<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Donna's SecurityFlash : Advisories</title><link>http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx</link><description>Tags: Advisories</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft Security Advisory 943521 (Updated)</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/microsoft-security-advisory-943521-updated.aspx</link><pubDate>Fri, 26 Oct 2007 06:21:14 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1264978</guid><dc:creator>donna</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1264978</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1264978</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/10/26/microsoft-security-advisory-943521-updated.aspx#comments</comments><description>Microsoft Security Advisory (943521) URL Handling Vulnerability in Windows XP and Windows Server 2003 with Windows Internet Explorer 7 Could Allow Remote Code Execution Published: October 10, 2007 | Updated: October 25, 2007 Revisions: • October 10, 2007...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/26/microsoft-security-advisory-943521-updated.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1264978" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Security Bulletin MS06-067 revised</title><link>http://msmvps.com/blogs/donna/archive/2007/10/25/microsoft-security-bulletin-ms06-067-revised.aspx</link><pubDate>Wed, 24 Oct 2007 23:51:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1262480</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1262480</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1262480</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/10/25/microsoft-security-bulletin-ms06-067-revised.aspx#comments</comments><description>MS06-067 - http://www.microsoft.com/technet/security/bulletin/ms06-067.mspx - Reason for Revision: Revised to include MS06-065 as a bulletin that is replaced by this bulletin. - Originally posted: November 14, 2006 - Updated: October 24, 2007 - Bulletin...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/25/microsoft-security-bulletin-ms06-067-revised.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1262480" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Adobe Security Bulletin APSB07-18</title><link>http://msmvps.com/blogs/donna/archive/2007/10/22/adobe-security-bulletin-apsb07-18.aspx</link><pubDate>Mon, 22 Oct 2007 17:51:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1258197</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1258197</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1258197</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/10/22/adobe-security-bulletin-apsb07-18.aspx#comments</comments><description>Update available for vulnerability in versions 8.1 and earlier of Adobe Reader and Acrobat Release date: October 22, 2007 Vulnerability identifier: APSB07-18 CVE number: CVE-2007-5020 Platform: Windows XP (Vista users are not affected) with Internet Explorer...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/22/adobe-security-bulletin-apsb07-18.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1258197" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Opera JPEG Processing Heap Corruption Vulnerabilities</title><link>http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx</link><pubDate>Tue, 09 Jan 2007 08:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:479116</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=479116</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=479116</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx#comments</comments><description>Opera is vulnerable in parsing the JPEG file format. Discovered were four vulnerabilities, each in different segments of the file format. posidron will describe in this advisory the two important ones. 1 - ntdll.RtlAllocateHeap() DHT vulnerability 2 ...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=479116" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Kerio Fake 'iphlpapi' DLL injection Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2007/01/08/kerio-fake-iphlpapi-dll-injection-vulnerability.aspx</link><pubDate>Mon, 08 Jan 2007 12:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:477314</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=477314</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=477314</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/08/kerio-fake-iphlpapi-dll-injection-vulnerability.aspx#comments</comments><description>A vulnerability in the Kerio allows local attackers to cause the product to load an arbitrary DLL which in turn can be used to compromise the system. Vulnerable software: * Sunbelt Kerio Personal Firewall 4.3.268 * Sunbelt Kerio Personal Firewall 4.3...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/08/kerio-fake-iphlpapi-dll-injection-vulnerability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=477314" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2007/01/07/multiple-pdf-readers-multiple-remote-buffer-overflow-vulnerability.aspx</link><pubDate>Sun, 07 Jan 2007 23:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:476523</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=476523</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=476523</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/07/multiple-pdf-readers-multiple-remote-buffer-overflow-vulnerability.aspx#comments</comments><description>Vulnerable: Xpdf Xpdf 3.0.1 (Patch 2) Apple Mac OS X Preview.app 3.0.8 Adobe Acrobat Reader v8 and earlier versions Multiple PDF readers are prone to multiple remote buffer-overflow vulnerabilities. These issues occur because the applications fail to...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/07/multiple-pdf-readers-multiple-remote-buffer-overflow-vulnerability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=476523" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Kaspersky Antivirus PE File Handling Denial of Service</title><link>http://msmvps.com/blogs/donna/archive/2007/01/06/kaspersky-antivirus-pe-file-handling-denial-of-service.aspx</link><pubDate>Sat, 06 Jan 2007 11:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:473501</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=473501</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=473501</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/06/kaspersky-antivirus-pe-file-handling-denial-of-service.aspx#comments</comments><description>Affected Software: Kaspersky Anti-Virus 4.x Kaspersky Anti-Virus 5.x Kaspersky Anti-Virus 6.x Kaspersky Internet Security 6.x Kaspersky SMTP Gateway 5.x Description: A vulnerability has been reported in Kaspersky Antivirus, which can be exploited by malicious...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/06/kaspersky-antivirus-pe-file-handling-denial-of-service.