<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Mon, 08 Jun 2026 22:38:09 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-07-080: Multiple Vendor Web Console Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-173</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-080/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of TippingPoint IPS and Juniper ScreenOS. Authentication is required to exploit this vulnerability.]]></description>
      <pubDate>Wed, 27 Jan 2010 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-079: Hewlett-Packard HP-UX swagentd Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-201</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-079/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard HP-UX operating system. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-6195.]]></description>
      <pubDate>Mon, 17 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-078: St. Bernard Open File Manager Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-225</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-078/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of St. Bernard Open File Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-6281.]]></description>
      <pubDate>Mon, 17 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-077: Trend Micro ServerProtect StRpcSrv.dll Insecure Method Exposure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-157</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-077/</link>
      <description><![CDATA[These vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of Trend Micro ServerProtect. Authentication is not required to exploit these vulnerabilities. The following CVEs are assigned: CVE-2007-6507.]]></description>
      <pubDate>Mon, 17 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-076: Microsoft Windows Message Queuing Service Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-178</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-076/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows with the Message Queuing Service enabled. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3039.]]></description>
      <pubDate>Tue, 11 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-075: Microsoft Internet Explorer Element Tags Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-230</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-075/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-5344.]]></description>
      <pubDate>Tue, 11 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-074: Microsoft Internet Explorer Node Manipulation Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-189</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-074/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-3903.]]></description>
      <pubDate>Tue, 11 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-073: Microsoft Internet Explorer setExpression Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-229</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-073/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-3902.]]></description>
      <pubDate>Tue, 11 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-072: Novell NetMail AntiVirus Agent Multiple Heap Overflow Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-162</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-072/</link>
      <description><![CDATA[These vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of Novell NetMail. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-6302.]]></description>
      <pubDate>Mon, 10 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-071: Hewlett-Packard OpenView Network Node Manager Multiple CGI Buffer Overflow Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-111</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-071/</link>
      <description><![CDATA[These vulnerabilities allow remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard (HP) OpenView Network Node Manager (NNM). Authentication is not required to exploit these vulnerabilities. The following CVEs are assigned: CVE-2007-6204.]]></description>
      <pubDate>Thu, 06 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-070: Skype URI Handler Remote Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-236</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-070/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-5989.]]></description>
      <pubDate>Thu, 06 Dec 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-069: CA BrightStor ARCserve Backup Message Engine Insecure Method Exposure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-143</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-069/</link>
      <description><![CDATA[This vulnerability allows attackers to arbitrarily access and modify the file system and registry of vulnerable installations of Computer Associates BrightStor ARCserve Backup. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-5328.]]></description>
      <pubDate>Mon, 26 Nov 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-068: Apple QuickTime Uncompressedfile Opcode Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-242</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-068/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious image file. The following CVEs are assigned: CVE-2007-4672.]]></description>
      <pubDate>Mon, 05 Nov 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-067: Apple QuickTime PICT File Poly Opcodes Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-241</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-067/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-4676.]]></description>
      <pubDate>Mon, 05 Nov 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-066: Apple Quicktime PICT File PackBitsRgn Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-240</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-066/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-4676.]]></description>
      <pubDate>Mon, 05 Nov 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-065: Apple QuickTime Color Table RGB Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-239</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-065/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2007-4677.]]></description>
      <pubDate>Mon, 05 Nov 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-064: Novell Client Trust Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-199</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-064/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell software which utilize the Novell Client Trust. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-5767.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-063: RealPlayer RA Field Size File Processing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-150</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-063/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of RealPlayer. User interaction is required in that a user must open a malicious .ra/.ram file or visit a malicious web site. The following CVEs are assigned: CVE-2007-2264.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-062: RealNetworks RealPlayer PLS File Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-148</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-062/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of RealPlayer. User interaction is required in that a user must open a malicious .pls file or visit a malicious web site. The following CVEs are assigned: CVE-2007-4599.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-061: RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-141</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-061/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the RealNetworks RealPlayer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-2263.]]></description>
