<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" href="http://vigilance.fr/rss/2/2"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/">
  <channel rdf:about="https://vigilance.fr/?action=76923369&amp;langue=2">
    <title>Vigil@nce - public vulnerabilities explained by our team</title>
    <link>http://vigilance.fr/?langue=2</link>
    <description>This RSS feed tracks public vulnerabilities detailed by Vigil@nce. These information are published with a time delay. Our subscribers can read our bulletins without this time delay.</description>
    <dc:language>en-US</dc:language>
    <dc:publisher>Vigil@nce</dc:publisher>
    <dc:creator>Orange Business Services Vigil@nce</dc:creator>
    <dc:rights>Copyright 1999-2013 Orange Business Services Vigil@nce</dc:rights>
    <dc:date>2013-05-21T08:57:50Z</dc:date>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>2000-01-01T00:00:00Z</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li resource="http://vigilance.fr/vulnerability/Nagios-file-corruption-via-nagios-upgrade-to-v3-sh-12741"/>
        <rdf:li resource="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/KDE-password-displayed-in-KIO-Slave-HTTP-error-messages-12770"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/LibreOffice-Cacl-links-followed-without-Control-12769"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-use-after-free-via-veth-12728"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-scm-set-cred-12727"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-uid-map-12726"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EXT4-ORPHAN-FS-12719"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Internet-Explorer-file-detection-via-XMLDOM-12762"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Cisco-ASA-enumeration-of-VPN-groups-12691"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/MIT-krb5-denial-of-service-via-TGS-12685"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Xen-file-reading-via-qemu-nbd-12676"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/cURL-obtaining-Cookies-12664"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-buffer-overflow-of-tg3-VPD-12662"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/X-Org-Server-character-injection-via-VT-Switch-12686"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Xen-memory-corruption-of-XSM-12608"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/NVIDIA-UNIX-GPU-Driver-buffer-overflow-of-NoScanout-12603"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-FUNCTION-TRACER-12674"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/glibc-buffer-overflow-of-getaddrinfo-12599"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Asterisk-denial-of-service-via-Content-Length-12588"/>
        <rdf:li resource="http://vigilance.fr/vulnerability/Linux-kernel-memory-reading-via-VIDEO-SET-SPU-PALETTE-12611"/>
      </rdf:Seq>
    </items>
  </channel>
  <item rdf:about="http://vigilance.fr/vulnerability/Nagios-file-corruption-via-nagios-upgrade-to-v3-sh-12741">
    <title>Vigil@nce - Nagios: file corruption via nagios.upgrade_to_v3.sh, analyzed on 02/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Nagios-file-corruption-via-nagios-upgrade-to-v3-sh-12741</link>
    <description>When the administrator runs the nagios.upgrade_to_v3.sh script, a local attacker can create a symbolic link, in order to corrupt a file with root privileges.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12741</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-17T09:18:28Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management">
    <title>Vigil@nce - Networks vulnerabilities database</title>
    <link>http://vigilance.fr/offer/Vulnerability-watch-database-alert-and-management</link>
    <description>The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system.</description>
    <dc:type>0</dc:type>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-16T12:00:00Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/KDE-password-displayed-in-KIO-Slave-HTTP-error-messages-12770">
    <title>Vigil@nce - KDE: password displayed in KIO Slave HTTP error messages, analyzed on 13/05/2013</title>
    <link>http://vigilance.fr/vulnerability/KDE-password-displayed-in-KIO-Slave-HTTP-error-messages-12770</link>
    <description>A local attacker can trigger a network error, so that KDE displays an error message containing the password used by the HTTP KIO Slave.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12770</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-16T06:49:31Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/LibreOffice-Cacl-links-followed-without-Control-12769">
    <title>Vigil@nce - LibreOffice Cacl: links followed without Control, analyzed on 13/05/2013</title>
    <link>http://vigilance.fr/vulnerability/LibreOffice-Cacl-links-followed-without-Control-12769</link>
