<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" href="http://vigilance.fr/rss/2/2"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/">
  <channel rdf:about="https://vigilance.fr/?action=76923369&amp;langue=2">
    <title>Vigil@nce - public vulnerabilities</title>
    <link>http://vigilance.fr/?langue=2</link>
    <description>This RSS feed tracks public vulnerabilities of Vigil@nce.</description>
    <dc:language>en-US</dc:language>
    <dc:publisher>Vigil@nce</dc:publisher>
    <dc:creator>Orange Business Services Vigil@nce</dc:creator>
    <dc:rights>Copyright 1999-2010 Orange Business Services Vigil@nce</dc:rights>
    <dc:date>2010-03-10T19:42:57Z</dc:date>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>2000-01-01T00:00:00Z</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-denials-of-service-9491"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Apache-httpd-information-disclosure-via-SubRequest-9490"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-NFS-9489"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/libpng-denial-of-service-during-the-decompression-9488"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Apache-httpd-denials-of-service-of-of-modules-9487"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Lotus-Domino-Cross-Site-Scripting-of-help-9486"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Opera-two-vulnerabilities-9484"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/TYPO3-SQL-injection-in-Calendar-Base-9483"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/ncpfs-two-vulnerabilities-9502"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Lotus-iNotes-2-vulnerabilities-9482"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/PHP-several-vulnerabilities-9478"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/PowerDNS-Recursor-two-vulnerabilities-9326"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-hvc-console-9498"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Asterisk-bypassing-ACLs-9476"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/GNU-M4-file-modification-via-dist-and-distcheck-9475"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Adobe-Flash-Reader-software-installation-9474"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-executable-page-on-Sparc-9472"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Avast-privilege-elevation-via-aavmker4-sys-9470"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/sudo-group-elevation-9469"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-DVB-9481"/>
      </rdf:Seq>
    </items>
  </channel>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-denials-of-service-9491">
    <title>Cisco Unified Communications Manager: denials of service</title>
    <link>http://vigilance.fr/vulnerability/Cisco-Unified-Communications-Manager-denials-of-service-9491</link>
    <description>An attacker can use SCCP, SIP or CIT messages, in order to generate denials of service on Cisco Unified Communications Manager.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9491</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-10T16:04:33Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Apache-httpd-information-disclosure-via-SubRequest-9490">
    <title>Apache httpd: information disclosure via SubRequest</title>
    <link>http://vigilance.fr/vulnerability/Apache-httpd-information-disclosure-via-SubRequest-9490</link>
    <description>When Apache httpd uses a SubRequest and a multi-threaded MPM, session data can be returned to another user.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9490</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-10T15:19:04Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-NFS-9489">
    <title>Linux kernel: denial of service via NFS</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-NFS-9489</link>
    <description>An attacker can truncate a NFS file, in order to stop the kernel, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9489</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-10T13:05:13Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/libpng-denial-of-service-during-the-decompression-9488">
    <title>libpng: denial of service during the decompression</title>
    <link>http://vigilance.fr/vulnerability/libpng-denial-of-service-during-the-decompression-9488</link>
    <description>An attacker can create an extremely compressed image, and invite the victim to open it with libpng, in order to generate a denial of service on his computer.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9488</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-10T08:59:53Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Apache-httpd-denials-of-service-of-of-modules-9487">
    <title>Apache httpd: denials of service of of modules</title>
    <link>http://vigilance.fr/vulnerability/Apache-httpd-denials-of-service-of-of-modules-9487</link>
    <description>An attacker can generate a denial of service in mod_proxy_ajp and mod_isapi modules of Apache httpd.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9487</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-10T08:16:15Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Lotus-Domino-Cross-Site-Scripting-of-help-9486">
    <title>Lotus Domino: Cross Site Scripting of help</title>
    <link>http://vigilance.fr/vulnerability/Lotus-Domino-Cross-Site-Scripting-of-help-9486</link>
    <description>An attacker can invite the victim to display a malicious url, in order to execute JavaScript code in the context of the Lotus Domino server.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9486</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-09T14:54:25Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Opera-two-vulnerabilities-9484">
    <title>Opera: two vulnerabilities</title>
    <link>http://vigilance.fr/vulnerability/Opera-two-vulnerabilities-9484</link>
    <description>Two vulnerabilities were announced in Opera. The first one can be used to inject data in a TLS session.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9484</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-09T12:44:48Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/TYPO3-SQL-injection-in-Calendar-Base-9483">