      <pubDate>Fri, 02 Nov 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-060: Hewlett-Packard OpenView Radia Integration Server File System Exposure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-134</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-060/</link>
      <description><![CDATA[This vulnerability allows remote attackers to access arbitrary files on systems with vulnerable installations of Hewlett-Packard OpenView Radia Integration Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-5413.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-059: Verity KeyView SDK Multiple File Format Parsing Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-047</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-059/</link>
      <description><![CDATA[Several vulnerabilities exist in the popular Verity KeyView SDK used in many enterprise applications like IBM Lotus Notes. When parsing several different file formats a standard stack overflow occurs allowing a malicious user to gain complete control of the affected machine under the rights of the currently logged in user. The problem lies when copying user supplied data to a stack based buffer without any boundary conditions. The following CVEs are assigned: CVE-2007-5909.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-058: Oracle E-Business Suite SQL Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-159</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-058/</link>
      <description><![CDATA[This vulnerability allows remote attackers to inject arbitrary SQL on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-5766.]]></description>
      <pubDate>Wed, 31 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-057: Firebird process_packet() Remote Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-237</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-057/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Firebird SQL server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-4992.]]></description>
      <pubDate>Wed, 10 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-056: IBM DB2 DB2JDS Multiple Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-125</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-056/</link>
      <description><![CDATA[The most severe of these vulnerabilities allows remote attackers to execute arbitrary code on vulnerable installations of IBM DB2 Universal Database. Authentication is not required to exploit these vulnerabilities. The following CVEs are assigned: CVE-2007-2582.]]></description>
      <pubDate>Wed, 10 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-055: Microsoft Windows DCERPC Authentication Denial of Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-164</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-055/</link>
      <description><![CDATA[This vulnerability allows remote attackers to crash systems with vulnerable installations of the Microsoft Windows operating system. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2228.]]></description>
      <pubDate>Wed, 10 Oct 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-054: IBM Tivoli Storage Manager Express CAD Service Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-188</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-054/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager Express. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-4880.]]></description>
      <pubDate>Mon, 24 Sep 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-053: Microsoft ISA Server SOCKS4 Proxy Connection Leakage Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-018</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-053/</link>
      <description><![CDATA[This vulnerability allows remote attackers to extract IP addresses visited through the SOCKS4 Proxy on vulnerable ISA Server installations. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-4991.]]></description>
      <pubDate>Thu, 20 Sep 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-052: Multiple Kerberos Implementations Authentication Context Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-208</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-052/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of MIT Kerberos. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3999.]]></description>
      <pubDate>Wed, 12 Sep 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-051: Trend Micro ServerProtect TMregChange() Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-217</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-051/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Server Protect. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-4731.]]></description>
      <pubDate>Fri, 07 Sep 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-050: Trend Micro ServerProtect RPCFN_SetComputerName() Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-215</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-050/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro ServerProtect. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-4218.]]></description>
      <pubDate>Fri, 07 Sep 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-049: EMC Legato Networker Remote Exec Service Stack Overflow Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-170</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-049/</link>
      <description><![CDATA[These vulnerabilities allow remote attackers to execute arbitrary code on vulnerable installations of EMC Networker. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3618.]]></description>
      <pubDate>Mon, 20 Aug 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-048: Microsoft Internet Explorer substringData Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-096</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-048/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Microsoft software User interaction is required to exploit this vulnerability in that the target must visit a malicious page.  The following CVEs are assigned: CVE-2007-2223.]]></description>
      <pubDate>Tue, 14 Aug 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-047: Microsoft Windows Media Player Malformed Skin Header Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-198</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-047/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-3035.]]></description>
      <pubDate>Tue, 14 Aug 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-046: Microsoft Windows Media Player Skin Parsing Size Mismatch Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-182</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-046/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-3037.]]></description>
      <pubDate>Tue, 14 Aug 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-045: Novell Client NWSPOOL.DLL Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-146</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-045/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the Novell Netware Client. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2954.]]></description>
      <pubDate>Mon, 06 Aug 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-044: BakBone NetVault Reporter Scheduler Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-147</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-044/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with affected installations of BakBone NetVault Reporter. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3911.]]></description>
      <pubDate>Wed, 25 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-043: Ipswitch IMail IMAP Daemon SUBSCRIBE Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-179</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-043/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Ipswitch IMail and ICS server. Authentication is required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2795.]]></description>