    <description>When the user configured the security option "Ctrl-click required to follow hyperlinks", it is not honored in LibreOffice Calc, so an attacker can force the victim to browse a site.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12769</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-16T06:27:34Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-use-after-free-via-veth-12728">
    <title>Vigil@nce - Linux kernel: use after free via veth, analyzed on 29/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-use-after-free-via-veth-12728</link>
    <description>An attacker can use a freed memory area in veth of Linux kernel, in order to trigger a denial of service, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12728</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-14T11:39:14Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-scm-set-cred-12727">
    <title>Vigil@nce - Linux kernel: privilege escalation via scm_set_cred, analyzed on 29/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-scm-set-cred-12727</link>
    <description>An attacker can use a suid/sgid application using SCM, in order to escalate his privileges.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12727</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-14T08:31:05Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-uid-map-12726">
    <title>Vigil@nce - Linux kernel: privilege escalation via uid_map, analyzed on 29/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-privilege-escalation-via-uid-map-12726</link>
    <description>An attacker can edit the content of the /proc/pid/uid_map file of the Linux kernel, in order to escalate his privileges.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12726</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-14T08:11:20Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EXT4-ORPHAN-FS-12719">
    <title>Vigil@nce - Linux kernel: denial of service via EXT4_ORPHAN_FS, analyzed on 26/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EXT4-ORPHAN-FS-12719</link>
    <description>An attacker can mount an ext4 filesystem with no journal and using an orphan extend, to create an infinite loop in the Linux kernel, in order to trigger a denial of service.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12719</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-11T13:39:03Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Internet-Explorer-file-detection-via-XMLDOM-12762">
    <title>Vigil@nce - Internet Explorer: file detection via XMLDOM, analyzed on 07/05/2013</title>
    <link>http://vigilance.fr/vulnerability/Internet-Explorer-file-detection-via-XMLDOM-12762</link>
    <description>An attacker can create an HTML page using XMLDOM of Internet Explorer, in order to detect if a file or a directory exists on user's computer.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12762</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-10T08:11:16Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Cisco-ASA-enumeration-of-VPN-groups-12691">
    <title>Vigil@nce - Cisco ASA: enumeration of VPN groups, analyzed on 18/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Cisco-ASA-enumeration-of-VPN-groups-12691</link>
    <description>An unauthenticated attacker can send ISAKMP AM1 messages to Cisco ASA, in order to detect if a VPN Group name is valid.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12691</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-03T09:38:49Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/MIT-krb5-denial-of-service-via-TGS-12685">
    <title>Vigil@nce - MIT krb5: denial of service via TGS, analyzed on 17/04/2013</title>
    <link>http://vigilance.fr/vulnerability/MIT-krb5-denial-of-service-via-TGS-12685</link>
    <description>An authenticated attacker can send a special TGS query to MIT krb5, in order to dereference a NULL pointer, which leads to a denial of service.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12685</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-05-02T09:03:57Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Xen-file-reading-via-qemu-nbd-12676">
    <title>Vigil@nce - Xen: file reading via qemu-nbd, analyzed on 15/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Xen-file-reading-via-qemu-nbd-12676</link>
    <description>When the host system uses the autodetection of qemu-nbd, an administrator located in a guest system can read files of the host system.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12676</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-30T16:31:26Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/cURL-obtaining-Cookies-12664">
    <title>Vigil@nce - cURL: obtaining Cookies, analyzed on 12/04/2013</title>
    <link>http://vigilance.fr/vulnerability/cURL-obtaining-Cookies-12664</link>
