<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Mon, 08 Jun 2026 22:38:14 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-08-099: Microsoft Office Excel REPT Formula Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-357</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-099/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, or open a malicious file. The following CVEs are assigned: CVE-2008-4019.]]></description>
      <pubDate>Tue, 14 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-098: AOL AIM SIPFoundry sipXtapi RTP Processing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-279</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-098/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of any communication application utilizing the SIP Foundry API.  This includes vendors such as AOL, Yahoo, Skype, Oracle, Nortel and more.  Authentication is not required to exploit these vulnerabilities, however a user must have a voice session active to expose the flaw.]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-097: AOL AIM SIPFoundry sipXtapi RTCP Processing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-251</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-097/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of AOL AIM. Successful exploitation requires the victim to accept a Video Messaging session with the attacker. ]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-096: EMC ApplicationXtender Workflow Server Admin Agent Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-360</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-096/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC ApplicationXtender Workflow Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-3684.]]></description>
      <pubDate>Thu, 14 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-095: EMC ApplicationXtender Workflow Server Admin Agent Arbitrary File Upload Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-358</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-095/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC ApplicationXtender Workflow Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-3685.]]></description>
      <pubDate>Thu, 14 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-094: Mozilla Firefox Flash Player Dynamic Module Unloading Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-259</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-094/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of Mozilla Firefox with Adobe&#x27;s Flash Player. User interaction is required in that a user must visit a malicious web site.  The following CVEs are assigned: CVE-2008-5013.]]></description>
      <pubDate>Wed, 12 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-093: Mozilla Firefox Input Box Type Property Dangling Pointer Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-390</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-093/</link>
      <description><![CDATA[This vulnerability allows attackers to potentially execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-5021.]]></description>
      <pubDate>Wed, 12 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-092: Adobe Flash Script Injection Cross Domain Scripting Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-268</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-092/</link>
      <description><![CDATA[This vulnerability allows remote attackers to inject scripts across domains through vulnerable versions of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2007-6637.]]></description>
      <pubDate>Tue, 08 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-091: RealNetworks Helix Server NTLM Authentication Malformed Base64 Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-380</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-091/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of RealNetworks Helix Server. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 16 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-090: RealNetworks Helix Server DataConvertBuffer Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-333</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-090/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of RealNetworks Helix Server. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 16 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-089: RealNetworks Helix DNA Server RTSP DESCRIBE Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-293</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-089/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of RealNetworks Helix Server. User interaction is not required to exploit this vulnerability. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 16 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-088: Oracle E-Business Suite Business Intelligence SQL Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-160</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-088/</link>
      <description><![CDATA[This vulnerability allows remote attackers to inject arbitrary SQL on vulnerable installations of Oracle E-Business Suite Business Intelligence. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 16 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-087: Microsoft Internet Explorer Webdav Request Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-331</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-087/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer 7 on the Microsoft Vista operating system. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-4259.]]></description>
      <pubDate>Tue, 09 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-086: Microsoft Office Word Document Table Property Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-377</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-086/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Word. Exploitation requires that the attacker coerce the target into opening a malicious .DOC file. The following CVEs are assigned: CVE-2008-4837.]]></description>
      <pubDate>Tue, 09 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-085: Microsoft Office RTF Drawing Object Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-351</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-085/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Microsoft products including Word and Outlook. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious e-mail, or open a malicious file. The following CVEs are assigned: CVE-2008-4028.]]></description>
      <pubDate>Tue, 09 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-084: Microsoft Office RTF Consecutive Drawing Object Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-334</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-084/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious e-mail, or open a malicious file. The following CVEs are assigned: CVE-2008-4027.]]></description>
      <pubDate>Tue, 09 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-083: Microsoft Animation ActiveX Control Malformed AVI Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-387</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-083/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code through vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-4255.]]></description>
      <pubDate>Tue, 09 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-082: BMC PatrolAgent Version Logging Format String Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-325</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-082/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of BMC PatrolAgent. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5982.]]></description>
      <pubDate>Mon, 08 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-081: Sun Java Web Start and Applet Multiple Sandbox Bypass Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-363</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-081/</link>
      <description><![CDATA[These vulnerabilities allow remote attackers to bypass sandbox restrictions on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-5339.]]></description>
      <pubDate>Thu, 04 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-080: Sun Java AWT Library Sandbox Violation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-319</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-080/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java. User interaction is required in that a user must open a malicious file or visit a malicious web page. The following CVEs are assigned: CVE-2008-5359.]]></description>
      <pubDate>Thu, 04 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-079: Trillian AIM Plugin Malformed XML Tag Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-410</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-079/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cerulean Studios Trillian. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5403.]]></description>
      <pubDate>Thu, 04 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-078: Trillian IMG SRC ID Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-409</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-078/</link>
      <description><![CDATA[This vulnerability allows remote attackers to potentially execute arbitrary code on vulnerable installations of Cerulean Studios Trillian. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5402.]]></description>