      <pubDate>Thu, 19 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-042: Ipswitch IMail Server GetIMailHostEntry Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-166</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-042/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Ipswitch IMail and ICS server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2795.]]></description>
      <pubDate>Thu, 19 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-041: Panda Software AdminSecure Agent Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-127</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-041/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on affected installations of Panda AdminSecure. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3026.]]></description>
      <pubDate>Fri, 20 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-040: Symantec AntiVirus Engine CAB Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-124</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-040/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with affected installations of Symantec&#x27;s AntiVirus Engine. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0447.]]></description>
      <pubDate>Thu, 12 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-039: Symantec AntiVirus Engine RAR File Parsing DoS Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-097</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-039/</link>
      <description><![CDATA[This vulnerability allows attackers to create a denial of service condition on software with vulnerable installations of the Symantec&#x27;s AntiVirus engine. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-3699.]]></description>
      <pubDate>Thu, 12 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-038: Microsoft Internet Explorer Prototype Dereference Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-168</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-038/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-1751.]]></description>
      <pubDate>Tue, 12 Jun 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-037: Microsoft Internet Explorer Language Pack Installation Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-119</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-037/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-3027.]]></description>
      <pubDate>Tue, 12 Jun 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-036: Arris Cadant C3 CMTS Remote DoS Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-149</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-036/</link>
      <description><![CDATA[This vulnerability allows remote attackers to cause a denial of service on vulnerable Arris Cadant C3 CMTS systems. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2796.]]></description>
      <pubDate>Mon, 11 Jun 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-035: CA Multiple Product AV Engine CAB Header Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-154</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-035/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on The following CVEs are assigned: CVE-2007-2864.]]></description>
      <pubDate>Tue, 05 Jun 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-034: CA Multiple Product AV Engine CAB Filename Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-123</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-034/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Computer Associates products. The following CVEs are assigned: CVE-2007-2863.]]></description>
      <pubDate>Tue, 05 Jun 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-033: Samba lsa_io_trans_names Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-197</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-033/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Samba. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2446.]]></description>
      <pubDate>Wed, 11 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-032: Samba sec_io_acl Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-194</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-032/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Samba. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2446.]]></description>
      <pubDate>Wed, 11 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-031: Samba smb_io_notify_option_type_data Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-193</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-031/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Samba. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2446.]]></description>
      <pubDate>Wed, 11 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-030: Samba netdfs_io_dfs_EnumInfo_d Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-192</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-030/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Samba. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2446.]]></description>
      <pubDate>Wed, 11 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-029: Samba lsa_io_privilege_set Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-191</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-029/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Samba. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2446.]]></description>
      <pubDate>Wed, 11 Jul 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-028: CA eTrust AntiVirus Server inoweb Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-104</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-028/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates AntiVirus Server. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2522.]]></description>
      <pubDate>Thu, 10 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-027: Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-098</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-027/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-0944.]]></description>
      <pubDate>Tue, 08 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-131</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-026/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The following CVEs are assigned: CVE-2007-0215.]]></description>
      <pubDate>Tue, 08 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-025: Trend Micro ServerProtect AgRpcCln.dll Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-156</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-025/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Trend Micro ServerProtect. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2508.]]></description>
      <pubDate>Mon, 07 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-024: Trend Micro ServerProtect EarthAgent Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-155</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-024/</link>
      <description><![CDATA[These vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of Trend Micro ServerProtect. Authentication is not required to exploit these vulnerabilities. The following CVEs are assigned: CVE-2007-2508.]]></description>
      <pubDate>Mon, 07 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-023: Apple QTJava toQTPointer() Pointer Arithmetic Memory Overwrite Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-190</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-023/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on systems with vulnerable installations of Apple&#x27;s QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-2175.]]></description>
      <pubDate>Tue, 01 May 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-022: CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-171</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-022/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Media Server. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2139.]]></description>
