<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
        <channel>
         <title>      @RISK: The Consensus Security Alert</title>
  <link>       http://www.sans.org/newsletters/risk/display.php</link>
  <description>All Updates From Vol: 11 - Issue: 6</description>
  <language>   en-us</language>
<copyright>(C) SANS Institute 2012</copyright>
             <webMaster>webmaster@sans.org</webMaster>
             <image>
               <title>SANS RSS Feed</title>
               <url>http://www.sans.org/images/rss_logo.gif</url>
               <link>http://www.sans.org/newsletters/risk/display.php</link>
             </image>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SansInstituteAtRiskAll" /><feedburner:info uri="sansinstituteatriskall" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
    <title>SANSFIRE 2011</title>
    <link>http://www.sans.org/info/74039</link>
  <guid>       http://www.sans.org/info/74039</guid>
    <description>SANSFIRE 2011</description>
  </item>
  <item>
    <title>(1) MEDIUM: RealNetworks RealPlayer Multiple Security Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#widely1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#widely1</guid>
    <description><![CDATA[
                                       <p><strong>Category:</strong> Widely Deployed Software</p>
                                       <p><strong>Affected:</strong><ul class="affected"><li> RealNetworks RealPlayer 11.0-11.1</li><li>  RealNetworks RealPlayer SP 1.0-1.1.5</li><li>  RealNetworks RealPlayer 14.0.0-14.0.7</li><li>  RealNetworks RealPlayer 15.0.0-15.0.1.13</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>(2) MEDIUM: Novell iPrint Server Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#widely2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#widely2</guid>
    <description><![CDATA[
                                       <p><strong>Category:</strong> Widely Deployed Software</p>
                                       <p><strong>Affected:</strong><ul class="affected"><li> Novell iPrint for Linux Open Enterprise Server prior to OES2 SP3 patch 7885</li></ul></p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.9 IBM AIX TCP Stack Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.9</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.9</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0194 </p>
                                       <p><strong>Platform:</strong> Aix
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.10 PHP "htmlspecialchars()" Function Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.10</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.10</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.11 Condor Multiple Format String Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.11</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.11</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-4930 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.12 Real Networks RealPlayer Multiple Remote Code Execution
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.12</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.12</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0922,CVE-2012-0923,CVE-2012-0924,CVE-2012-0925,CVE-2012-0926,CVE-2012-0927,CVE-2012-0928 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.13 Apache CXF UsernameToken Policy Validation Security Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.13</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.13</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0803 </p>
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.8 JBoss Web Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.8</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.8</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-4610 </p>
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.1 Siemens SIMATIC HMI Multiple Unspecified Cross-Site Scripting
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.1</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-4511,CVE-2011-4510 </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.2 Skype Prior to 5.8.0.154 Unspecified Security Vulnerability
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.2</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.3 Symantec pcAnywhere Session Closure Access Violation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.3</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0290 </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.4 Edraw Diagram Component ActiveX Control Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.4</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.4</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.5 TYPSoft FTP Server Multiple Commands Remote Denial of Service
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.5</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.5</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.6 XnView JPEG2000 Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.6</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.6</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.7 Ing. Punzenberger COPA-DATA GmbH zenon Multiple Denial of
 Service Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.7</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.7</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-4534,CVE-2011-4533 </p>
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.19 Apache HTTP Server "mod_proxy" Reverse Proxy Security Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.19</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.19</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2011-3639 </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.20 ManageEngine Applications Manager Multiple Cross-Site Scripting
 and SQL Injection Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.20</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.20</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.21 TYPO3 Third Party Extensions Multiple Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.21</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.21</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.22 DotNetNuke Cross-Site Scripting and Security Bypass
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.22</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.22</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.23 EMC Documentum xPlore Information Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.23</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.23</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: CVE-2012-0396 </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.24 EPiServer CMS Cross Site Scripting and Security Bypass
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.24</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.24</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.25 Vespa "getid3.php" Local File Include
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.25</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.25</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.14 NexorONE "login.php" Multiple Cross Site Scripting
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.14</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.14</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.15 Simple Groupware "export" Parameter Cross Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.15</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.15</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.16 eFront "administrator.php" Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.16</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.16</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.17 HDWiki URI SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.17</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.17</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>12.6.18 BASE "base_qry_main.php" SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.18</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=11&amp;i=6&amp;rss=Y#12.6.18</guid>
    <description><![CDATA[
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p>
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
</channel>
</rss>