      <pubDate>Thu, 04 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-077: Trillian AIM IMG Tag Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-408</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-077/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cerulean Studios Trillian. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5401.]]></description>
      <pubDate>Thu, 04 Dec 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-076: EMC Control Center SST_SENDFILE Remote File Retrieval Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-406</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-076/</link>
      <description><![CDATA[This vulnerability allows remote attackers to retrieve arbitrary files on systems with vulnerable installations of EMC Control Center. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5420.]]></description>
      <pubDate>Thu, 20 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-075: EMC Control Center SST_CTGTRANS Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-398</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-075/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC Control Center. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5419.]]></description>
      <pubDate>Thu, 20 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-074: Adobe Acrobat PDF Javascript getCosObj Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-329</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-074/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe Acrobat. User interaction is required in that a user must visit a malicious web site. The following CVEs are assigned: CVE-2008-4813.]]></description>
      <pubDate>Tue, 04 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-073: Adobe Acrobat Reader Malformed PDF Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-302</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-073/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious web address or open a malicious file. The following CVEs are assigned: CVE-2008-4813.]]></description>
      <pubDate>Tue, 04 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-072: Adobe Acrobat PDF Javascript printf Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-283</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-072/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-2992.]]></description>
      <pubDate>Tue, 04 Nov 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-071: IBM Tivoli Storage Manager Express for Microsoft SQL Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-321</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-071/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager Express for Microsoft SQL. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4801.]]></description>
      <pubDate>Thu, 30 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-070: SonicWALL Content-Filtering Universal Script Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-350</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-070/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute a script injection attack on arbitrary sites through vulnerable installations of SonicWALL. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page or open a malicious web link. The following CVEs are assigned: CVE-2008-4918.]]></description>
      <pubDate>Thu, 30 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-069: Microsoft Internet Explorer componentFromPoint Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-353</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-069/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-3475.]]></description>
      <pubDate>Tue, 14 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-068: Microsoft Office Excel BIFF File Format Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-345</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-068/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the victim to open the malformed BIFF (.xls) document.  The following CVEs are assigned: CVE-2008-3471.]]></description>
      <pubDate>Tue, 14 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-067: Apple CUPS HP-GL/2 Filter Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-367</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-067/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple CUPS. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-3641.]]></description>
      <pubDate>Thu, 09 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-066: Novell eDirectory Core Protocol Opcode 0x24 Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-335</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-066/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4480.]]></description>
      <pubDate>Wed, 08 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-065: Novell eDirectory Core Protocol Opcode 0x0F Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-336</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-065/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4478.]]></description>
      <pubDate>Wed, 08 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-064: Novell eDirectory dhost.exe Accept Language Header Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-313</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-064/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4479.]]></description>
      <pubDate>Wed, 08 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-063: Novell eDirectory dhost.exe Content-Length Header Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-312</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-063/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4478.]]></description>
      <pubDate>Wed, 08 Oct 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-062: Apple QuickTime MDAT Frame Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-339</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-062/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3627.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-061: Apple QuickTime Player H.264 Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-309</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-061/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3627.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-060: Apple QuickTime AVC1 Atom Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-304</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-060/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3627.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-059: Apple QuickTime STSZ Atom Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-328</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-059/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3626.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-058: Apple QuickTime Panorama PDAT Atom Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-356</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-058/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3625.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-057: Apple QuickTime IV32 Codec Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-376</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-057/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3635.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-056: Microsoft Windows GDI+ GIF Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-249</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-056/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows XP, Server and Vista. User interaction is required in that a user must open a malicious image file or browse to a malicious website. The following CVEs are assigned: CVE-2008-3013.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-055: Microsoft Windows GDI+ BMP Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-211</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-055/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows XP, Server and Vista. User interaction is required in that a user must open a malicious image file. The following CVEs are assigned: CVE-2008-3015.]]></description>
      <pubDate>Tue, 09 Sep 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-054: Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-338</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-054/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of messaging applications that make use of the libpurple library. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2927.]]></description>
      <pubDate>Thu, 28 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-053: Symantec Veritas Storage Foundation Scheduler Service NULL Session Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-359</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-053/</link>
      <description><![CDATA[This vulnerability allows an attacker to execute arbitrary code on vulnerable installations of Symantec Veritas Storage Foundation. User interaction is not required to exploit this vulnerability. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-3703.]]></description>
      <pubDate>Thu, 14 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-052: OpenLDAP BER Decoding Remote DoS Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-347</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-052/</link>