      <pubDate>Tue, 24 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-087</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-021/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of GraceNote&#x27;s CDDBControl ActiveX Control. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-0443.]]></description>
      <pubDate>Thu, 19 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-020: BMC Performance Manager SNMP Command Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-153</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-020/</link>
      <description><![CDATA[These vulnerabilities allows attackers to execute arbitrary code on vulnerable installations of BMC Performance Manager. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-1972.]]></description>
      <pubDate>Wed, 18 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-019: BMC Patrol PerformAgent bgs_sdservice Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-151</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-019/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of BMC Patrol. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2136.]]></description>
      <pubDate>Wed, 18 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-018: IBM Tivoli Monitoring Express Universal Agent Heap Overflow Vunlerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-069</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-018/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Monitoring Express. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2137.]]></description>
      <pubDate>Tue, 17 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-017: Oracle E-Business Suite Arbitrary Document Download Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-132</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-017/</link>
      <description><![CDATA[This vulnerability allows remote attackers to download any existing document in the APPS.FND_DOCUMENTS table on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2135.]]></description>
      <pubDate>Wed, 18 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-016: Oracle E-Business Suite Arbitrary Node Deletion Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-136</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-016/</link>
      <description><![CDATA[This vulnerability allows remote attackers to delete any existing Document Management node on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2170.]]></description>
      <pubDate>Tue, 17 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-015: Novell Groupwise WebAccess Base64 Decoding Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-181</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-015/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Groupwise WebAccess. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2171.]]></description>
      <pubDate>Wed, 18 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-014: Kaspersky Antivirus ActiveX Unsafe Methods Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-138</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-014/</link>
      <description><![CDATA[This vulnerability allows remote attackers to download and remove any file on vulnerable installations of Kaspersky Anti-Virus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-1112.]]></description>
      <pubDate>Thu, 05 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-113</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-013/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with affected installations of the Kaspersky Anti-Virus Engine. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0445.]]></description>
      <pubDate>Thu, 05 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-110</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-012/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Yahoo Messenger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-1680.]]></description>
      <pubDate>Tue, 03 Apr 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-011: IBM Lotus Domino IMAP Server CRAM-MD5 Authentication Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-060</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-011/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Domino Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-1675.]]></description>
      <pubDate>Wed, 28 Mar 2007 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-010: Apple Quicktime UDTA Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-093</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-010/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2007-0714.]]></description>
      <pubDate>Wed, 07 Mar 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-009: Novell Netmail WebAdmin Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-133</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-009/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell NetMail. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-1350.]]></description>
      <pubDate>Wed, 07 Mar 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-008: Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-152</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-008/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apache Tomcat JK Web Server Connector. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0774.]]></description>
      <pubDate>Fri, 02 Mar 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-007: Hewlett-Packard Mercury LoadRunner Agent Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-112</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-007/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Mercury LoadRunner Agent, Mercury Performance Center Agent and Mercury Monitor over Firewall. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0446.]]></description>
      <pubDate>Thu, 08 Feb 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-101</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-006/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of Citrix Presentation Server, Metaframe Presentation Server or MetaFrame XP. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0444.]]></description>
      <pubDate>Wed, 24 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-054</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-005/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java Virtual Machine (JVM). User interaction is required to exploit this vulnerability in that the target must visit a malicious website. The following CVEs are assigned: CVE-2007-0243.]]></description>
      <pubDate>Tue, 16 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-130</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-004/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0169.]]></description>
      <pubDate>Thu, 11 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-129</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-003/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0169.]]></description>
      <pubDate>Thu, 11 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-118</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-002/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-0168.]]></description>
      <pubDate>Thu, 11 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-07-001: QUALCOMM Eudora WorldMail Remote Management Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-073</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-07-001/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Eudora WorldMail. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2006-6336.]]></description>
      <pubDate>Fri, 05 Jan 2007 00:00:00 -0600</pubDate>
    </item>
    
  </channel>
</rss>
