticated on the Cisco Unified Communications Manager CLI, can read any file on the system.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12757</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-21T08:13:10Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/EMC-VNX-Celerra-Control-Station-privilege-escalation-via-nasadmin-12841">
    <title>Vigil@nce - EMC VNX/Celerra Control Station: privilege escalation via nasadmin, analyzed on 16/05/2013</title>
    <link>http://vigilance.fr/vulnerability/EMC-VNX-Celerra-Control-Station-privilege-escalation-via-nasadmin-12841</link>
    <description>An attacker, who is member of the nasadmin group, can alter scripts of EMC VNX/Celerra Control Station, in order to escalate his privileges.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12841</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-19T17:50:22Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/RSA-SecurID-obsolete-algorithm-12840">
    <title>Vigil@nce - RSA SecurID: obsolete algorithm, analyzed on 16/05/2013</title>
    <link>http://vigilance.fr/vulnerability/RSA-SecurID-obsolete-algorithm-12840</link>
    <description>Several products related to RSA SecurID use an obsolete encryption algorithm, and a short key size.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12840</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-19T17:39:52Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/EMC-Avamar-Client-incorrect-validation-of-certificate-12753">
    <title>Vigil@nce - EMC Avamar Client: incorrect validation of certificate, analyzed on 03/05/2013</title>
    <link>http://vigilance.fr/vulnerability/EMC-Avamar-Client-incorrect-validation-of-certificate-12753</link>
    <description>When a certificate authentication is configured, an attacker can create a malicious EMC Avamar server, in order to deceive the client.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12753</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-18T12:58:35Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/EMC-Avamar-file-reading-via-File-Restore-12752">
    <title>Vigil@nce - EMC Avamar: file reading via File Restore, analyzed on 03/05/2013</title>
    <link>http://vigilance.fr/vulnerability/EMC-Avamar-file-reading-via-File-Restore-12752</link>
    <description>An attacker can manipulate the url of the file restore web interface of EMC Avamar, in order to read a file.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12752</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-18T12:47:57Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/EMC-NetWorker-privilege-escalation-via-nsrpush-12751">
    <title>Vigil@nce - EMC NetWorker: privilege escalation via nsrpush, analyzed on 03/05/2013</title>
    <link>http://vigilance.fr/vulnerability/EMC-NetWorker-privilege-escalation-via-nsrpush-12751</link>
    <description>A local attacker can use an unprotected file of nsrpush of EMC NetWorker, in order to escalate his privileges.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12751</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-18T09:25:30Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/WordPress-information-disclosure-via-Advanced-XML-Reader-12750">
    <title>Vigil@nce - WordPress: information disclosure via Advanced XML Reader, analyzed on 03/05/2013</title>
    <link>http://vigilance.fr/vulnerability/WordPress-information-disclosure-via-Advanced-XML-Reader-12750</link>
    <description>An attacker can use an external XML entity in Advanced XML Reader of WordPress, in order to obtain sensitive information.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12750</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-18T08:07:26Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Xen-denial-of-service-via-VT-d-MSI-12749">
    <title>Vigil@nce - Xen: denial of service via VT-d MSI, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Xen-denial-of-service-via-VT-d-MSI-12749</link>
    <description>An attacker, who is located in a guest system, can remap interruptions of a device, in order to trigger a denial of service.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12749</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T15:23:48Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-IOS-XR-denial-of-service-via-SNMP-12748">
    <title>Vigil@nce - Cisco IOS XR: denial of service via SNMP, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Cisco-IOS-XR-denial-of-service-via-SNMP-12748</link>
    <description>An attacker can send malformed SNMP packets to Cisco IOS XR, in order to trigger a denial of service.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12748</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T15:16:58Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Prime-Central-for-Hosted-Collaboration-Solution-multiple-vulnerabilities-12746">
    <title>Vigil@nce - Cisco Prime Central for Hosted Collaboration Solution: multiple vulnerabilities, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Prime-Central-for-Hosted-Collaboration-Solution-multiple-vulnerabilities-12746</link>
    <description>An attacker can use several vulnerabilities of Cisco Prime Central for Hosted Collaboration Solution.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12746</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T13:14:20Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Prime-Secure-ACS-privilege-escalation-12745">
    <title>Vigil@nce - Cisco Prime, Secure ACS: privilege escalation, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Prime-Secure-ACS-privilege-escalation-12745</link>
    <description>An attacker can format special commands for Cisco Prime and Secure ACS, in order to escalate his privileges.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12745</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T12:38:23Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2p-write-pdf-page-12744">
    <title>Vigil@nce - libtiff: buffer overflow of tiff2pdf t2p_write_pdf_page, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2p-write-pdf-page-12744</link>
    <description>An attacker can invite the victim to open a malicious TIFF image with tiff2pdf, in order to create a denial of service or to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12744</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T12:14:12Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2-process-jpeg-strip-12743">
    <title>Vigil@nce - libtiff: buffer overflow of tiff2pdf t2_process_jpeg_strip, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/libtiff-buffer-overflow-of-tiff2pdf-t2-process-jpeg-strip-12743</link>
    <description>An attacker can invite the victim to open a malicious TIFF image with tiff2pdf, in order to create a denial of service or to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12743</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T11:56:50Z</dc:date>
  </item>
</rdf:RDF>