      <description><![CDATA[This vulnerability allows remote attackers to deny services on vulnerable installations of OpenLDAP. Authentication is not required to exploit this vulnerability.  The following CVEs are assigned: CVE-2008-2952.]]></description>
      <pubDate>Thu, 14 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-051: Microsoft Internet Explorer  Table Layout Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-308</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-051/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-2258.]]></description>
      <pubDate>Tue, 12 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-050: Microsoft Internet Explorer XHTML Rendering Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-322</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-050/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-2257.]]></description>
      <pubDate>Tue, 12 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-049: Microsoft Windows Graphics Rendering Engine PICT Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-103</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-049/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2008-3021.]]></description>
      <pubDate>Tue, 12 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-048: Microsoft Excel COUNTRY Record Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-307</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-048/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The following CVEs are assigned: CVE-2008-3006.]]></description>
      <pubDate>Tue, 12 Aug 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-047: RealNetworks RealPlayer rmoc3260 ActiveX Control Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-270</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-047/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of RealPlayer. User interaction is required in that a user must visit a malicious web site. The following CVEs are assigned: CVE-2008-1309.]]></description>
      <pubDate>Fri, 25 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-046: RealNetworks RealPlayer Library File Deletion Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-231</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-046/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the RealNetworks RealPlayer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-3066.]]></description>
      <pubDate>Fri, 25 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-045: Apple Safari StyleSheet ownerNode Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-332</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-045/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-2317.]]></description>
      <pubDate>Fri, 25 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-044: Mozilla Firefox CSSValue Array Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-349</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-044/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-2785.]]></description>
      <pubDate>Thu, 17 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-043: Sun Java Web Start vm args Stack-Based Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-287</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-043/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-3111.]]></description>
      <pubDate>Thu, 17 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-042: Sun Java Web Start Sandbox Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-315</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-042/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-3112.]]></description>
      <pubDate>Thu, 17 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-041: Novell eDirectory dhost Integer Overflow Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-276</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-041/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-3159.]]></description>
      <pubDate>Thu, 10 Jul 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-040: Microsoft DirectX SAMI File Format Name Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-281</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-040/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-1444.]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-039: Microsoft Internet Explorer DOM Object substringData() Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-269</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-039/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-1442.]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-038: Apple QuickTime SMIL qtnext Redirect File Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-326</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-038/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2008-1585.]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-037: Apple QuickTime Indeo Video Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-297</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-037/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple Quicktime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-1584.]]></description>
      <pubDate>Tue, 10 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-036: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-341</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-036/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates eTrust Secure Content Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2541.]]></description>
      <pubDate>Wed, 04 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-035: CA ETrust Secure Content Manager Gateway FTP PASV Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-340</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-035/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates eTrust Secure Content Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2541.]]></description>
      <pubDate>Wed, 04 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-034: Hewlett-Packard StorageWorks Storage Mirroring Authentication Processing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-185</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-034/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett Packard StorageWorks Storage Mirroring. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-1661.]]></description>
      <pubDate>Wed, 04 Jun 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-033: Motorola RAZR JPG Processing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-222</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-033/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable Motorola RAZR firmware based cell phones. User interaction is required to exploit this vulnerability in that the target must accept a malicious image sent via MMS. The following CVEs are assigned: CVE-2008-2548.]]></description>
      <pubDate>Tue, 27 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-032: Adobe Flash DefineSceneAndFrameLabelData Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-280</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-032/</link>
      <description><![CDATA[TippingPoint Note: This issue was originally disclosed on April 8, 2008 as ZDI-08-022 but due to an error on our behalf the original advisory was clobbered and is now being re-released as ZDI-08-032. The following CVEs are assigned: CVE-2007-0071.]]></description>
      <pubDate>Thu, 22 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-031: Trillian MSN MIME Header Stack-Based Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-323</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-031/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cerulean Studios Trillian Pro. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2409.]]></description>
      <pubDate>Wed, 21 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-030: Trillian Multiple Protocol XML Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-311</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-030/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cerulean Studios Trillian Pro. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2408.]]></description>
      <pubDate>Wed, 21 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-029: Trillian AIM.DLL Long HTML Font Parameter Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-275</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-029/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trillian. User interaction is required to exploit this vulnerability in that the target must open a malicious image file. The following CVEs are assigned: CVE-2008-2407.]]></description>
      <pubDate>Wed, 21 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-028: IBM Lotus Sametime Community Services Multiplexer Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-247</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-028/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Sametime. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2499.]]></description>
