<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
        <channel>
         <title>      @RISK: The Consensus Security Alert - Part 2</title>
  <link>       http://www.sans.org/newsletters/risk/display.php</link>
  <description>All Updates From Part 2 of Vol: 9 - Issue: 6</description>
  <language>   en-us</language>
<copyright>(C) SANS Institute 2010</copyright>
             <webMaster>webmaster@sans.org</webMaster>
             <image>
               <title>SANS RSS Feed</title>
               <url>http://www.sans.org/images/rss_logo.gif</url>
               <link>http://www.sans.org/newsletters/risk/display.php</link>
             </image>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SansInstituteAtRiskPart2" /><feedburner:info uri="sansinstituteatriskpart2" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
    <title>10.6.9 OpenBSD "ptrace()" Local Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.9</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.9</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> BSD
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.32 Adobe ColdFusion Solr Service Information Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.32</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.32</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0185 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.16 Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow
 Vulnerability
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.16</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.16</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0010 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.39 Asterisk T.38 "FaxMaxDatagram" Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.39</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.39</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0441 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.33 bitfolge snif Remote File Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.33</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.33</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.36 C++ Sockets Library HTTP Headers Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.36</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.36</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.15 Cisco Unified MeetingPlace Multiple Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.15</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.15</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0139, CVE-2010-0140, CVE-2010-0141,CVE-2010-0142 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.41 Citrix XenServer Authentication Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.41</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.41</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.30 ejabberd "client2server" Message Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.30</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.30</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.19 FUSE "fusermount" Race Condition
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.19</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.19</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3297 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.20 GNU Mailman Unspecified Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.20</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.20</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.27 Hitachi Multiple Products Image File Parsing Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.27</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.27</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.14 HP OpenView Storage Data Protector Unspecified Remote
 Unauthorized Access
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.14</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.14</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-4183 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.40 HP OpenVMS RMS Patch Kit Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.40</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.40</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0443 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.31 Hybserv2 ":help" Command Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.31</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.31</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0303 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.34 IBM DB2 "kuddb2" Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.34</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.34</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.11 IBM DB2 "REPEAT()" Heap Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.11</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.11</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.28 Ingres Database Heap Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.28</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.28</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.12 IRCD-Hybrid and ircd-ratbox "LINKS" Command Remote Integer
 Underflow
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.12</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.12</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-4016 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.13 ircd-ratbox "HELP" Command Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.13</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.13</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0300 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.25 Libpurple MSN Protocol "slp.c" Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.25</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.25</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0227 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.37 lighttpd Slow Request Handling Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.37</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.37</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0295 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.38 MySQL "sql/sql_table.cc" CREATE TABLE Security Bypass
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.38</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.38</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2008-7247 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.35 Oracle Times Ten In-Memory Database Remote Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.35</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.35</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.18 PostgreSQL "bitsubstr" Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.18</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.18</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0442 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.24 Samba "mount.cifs" Utility Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.24</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.24</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3297 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.29 SQLite "SQLITE_SECURE_DELETE" Local Information Disclosure
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.29</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.29</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.17 sudosh3 "replay.c" Multiple Buffer Overflow Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.17</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.17</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.26 Sun Java System Application Server HTTP TRACE Information
 Disclosure
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.26</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.26</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0386 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.22 Symantec Altiris Notification Server Static Encryption Key
 Unauthorized Access
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.22</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.22</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-3035 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.21 Wireshark Dissector LWRES Multiple Buffer Overflow
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.21</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.21</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0304 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.23 ZABBIX "node_process_command()" Remote Command Execution
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.23</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.23</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-4998 </p> 
                                       <p><strong>Platform:</strong> Cross Platform
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.8 HP Enterprise Cluster Master Toolkit Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.8</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.8</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-4184 </p> 
                                       <p><strong>Platform:</strong> HP-UX
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.5 Battery Life Toolkit "bltk_sudo" Local Privilege Escalation
