<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Mon, 08 Jun 2026 22:38:14 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-06-054: Novell NetMail IMAP APPEND Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-086</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-054/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Novell NetMail. Successful exploitation requires the attacker to successfully authenticate to the affected service. The following CVEs are assigned: CVE-2006-6425.]]></description>
      <pubDate>Fri, 22 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-053: Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-085</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-053/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected versions of Novell NetMail. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-6424.]]></description>
      <pubDate>Fri, 22 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-052: Novell NetMail NMAP STOR Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-082</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-052/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Novell NetMail. Successful exploitation requires the attacker to successfully authenticate to the affected service. The following CVEs are assigned: CVE-2006-6424.]]></description>
      <pubDate>Fri, 22 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-051: Mozilla Firefox SVG Processing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-126</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-051/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-6504.]]></description>
      <pubDate>Tue, 19 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-050: Symantec Veritas NetBackup CONNECT_OPTIONS Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-071</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-050/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec Veritas NetBackup. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5822.]]></description>
      <pubDate>Wed, 13 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-049: Symantec Veritas NetBackup Long Request Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-070</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-049/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec Veritas NetBackup. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-6222.]]></description>
      <pubDate>Wed, 13 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-048: Microsoft Internet Explorer normalize() Function Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-072</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-048/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-5581.]]></description>
      <pubDate>Tue, 12 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-047: Microsoft Visual Studio WmiScriptUtils.dll Cross-Zone Scripting Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-068</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-047/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. Successful exploitation requires that the target user browse to a malicious web page. The following CVEs are assigned: CVE-2006-4704.]]></description>
      <pubDate>Tue, 12 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-046: Sophos Anti-Virus SIT Archive Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-091</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-046/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sophos Anti-Virus. The following CVEs are assigned: CVE-2006-6335.]]></description>
      <pubDate>Tue, 12 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-045: Sophos Anti-Virus CPIO Archive Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-090</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-045/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sophos Anti-Virus. The following CVEs are assigned: CVE-2006-6335.]]></description>
      <pubDate>Tue, 12 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-044: Adobe Download Manager AOM Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-042</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-044/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Adobe Download Manager application. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-5856.]]></description>
      <pubDate>Wed, 06 Dec 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-043: Novell Netware Client Print Provider Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-100</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-043/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the Novell Netware Client. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5854.]]></description>
      <pubDate>Wed, 29 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-042: Verity Ultraseek Request Proxying Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-039</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-042/</link>
      <description><![CDATA[This vulnerability allows remote attackers to proxy web attacks and scan internal hosts through vulnerable installations of Verity Ultraseek. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5819.]]></description>
      <pubDate>Wed, 15 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-041: Microsoft Internet Explorer CSS Float Property Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-080</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-041/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-4687.]]></description>
      <pubDate>Tue, 14 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-040: WinZip FileView ActiveX Control Unsafe Method Exposure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-077</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-040/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-5198.]]></description>
      <pubDate>Tue, 14 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-039: Marshal MailMarshal ARJ Extraction Directory Traversal Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-003</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-039/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Marshal MailMarshal (formerly of NetIQ). Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5487.]]></description>
      <pubDate>Fri, 10 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-038: Citrix MetaFrame IMA Management Module Remote Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-062</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-038/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Citrix MetaFrame Presentation Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5821.]]></description>
      <pubDate>Thu, 09 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-037: America Online ICQ ActiveX Control Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-102</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-037/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of AOL ICQ. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5650.]]></description>
      <pubDate>Mon, 06 Nov 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-036: Novell Netmail User Authentication Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-076</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-036/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netmail. Exploitation does not require authentication. The following CVEs are assigned: CVE-2006-5478.]]></description>
      <pubDate>Tue, 31 Oct 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-081</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-035/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5478.]]></description>
      <pubDate>Thu, 26 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-034: Microsoft Word Malformed Chart Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-061</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-034/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target user into opening a malicious .XLS file. The following CVEs are assigned: CVE-2006-3650.]]></description>
      <pubDate>Tue, 10 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-033: Microsoft Office Excel File Format DATETIME Record Parsing Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-059</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-033/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target user into opening a malicious .XLS file. The following CVEs are assigned: CVE-2006-2387.]]></description>
      <pubDate>Tue, 10 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-032: Microsoft PowerPoint Malformed Slide Notes Rebuilding Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-065</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-032/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target user into opening a malicious .PPT file. The following CVEs are assigned: CVE-2006-3435.]]></description>
      <pubDate>Tue, 10 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-031: CA Multiple Product Message Engine RPC Server Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-046</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-031/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup, Enterprise Backup, Server Protection Suite and Business Protection Suite. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5143.]]></description>
      <pubDate>Thu, 05 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-030: CA BrightStor ARCserve Discovery Service Remote Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-041</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-030/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup, Enterprise Backup, Server Protection Suite and Business Protection Suite. Authentication is not required to exploit this vulnerability and both client and servers are affected. The following CVEs are assigned: CVE-2006-5143.]]></description>
      <pubDate>Thu, 05 Oct 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-029: Ipswitch WS_FTP Server Checksum Command Parsing Buffer Overflow Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-078</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-029/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ipswitch WS_FTP Server. Anonymous access or authentication is required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-5000.]]></description>
      <pubDate>Tue, 26 Sep 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-028: Ipswitch Collaboration Suite SMTP Server Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-067</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-028/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ipswitch Collaboration Suite and IMail. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-4379.]]></description>