      <pubDate>Wed, 21 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-027: CA BrightStor ARCserve Backup caloggerd Arbitrary File Writing Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-088</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-027/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Computer Associates ARCserve Backup. Authentication is not required exploit this vulnerability. The following CVEs are assigned: CVE-2008-2241.]]></description>
      <pubDate>Mon, 19 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-026: CA BrightStor ARCserve Backup XDR Parsing Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-063</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-026/</link>
      <description><![CDATA[This vulnerability allws attackers to execute arbitrary code on vulnerable installations of CA BrightStor ARCserve Backup for Linux. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2242.]]></description>
      <pubDate>Mon, 19 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-291</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-025/</link>
      <description><![CDATA[This vulnerability allows attackers to remotely obtain domain credentials on vulnerable installations of Symantec Altiris Deployment Solution. User interaction is not required to exploit this vulnerability. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2291.]]></description>
      <pubDate>Thu, 15 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-290</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-024/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec Altiris Deployment Solution. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-2286.]]></description>
      <pubDate>Thu, 15 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-023: Microsoft Office RTF Parsing Engine Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-284</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-023/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious email, or open a malicious file. The following CVEs are assigned: CVE-2008-1091.]]></description>
      <pubDate>Tue, 13 May 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-022: Apple Safari WebKit PCRE Handling Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-303</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-022/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-1026.]]></description>
      <pubDate>Wed, 16 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-021: Adobe Flash Player DeclareFunction2 Invalid Object Use Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-277</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-021/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe&#x27;s Flash Player. User interaction is required in that a user must visit a malicious web site. The following CVEs are assigned: CVE-2007-6019.]]></description>
      <pubDate>Tue, 08 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-020: Microsoft GDI WMF Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-295</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-020/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a user must open a malicious file or visit a malicious web page. The following CVEs are assigned: CVE-2008-1083.]]></description>
      <pubDate>Tue, 08 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-019: Apple QuickTime Malformed VR obji Atom Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-272</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-019/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2008-1022.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-018: Apple QuickTime Run Length Encoding Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-296</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-018/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-1021.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-017: Apple QuickTime Kodak Encoding Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-289</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-017/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-1020.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-016: Apple QuickTime MP4A Atom Parsing Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-285</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-016/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-1018.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-015: Apple QuickTime Clipping Region Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-292</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-015/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2008-1017.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-014: Apple Quicktime Multiple Opcode Memory Corruption Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-267</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-014/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2008-1019.]]></description>
      <pubDate>Thu, 03 Apr 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-013: Novell eDirectory for Linux LDAP delRequest Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-214</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-013/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory for Linux. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0924.]]></description>
      <pubDate>Wed, 26 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-012: IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-255</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-012/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of IBM&#x27;s Informix Dynamic Server. User interaction is not required to exploit this vulnerability. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0727.]]></description>
      <pubDate>Thu, 13 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-011: IBM Informix Dynamic Server DBPATH Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-254</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-011/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of IBM&#x27;s Informix Dynamic Server. User interaction is not required to exploit this vulnerability. Authentication is required in that an attacker must have database connection priviliges. The following CVEs are assigned: CVE-2008-0727.]]></description>
      <pubDate>Thu, 13 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-010: Java Web Start encoding Stack Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-235</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-010/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-1188.]]></description>
      <pubDate>Wed, 12 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-009: Java Web Start tempbuff Stack Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-234</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-009/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-1188.]]></description>
      <pubDate>Wed, 12 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-008: Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-195</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-008/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The following CVEs are assigned: CVE-2008-0113.]]></description>
      <pubDate>Tue, 11 Mar 2008 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-227</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-007/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec VERITAS Storage Foundation. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0638.]]></description>
      <pubDate>Wed, 20 Feb 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-243</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-006/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2008-0077.]]></description>
      <pubDate>Tue, 12 Feb 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-005: Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-266</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-005/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the Novell Netware Client. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0639.]]></description>
      <pubDate>Mon, 11 Feb 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-004: Adobe Acrobat Javascript for PDF Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-262</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-004/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious web address or open a malicious file. The following CVEs are assigned: CVE-2008-0726.]]></description>
      <pubDate>Mon, 11 Feb 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-253</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-003/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Symantec Backup Exec System Recovery Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0457.]]></description>
      <pubDate>Wed, 06 Feb 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-002: Citrix Metaframe Presentation Server IMA Service Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-212</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-002/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Citrix Presentation Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0356.]]></description>
      <pubDate>Thu, 17 Jan 2008 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-196</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-08-001/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Storage Manager Express. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-0247.]]></description>
      <pubDate>Mon, 14 Jan 2008 00:00:00 -0600</pubDate>
    </item>
    
  </channel>
</rss>