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=473501" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Security Bulletins Advanced Notification (UPDATED)</title><link>http://msmvps.com/blogs/donna/archive/2007/01/06/microsoft-security-bulletins-advanced-notification-updated.aspx</link><pubDate>Sat, 06 Jan 2007 00:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:472636</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=472636</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=472636</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/06/microsoft-security-bulletins-advanced-notification-updated.aspx#comments</comments><description>Microsoft earlier plan to release eight (8) updates on 9 January 2007 but there is a change today on the said plan: Security Updates One Microsoft Security Bulletin affecting Microsoft Windows. The highest Maximum Severity rating for this is Critical...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/06/microsoft-security-bulletins-advanced-notification-updated.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=472636" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Apple iLife, Opera Browser, OpenOffice, StarOffice &amp; WordPress Vulnerabilities</title><link>http://msmvps.com/blogs/donna/archive/2007/01/06/apple-ilife-opera-browser-openoffice-staroffice-wordpress-vulnerabilities.aspx</link><pubDate>Sat, 06 Jan 2007 00:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:472615</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=472615</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=472615</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/06/apple-ilife-opera-browser-openoffice-staroffice-wordpress-vulnerabilities.aspx#comments</comments><description>Apple iLife iPhoto Photocast XML "title" Format String Vulnerability - a vulnerability in iLIfe iPhoto, which potentially can be exploited by malicious people to compromise a user's system has been discovered by Kevin Finisterre. Possible solution is...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/06/apple-ilife-opera-browser-openoffice-staroffice-wordpress-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=472615" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Security Bulletins - Advanced Notifications</title><link>http://msmvps.com/blogs/donna/archive/2007/01/05/microsoft-security-bulletins-advanced-notifications.aspx</link><pubDate>Fri, 05 Jan 2007 00:42:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:469774</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=469774</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=469774</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/05/microsoft-security-bulletins-advanced-notifications.aspx#comments</comments><description>Microsoft Security Bulletin Advance Notification http://www.microsoft.com/technet/security/bulletin/advance.mspx On 9 January 2007 Microsoft is planning to release: Security Updates Three Microsoft Security Bulletins affecting Microsoft Windows. The highest...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/05/microsoft-security-bulletins-advanced-notifications.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=469774" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Windows Workstation Service NetrWkstaUserEnum Denial of Service </title><link>http://msmvps.com/blogs/donna/archive/2006/12/26/windows-workstation-service-netrwkstauserenum-denial-of-service.aspx</link><pubDate>Tue, 26 Dec 2006 19:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:453243</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=453243</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=453243</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/26/windows-workstation-service-netrwkstauserenum-denial-of-service.aspx#comments</comments><description>Affected OS: Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows XP Home Edition Microsoft Windows XP Professional h07 has discovered a weakness...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/26/windows-workstation-service-netrwkstauserenum-denial-of-service.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=453243" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Windows MessageBoxA Denial of Service Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2006/12/21/microsoft-windows-messageboxa-denial-of-service-vulnerability.aspx</link><pubDate>Thu, 21 Dec 2006 01:49:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:438213</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=438213</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=438213</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/21/microsoft-windows-messageboxa-denial-of-service-vulnerability.aspx#comments</comments><description>Microsoft Windows is prone to a local denial-of-service vulnerability because the operating system fails to handle certain API calls with unexpected parameters. A local unprivileged attacker may exploit this issue by executing a malicious application...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/21/microsoft-windows-messageboxa-denial-of-service-vulnerability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=438213" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>NOD32 Antivirus DOC parsing Arbitrary Code Execution Advisory </title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/nod32-antivirus-doc-parsing-arbitrary-code-execution-advisory.aspx</link><pubDate>Wed, 20 Dec 2006 18:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:436976</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=436976</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=436976</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/nod32-antivirus-doc-parsing-arbitrary-code-execution-advisory.aspx#comments</comments><description>Affected Products: ESET NOD32 Antivirus Vulnerability: Arbitrary Code Execution (remote) Risk: HIGH Vendor communication: 2006/08/24 initial notification of ESET 2006/08/28 ESET Response 2006/08/29 PGP keys exchange 2006/08/29 PoC files sent to ESET 2006...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/nod32-antivirus-doc-parsing-arbitrary-code-execution-advisory.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=436976" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>CA Portal Technology Session Handling Vulnerability;CA Anti-Virus vetfddnt.sys and vetmonnt.sys Local DoS Vulnerabilities</title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/ca-portal-technology-session-handling-vulnerability-ca-anti-virus-vetfddnt-sys-and-vetmonnt-sys-local-dos-vulnerabilities.aspx</link><pubDate>Wed, 20 Dec 2006 18:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:436917</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=436917</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=436917</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/ca-portal-technology-session-handling-vulnerability-ca-anti-virus-vetfddnt-sys-and-vetmonnt-sys-local-dos-vulnerabilities.aspx#comments</comments><description>Affected Software: CA BrightStor Portal 11.x CA CleverPath Aion 10.x CA CleverPath Portal 4.x CA eTrust Security Command Center 1.x CA eTrust Security Command Center 8.x CA Unicenter Asset Portfolio Management 11.x CA Unicenter Database Command Center...