    <title>TYPO3: SQL injection in Calendar Base</title>
    <link>http://vigilance.fr/vulnerability/TYPO3-SQL-injection-in-Calendar-Base-9483</link>
    <description>An attacker can inject SQL queries in the Calendar Base extension of TYPO3.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9483</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-09T12:08:21Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/ncpfs-two-vulnerabilities-9502">
    <title>ncpfs: two vulnerabilities</title>
    <link>http://vigilance.fr/vulnerability/ncpfs-two-vulnerabilities-9502</link>
    <description>A local attacker can use two vulnerabilities of ncpfs, in order to obtain information or to create a denial of service.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-9502</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-09T09:08:24Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Lotus-iNotes-2-vulnerabilities-9482">
    <title>Lotus iNotes: 2 vulnerabilities</title>
    <link>http://vigilance.fr/vulnerability/Lotus-iNotes-2-vulnerabilities-9482</link>
    <description>Two vulnerabilities were announced in Lotus iNotes (DWA, Domino Web Access).</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9482</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-08T16:45:12Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/PHP-several-vulnerabilities-9478">
    <title>PHP: several vulnerabilities</title>
    <link>http://vigilance.fr/vulnerability/PHP-several-vulnerabilities-9478</link>
    <description>An attacker can use several vulnerabilities of PHP in order to bypass file access restrictions.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9478</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-08T10:26:27Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/PowerDNS-Recursor-two-vulnerabilities-9326">
    <title>PowerDNS Recursor: two vulnerabilities</title>
    <link>http://vigilance.fr/vulnerability/PowerDNS-Recursor-two-vulnerabilities-9326</link>
    <description>An attacker can generate a buffer overflow or change records of PowerDNS Recursor.</description>
    <dc:type>3</dc:type>
    <dc:identifier>VIGILANCE-VUL-9326</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-07T10:51:36Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-hvc-console-9498">
    <title>Linux kernel: denial of service via hvc_console</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-hvc-console-9498</link>
    <description>A local attacker can use virtio_console, in order to generate a denial of service in hvc_console.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-9498</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-06T09:45:40Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Asterisk-bypassing-ACLs-9476">
    <title>Asterisk: bypassing ACLs</title>
    <link>http://vigilance.fr/vulnerability/Asterisk-bypassing-ACLs-9476</link>
    <description>An attacker, who is normally blocked by ACLs, can send SIP INVITE messages to Asterisk.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9476</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-05T10:01:46Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/GNU-M4-file-modification-via-dist-and-distcheck-9475">
    <title>GNU M4: file modification via dist and distcheck</title>
    <link>http://vigilance.fr/vulnerability/GNU-M4-file-modification-via-dist-and-distcheck-9475</link>
    <description>When the dist and distcheck targets of GNU M4 are used, a local attacker can alter a file.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9475</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-04T14:46:07Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Adobe-Flash-Reader-software-installation-9474">
    <title>Adobe Flash, Reader: software installation</title>
    <link>http://vigilance.fr/vulnerability/Adobe-Flash-Reader-software-installation-9474</link>
    <description>The Adobe Download Manager product can be used to install an unwanted software.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9474</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-03T14:00:58Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-executable-page-on-Sparc-9472">
    <title>Linux kernel: executable page on Sparc</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-executable-page-on-Sparc-9472</link>
    <description>On a Sparc processor, memory pages tagged as non executable are actually executable.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9472</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-03T10:01:00Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Avast-privilege-elevation-via-aavmker4-sys-9470">
    <title>Avast: privilege elevation via aavmker4.sys</title>
    <link>http://vigilance.fr/vulnerability/Avast-privilege-elevation-via-aavmker4-sys-9470</link>
    <description>A local attacker can corrupt the memory of the aavmker4.sys driver, in order to generate a denial of service or to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9470</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-02T17:39:04Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/sudo-group-elevation-9469">
    <title>sudo: group elevation</title>
    <link>http://vigilance.fr/vulnerability/sudo-group-elevation-9469</link>
    <description>When the /etc/sudoers file contains "runas_default", a local attacker can execute a command with privileges of root's groups.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-9469</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-02T17:14:49Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-DVB-9481">
    <title>Linux kernel: denial of service via DVB</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-DVB-9481</link>
    <description>An attacker can send a malformed DVB/MPEG2-TS frame, in order to block the system.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-9481</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2010-03-02T15:57:20Z</dc:date>
  </item>
</rdf:RDF>