      <pubDate>Fri, 08 Sep 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-027: Microsoft Internet Explorer CSS Class Ordering Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-066</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-027/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-3450.]]></description>
      <pubDate>Tue, 08 Aug 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-026: Microsoft Internet Explorer Multiple CSS Imports Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-058</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-026/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-3451.]]></description>
      <pubDate>Tue, 08 Aug 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-025: Mozilla Firefox Javascript navigator Object Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-055</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-025/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla Firefox web browser. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2006-3677.]]></description>
      <pubDate>Wed, 26 Jul 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-024: eIQnetworks Enterprise Security Analyzer License Manager Buffer Overflow]]></title>
      <guid isPermaLink="false">ZDI-CAN-052</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-024/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of eIQnetworks Enterprise Security Analyzer. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-3838.]]></description>
      <pubDate>Tue, 25 Jul 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-023: eIQnetworks Enterprise Security Analyzer Syslog TCP Server Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-053</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-023/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of eIQnetworks Enterprise Security Analyzer. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-3838.]]></description>
      <pubDate>Tue, 25 Jul 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-022: Microsoft Office Excel File Rebuilding Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-045</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-022/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The following CVEs are assigned: CVE-2006-2388.]]></description>
      <pubDate>Tue, 11 Jul 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-021: WebEx Downloader Plug-in Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-034</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-021/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the WebEx Downloader Plug-in. Successful exploitation requires that the target user browse to a malicious web page. The following CVEs are assigned: CVE-2006-3423.]]></description>
      <pubDate>Thu, 06 Jul 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-043</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-020/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple iTunes. Exploitation requires an attacker to convince a target user into opening a malicious play list file. The following CVEs are assigned: CVE-2006-1467.]]></description>
      <pubDate>Thu, 29 Jun 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-019: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-040</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-019/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems that have some versions of the GraceNote CDDBControl ActiveX object installed. There is a buffer overflow in an ActiveXObject registered by several products that use the Gracenote CDDB for CD information lookup. The ActiveX Object is commonly registered as safe and can be accessed from a malicious web site. The following CVEs are assigned: CVE-2006-3134.]]></description>
      <pubDate>Tue, 27 Jun 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-018: Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-044</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-018/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. Successful exploitation requires that the target user browse to a malicious web page. The following CVEs are assigned: CVE-2006-2383.]]></description>
      <pubDate>Tue, 13 Jun 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-017: Microsoft Internet Explorer UTF-8 Decoding Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-012</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-017/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. Successful exploitation requires that the target user browse to a malicious web page. Exploitaton does not require JavaScript, Java or ActiveX to be enabled. The following CVEs are assigned: CVE-2006-2382.]]></description>
      <pubDate>Tue, 13 Jun 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-016: Novell eDirectory 8.8 NDS Server Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-027</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-016/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Exploitation does not require authentication. The following CVEs are assigned: CVE-2006-2496.]]></description>
      <pubDate>Tue, 13 Jun 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-015: Apple QuickTime H.264 Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-033</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-015/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple&#x27;s QuickTime media player. The following CVEs are assigned: CVE-2006-1463.]]></description>
      <pubDate>Thu, 11 May 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-014: Verisign I-Nav ActiveX Control Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-030</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-014/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Verisign i-Nav ActiveX control. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. The following CVEs are assigned: CVE-2006-2273.]]></description>
      <pubDate>Wed, 10 May 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-013: TippingPoint SMS Server Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-017</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-013/</link>
      <description><![CDATA[This vulnerability may allow attackers to access sensitive information from vulnerable TippingPoint SMS servers. The following CVEs are assigned: CVE-2006-0993.]]></description>
      <pubDate>Tue, 09 May 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-012: Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-032</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-012/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sophos AntiVirus. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0994.]]></description>
      <pubDate>Mon, 08 May 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-026</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-011/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail. The following CVEs are assigned: CVE-2006-0748.]]></description>
      <pubDate>Tue, 25 Apr 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-015</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-010/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail. The following CVEs are assigned: CVE-2006-1730.]]></description>
      <pubDate>Mon, 17 Apr 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-008</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-009/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail. The following CVEs are assigned: CVE-2006-0749.]]></description>
      <pubDate>Mon, 17 Apr 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-028</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-008/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Novell GroupWise Messenger. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0992.]]></description>
      <pubDate>Thu, 13 Apr 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-002</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-007/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Microsoft Windows operating system. User interaction is required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0014.]]></description>
      <pubDate>Tue, 11 Apr 2006 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-006: Symantec VERITAS NetBackup Database Manager Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-016</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-006/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable Symantec VERITAS NetBackup installations. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0990.]]></description>
      <pubDate>Mon, 27 Mar 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-005: Symantec VERITAS NetBackup Volume Manager Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-010</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-005/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable Symantec VERITAS NetBackup installations. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0989.]]></description>
      <pubDate>Mon, 27 Mar 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-024</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-004/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The following CVEs are assigned: CVE-2006-0028.]]></description>
      <pubDate>Tue, 14 Mar 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-003: Ipswitch Collaboration Suite Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-009</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-003/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ipswitch Collaboration Suite. Authentication is required to exploit this vulnerability. The following CVEs are assigned: CVE-2005-3526.]]></description>
      <pubDate>Mon, 13 Mar 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-002: Adobe Macromedia ShockWave Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-007</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-002/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Macromedia Shockwave. Exploitation requires the target to visit a malicious web site. The following CVEs are assigned: CVE-2005-3525.]]></description>
      <pubDate>Thu, 23 Feb 2006 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-011</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-06-001/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable Clam AntiVirus installations. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-0162.]]></description>
      <pubDate>Thu, 12 Jan 2006 00:00:00 -0600</pubDate>
    </item>
    
  </channel>
</rss>