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.5</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.5</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.4 Debian Lintian Multiple Local Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.4</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.4</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2009-4013, CVE-2009-4014, CVE-2009-4015 </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.6 Linux Kernel 64bit Personality Handling Local Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.6</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.6</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.7 Linux Kernel KVM "pit_ioport_read()" Local Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.7</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.7</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Linux
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.10 Sun Solaris "CODE_GET_VERSION IOCTL" Local Denial of Service
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.10</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.10</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Solaris
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.3 360.cn Qihoo 360 Security Guard "bregdrv.sys" Edit Registry
 Local Privilege Escalation
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.3</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.3</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.2 Corel Paint Shop Pro Photo X2 "FPX" File Heap Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.2</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.2</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.1 Vermillion FTP Daemon "Port" Command Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.1</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.1</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Third Party Windows Apps
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.64 Drupal Author Contact Module "block" HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.64</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.64</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.65 Drupal Feedback 2 Module User Agent String HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.65</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.65</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.72 Drupal MP3 Player MP3 Filename HTML Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.72</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.72</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.66 Joomla! "com_ccnewsletter" Component Directory Traversal
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.66</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.66</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.70 Joomla! "com_jeeventcalendar" Component "event_id" Parameter
 SQL Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.70</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.70</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.74 Joomla! AutartiTarot Component Directory Traversal
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.74</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.74</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.68 Maian Greetings Arbitrary File Upload
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.68</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.68</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.71 MoinMoin Unspecified Security
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.71</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.71</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.75 RoundCube Webmail DNS prefetching Domain Name Information
 Disclosure
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.75</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.75</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0464 </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.73 TYPO3 T3Blog HTML Forms Cross-Site Scripting and SQL Injection
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.73</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.73</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.67 XAMPP "showcode.php" Local File Include
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.67</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.67</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.69 Xerox WorkCentre PJL Daemon Buffer Overflow
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.69</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.69</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.48 Cisco Secure Desktop "translation" Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.48</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.48</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: CVE-2010-0440 </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.45 CommonSpot Server "utilities/longproc.cfm" Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.45</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.45</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.47 Comtrend CT-507 IT ADSL Router "scvrtsrv.cmd" Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.47</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.47</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.44 Discuz! "tid" Parameter Cross-Site Scripting
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.44</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.44</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.42 HP System Management Homepage "servercert" Parameter Cross-Site
 Scripting
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.42</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.42</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.43 SAP BusinessObjects URI Redirection and Cross-Site Scripting
 Vulnerabilities
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.43</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.43</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.49 WebCalendar Multiple Cross-Site Scripting Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.49</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.49</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.46 XAMPP Multiple Cross-Site Scripting Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.46</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.46</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - Cross Site Scripting
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.57 Evernew Free Joke Script "id" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.57</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.57</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.56 Joomla! "com_dms" Component "category_id" Parameter SQL
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.56</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.56</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.62 Joomla! "com_gambling" Component "gamblingEvent" Parameter SQL
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.62</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.62</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.60 Joomla! "com_job" Component "id_job" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.60</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.60</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.54 Joomla! "com_rsgallery2" Component "catid" Parameter SQL
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.54</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.54</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.55 Joomla! "com_simplefaq" Component "catid" Parameter SQL
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.55</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.55</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.58 Joomla! "com_yelp" Component "cid" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.58</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.58</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.59 Joomla! Documents Seller Component "category_id" Parameter SQL
 Injection
 </title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.59</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.59</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.61 Joomla! JE Quiz Component "eid" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.61</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.61</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.63 Joomla! JEvents Search Plug-in "eventsearch.php" SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.63</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.63</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.51 jVideoDirect Component for Joomla! "v" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.51</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.51</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.50 NovaBoard "forums" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.50</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.50</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.53 OCS Inventory NG Server "login" Parameter SQL Injection
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.53</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.53</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
  <item>
    <title>10.6.52 XAMPP Multiple SQL Injection Vulnerabilities
</title>
    <link>http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.52</link>
  <guid>       http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=6&amp;rss=Y#10.6.52</guid>
    <description><![CDATA[ 
                                       <p><strong>CVEs:</strong>  CVE: Not Available </p> 
                                       <p><strong>Platform:</strong> Web Application - SQL Injection
</p>
                                      ]]></description>
  </item>
</channel>
</rss>
