<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
        <channel>
         <title>      @RISK: The Consensus Security Alert</title>
  <link>       http://www.sans.org/newsletters/risk/display.php</link>
  <description>All Updates From Vol: 11 - Issue: 11</description>
  <language>   en-us</language>
<copyright>(C) SANS Institute 2012</copyright>
             <webMaster>webmaster@sans.org</webMaster>
             <image>
               <title>SANS RSS Feed</title>
               <url>http://www.sans.org/images/rss_logo.gif</url>
               <link>http://www.sans.org/newsletters/risk/display.php</link>
             </image>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SansInstituteAtRiskAll" /><feedburner:info uri="sansinstituteatriskall" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
    <title>SANSFIRE 2011</title>
    <link>http://www.sans.org/info/74039</link>
  <guid>       http://www.sans.org/info/74039</guid>
    <description>SANSFIRE 2011</description>
  </item>
  <item>
    <title>(1) HIGH: Google Chrome Sandbox Escapes
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely1</guid>
    <description><![CDATA[
                                       <p><strong>Category:</strong> Widely Deployed Software</p>
                                       <p><strong>Affected:</strong><ul class="affected"><li> Google Chrome Prior to 17.0.963.79</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(2) HIGH: Microsoft Remote Desktop Protocol Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely2</guid>
    <description><![CDATA[
                                       <p><strong>Category:</strong> Widely Deployed Software</p>
                                       <p><strong>Affected:</strong><ul class="affected"><li> Windows 7</li><li>  Windows Server 2003</li><li>  Windows Server 2008</li><li>  Windows Vista</li><li>  Windows XP</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(3) HIGH: Mozilla Firefox Use-After-Free Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#widely3</guid>
    <description><![CDATA[
                                       <p><strong>Category:</strong> Widely Deployed Software</p>
                                       <p><strong>Affected:</strong><ul class="affected"><li> Firefox prior to 11.0</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>2.8 Mozilla Firefox/Thunderbird/SeaMonkey "shlwapi.dll"
 Use-After-Free Memory Corruption
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#2.8</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#2.8</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-045410.0.3, Thunderbird versions prior to Thunderbird ESR versionsprior to and SeaMonkey versions prior to are affected. </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.11 IBM DB2 Multiple Security Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.11</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.11</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.12 IBM Maximo Asset Management Multiple Security Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.12</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.12</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE:CVE-2012-0195,CVE-2011-4819,CVE-2011-4818,CVE-2011-4817,CVE-2011-4816,CVE-2011-1397,CVE-2011-1396,CVE-2011-1395,CVE-2011-1394 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.13 Expat XML Parsing Multiple Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.13</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.13</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0876,CVE-2012-1148,CVE-2012-1147 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.14 Google Chrome Remote Code Execution
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.14</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.14</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-3047 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.15 OpenLDAP LDAP Search Request Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.15</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.15</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.16 Apple Safari International Domain Name URI Spoofing
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.16</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.16</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0584 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.5 Microsoft Expression "wintab32.dll" DLL Loading Arbitrary Code
 Execution
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.5</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.5</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0016 </p>
                                       <p><strong>Platform:</strong> Other Microsoft Products
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.6 Microsoft Visual Studio Add-In Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.6</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.6</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0008 </p>
                                       <p><strong>Platform:</strong> Other Microsoft Products
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.7 DAEMON Tools "IOCTL" Handling Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.7</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.7</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.8 VMware vCenter Chargeback Manager Information Disclosure and
 Denial of Service Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.8</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.8</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-1472 </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.9 XnView Multiple Buffer Overflow Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.9</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.9</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.10 Vegas Movie Studio HD "CFHDDecoder.dll" DLL Loading Arbitrary
 Code Execution
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.10</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.10</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.23 LotusCMS Multiple PHP Code Execution Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.23</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.23</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.24 Jenkins Multiple Cross-Site Scripting and Directory Traversal
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.24</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.24</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0325,CVE-2012-0324 </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.25 Zend Server Multiple HTML Injection Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.25</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.25</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.26 Invision Power Board Unspecified HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.26</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.26</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.18 Splunk Unspecified Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.18</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.18</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.19 SquirrelMail Autocomplete Plugin Email Addresses Cross-Site
 Scripting
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.19</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.19</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0323 </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.20 EJBCA "issuer" Parameter Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.20</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.20</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.21 Synology Photo Station "photo_one.php" Script Cross-Site
 Scripting
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.21</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.21</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-1556 </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.22 Aurora WebOPAC "txtEmailAliasBarcode" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.22</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.22</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.1 Microsoft Remote Desktop Protocol Multiple Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.1</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0002,CVE-2012-0152 </p>
                                       <p><strong>Platform:</strong> Windows
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.2 Microsoft Windows DNS Server Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.2</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0006 </p>
                                       <p><strong>Platform:</strong> Windows
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.3 Microsoft Windows Kernel "Win32k.sys" Local Privilege
 Escalation
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.3</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0157 </p>
                                       <p><strong>Platform:</strong> Windows
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.11.4 Microsoft Windows "DirectWrite" API Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.4</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=11&amp;rss=Y#12.11.4</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0156 </p>
                                       <p><strong>Platform:</strong> Windows
</p>
                                      ]]></description>
  </item>
</channel>
</rss>