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/ca-portal-technology-session-handling-vulnerability-ca-anti-virus-vetfddnt-sys-and-vetmonnt-sys-local-dos-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=436917" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Apple Mac OS X Quicktime For Java Information Disclosure Vulnerability;Apple released security fixes</title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/apple-mac-os-x-quicktime-for-java-information-disclosure-vulnerability-apple-released-security-fixes.aspx</link><pubDate>Wed, 20 Dec 2006 04:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:435248</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=435248</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=435248</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/apple-mac-os-x-quicktime-for-java-information-disclosure-vulnerability-apple-released-security-fixes.aspx#comments</comments><description>Apple Mac OS X is prone to an information-disclosure vulnerability. Attackers may exploit this issue by convincing victims into visiting a malicious website. Exploiting this issue may allow remote attackers to capture images rendered locally on screen...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/apple-mac-os-x-quicktime-for-java-information-disclosure-vulnerability-apple-released-security-fixes.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=435248" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Security Bulletin Revised: MS06-078</title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/microsoft-security-bulletin-revised-ms06-078.aspx</link><pubDate>Wed, 20 Dec 2006 03:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:435230</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=435230</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=435230</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/microsoft-security-bulletin-revised-ms06-078.aspx#comments</comments><description>MS06-078 - Vulnerability in Windows Media Format Could Allow Remote Code Execution (923689) http://www.microsoft.com/technet/security/bulletin/MS06-078.mspx?pubDate=2006-12-19 Revisions: V2.0 (December 19, 2006): Bulletin updated has been revised and...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/microsoft-security-bulletin-revised-ms06-078.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=435230" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Mozilla Foundation Security Advisories (Dec. 19, 2006)</title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx</link><pubDate>Wed, 20 Dec 2006 03:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:435211</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=435211</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=435211</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx#comments</comments><description>MFSA 2006-76 XSS using outer window's Function object MFSA 2006-75 RSS Feed-preview referrer leak MFSA 2006-74 Mail header processing heap overflows MFSA 2006-73 Mozilla SVG Processing Remote Code Execution MFSA 2006-72 XSS by setting img.src to BLOCKED...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=435211" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Winamp Web Interface Multiple Vulnerabilities</title><link>http://msmvps.com/blogs/donna/archive/2006/12/19/winamp-web-interface-multiple-vulnerabilities.aspx</link><pubDate>Tue, 19 Dec 2006 14:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:433565</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=433565</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=433565</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/19/winamp-web-interface-multiple-vulnerabilities.aspx#comments</comments><description>Winamp Web Interface (Wawi) is "a nice open source plugin for Winamp which allows the remote administration of the media player through any web browser". The Winamp Web Interface, WAWI for short, has been found to contain multiple vulnerabilities that...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/19/winamp-web-interface-multiple-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=433565" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Intel 2200BG W29N51.SYS Driver Beacon Frame Race Condition</title><link>http://msmvps.com/blogs/donna/archive/2006/12/19/intel-2200bg-w29n51-sys-driver-beacon-frame-race-condition.aspx</link><pubDate>Tue, 19 Dec 2006 14:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:433557</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=433557</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=433557</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/19/intel-2200bg-w29n51-sys-driver-beacon-frame-race-condition.aspx#comments</comments><description>Breno Silva Pinto has reported a vulnerability in Intel 2200BG drivers, which potentially can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a race condition when W29N51.SYS handles multiple beacon...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/19/intel-2200bg-w29n51-sys-driver-beacon-frame-race-condition.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=433557" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Microsoft Outlook Recipient ActiveX Control Lets Remote Users Deny Service</title><link>http://msmvps.com/blogs/donna/archive/2006/12/19/microsoft-outlook-recipient-activex-control-lets-remote-users-deny-service.aspx</link><pubDate>Tue, 19 Dec 2006 14:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:433540</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=433540</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=433540</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/19/microsoft-outlook-recipient-activex-control-lets-remote-users-deny-service.aspx#comments</comments><description>http://www.securitytracker.com/alerts/2006/Dec/1017397.html A vulnerability was reported in Microsoft Outlook. A remote user can cause denial of service conditions. A remote user can create specially crafted HTML that, when loaded by the target user,...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/19/microsoft-outlook-recipient-activex-control-lets-remote-users-deny-service.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=433540" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item></channel></rss>