    <description>An attacker can create a site with a domain name matching the end of another site, in order to force cURL to send its cookies.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12664</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-27T11:53:24Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-buffer-overflow-of-tg3-VPD-12662">
    <title>Vigil@nce - Linux kernel: buffer overflow of tg3 VPD, analyzed on 12/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-buffer-overflow-of-tg3-VPD-12662</link>
    <description>An attacker can plug a malicious Tigon3 device, to generate a buffer overflow in the tg3 driver of Linux kernel, in order to trigger a denial of service, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12662</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-27T07:51:22Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/X-Org-Server-character-injection-via-VT-Switch-12686">
    <title>Vigil@nce - X.Org Server: character injection via VT Switch, analyzed on 17/04/2013</title>
    <link>http://vigilance.fr/vulnerability/X-Org-Server-character-injection-via-VT-Switch-12686</link>
    <description>A local attacker can plug a keyboard, press keys, and then change the virtual terminal of X.Org Server, in order to inject characters in the X environment.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12686</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-20T11:38:39Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Xen-memory-corruption-of-XSM-12608">
    <title>Vigil@nce - Xen: memory corruption of XSM, analyzed on 05/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Xen-memory-corruption-of-XSM-12608</link>
    <description>An attacker can generate a memory corruption when XSM is enabled in Xen, in order to trigger a denial of service, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12608</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-20T06:49:14Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/NVIDIA-UNIX-GPU-Driver-buffer-overflow-of-NoScanout-12603">
    <title>Vigil@nce - NVIDIA UNIX GPU Driver: buffer overflow of NoScanout, analyzed on 04/04/2013</title>
    <link>http://vigilance.fr/vulnerability/NVIDIA-UNIX-GPU-Driver-buffer-overflow-of-NoScanout-12603</link>
    <description>An attacker can generate a buffer overflow in NoScanout mode of NVIDIA UNIX GPU Driver, in order to trigger a denial of service, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12603</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-19T11:19:05Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-FUNCTION-TRACER-12674">
    <title>Vigil@nce - Linux kernel: denial of service via FUNCTION_TRACER, analyzed on 15/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-FUNCTION-TRACER-12674</link>
    <description>A local privileged attacker can use the tracing features of the Linux kernel, in order to trigger a denial of service.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12674</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-18T12:47:56Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/glibc-buffer-overflow-of-getaddrinfo-12599">
    <title>Vigil@nce - glibc: buffer overflow of getaddrinfo, analyzed on 03/04/2013</title>
    <link>http://vigilance.fr/vulnerability/glibc-buffer-overflow-of-getaddrinfo-12599</link>
    <description>An attacker can generate a buffer overflow in the getaddrinfo() function of glibc, in order to trigger a denial of service, and possibly to execute code.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12599</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-18T12:42:25Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Asterisk-denial-of-service-via-Content-Length-12588">
    <title>Vigil@nce - Asterisk: denial of service via Content-Length, analyzed on 28/03/2013</title>
    <link>http://vigilance.fr/vulnerability/Asterisk-denial-of-service-via-Content-Length-12588</link>
    <description>An attacker can send an HTTP query with a large Content-Length header, in order to stop the web service of Asterisk.</description>
    <dc:type>2</dc:type>
    <dc:identifier>VIGILANCE-VUL-12588</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-12T12:23:34Z</dc:date>
  </item>
  <item rdf:about="http://vigilance.fr/vulnerability/Linux-kernel-memory-reading-via-VIDEO-SET-SPU-PALETTE-12611">
    <title>Vigil@nce - Linux kernel: memory reading via VIDEO_SET_SPU_PALETTE, analyzed on 08/04/2013</title>
    <link>http://vigilance.fr/vulnerability/Linux-kernel-memory-reading-via-VIDEO-SET-SPU-PALETTE-12611</link>
    <description>A local attacker can use the VIDEO_SET_SPU_PALETTE ioctl, in order to read a fragment of kernel memory.</description>
    <dc:type>1</dc:type>
    <dc:identifier>VIGILANCE-VUL-12611</dc:identifier>
    <dc:creator>Vigil@nce</dc:creator>
    <dc:date>2013-04-11T08:00:05Z</dc:date>
  </item>
</rdf:RDF>
