<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Mon, 08 Jun 2026 22:38:55 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-09-101: Novell ZENworks Desktop Management Installation Service Remote Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-450</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-101/</link>
      <description><![CDATA[This vulnerability allows remote attackers to impersonate valid users in vulnerable installations of Novell ZENworks Desktop Management. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Mon, 30 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-100: IBM DB2 Universal Database Multiple SQL Functions Remote Code Execution Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-488</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-100/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM DB2. Authentication is required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 15 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-099: Hewlett-Packard OpenView Data Protector Backup Client Service Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-105</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-099/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Storage Data Protector. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2007-2280.]]></description>
      <pubDate>Thu, 17 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-098: Symantec Multiple Products VRTSweb.exe Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-456</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-098/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of multiple Symantec products. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3027.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-097: Hewlett-Packard OpenView NNM nnmRptConfig.exe Template Variable strcat Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-523</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-097/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3849.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-096: Hewlett-Packard OpenView NNM nnmRptConfig.exe Template Variable vsprintf Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-522</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-096/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3848.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-095: Hewlett-Packard OpenView NNM Snmp.exe Oid Variable Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-518</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-095/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3849.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-094: Hewlett-Packard OpenView NNM Multiple Command Injection Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-453</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-094/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard&#x27;s Network Node Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3845.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-093: Adobe Flash Player ActionScript Exception Handler Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-392</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-093/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page or open a malicious SWF file. The following CVEs are assigned: CVE-2009-3799.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-092: Adobe Flash Player JPEG Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-517</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-092/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page or open a malicious SWF file. The following CVEs are assigned: CVE-2009-3794.]]></description>
      <pubDate>Wed, 09 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-091: Hewlett-Packard Application Recovery Manager MSG_PROTOCOL Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-503</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-091/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerability installations of HP Application Recovery Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3844.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-090: Microsoft Windows Intel Indeo Codec Parsing Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-432</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-090/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-4310.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-089: Microsoft Windows Intel Indeo Codec Parsing Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-314</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-089/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-4309.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-088: Microsoft Internet Explorer IFrame Attributes Circular Reference Dangling Pointer Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-547</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-088/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. The following CVEs are assigned: CVE-2009-3674.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-087: Microsoft Internet Explorer CSS Race Condition Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-541</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-087/</link>
      <description><![CDATA[This vulnerability allows remote attackers to potentially execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-3673.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-086: Microsoft Internet Explorer XHTML DOM Manipulation Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-496</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-086/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required in that a user must visit a malicious web page. The following CVEs are assigned: CVE-2009-3671.]]></description>
      <pubDate>Tue, 08 Dec 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-618</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-085/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Operations Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3843.]]></description>
      <pubDate>Fri, 20 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-084: Apple Quicktime FIRE Codec Heap Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-481</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-084/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0954.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-083: Microsoft Excel Shared Feature Header Pointer Offset Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-587</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-083/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious spreadsheet. The following CVEs are assigned: CVE-2009-3129.]]></description>
      <pubDate>Tue, 10 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-082: Microsoft Office Excel PivotTable Cache Record Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-567</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-082/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious document. The following CVEs are assigned: CVE-2009-3127.]]></description>
      <pubDate>Tue, 10 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-492</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-081/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Power Manager. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-2685.]]></description>
      <pubDate>Thu, 05 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-562</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-080/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun&#x27;s Java Runtime Environment. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-3874.]]></description>
      <pubDate>Wed, 04 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-551</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-079/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Runtime Environment. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-3871.]]></description>
      <pubDate>Wed, 04 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-078: Sun Java Runtime AWT setDifflCM Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-550</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-078/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Runtime Environment. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-3869.]]></description>
      <pubDate>Wed, 04 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-077: Sun Java Web Start Arbitrary Command Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-505</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-077/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java WebStart. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-3866.]]></description>
      <pubDate>Wed, 04 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-076: Sun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-491</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-076/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java. User interaction is required in that a user must open a malicious file or visit a malicious web page. The following CVEs are assigned: CVE-2009-3867.]]></description>
      <pubDate>Wed, 04 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-075: Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-513</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-075/</link>
      <description><![CDATA[This vulnerability allows attackers to deny services on vulnerable installations of Novell eDirectory. Authentication is not required in order to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3862.]]></description>
      <pubDate>Mon, 02 Nov 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-074: Multiple Vendor Hummingbird STR Service Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-369</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-074/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC Documentum eRoom, OpenText Hummingbird and OpenText Search Server. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Wed, 28 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-073: Adobe Reader Compact Font Format Malformed Index Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-479</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-073/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-2985.]]></description>
      <pubDate>Tue, 13 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-072: Microsoft Windows GDI+ TIFF Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-605</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-072/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a user must open a malicious image file or browse to a malicious website. The following CVEs are assigned: CVE-2009-2503.]]></description>
      <pubDate>Tue, 13 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-071: Microsoft Internet Explorer writing-mode Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-494</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-071/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required in that a user must visit a malicious web page. The following CVEs are assigned: CVE-2009-2531.]]></description>
      <pubDate>Tue, 13 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-070: Microsoft Internet Explorer Event Object Type Double-Free Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-489</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-070/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-2530.]]></description>
      <pubDate>Tue, 13 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-069: Microsoft Windows Media Player Audio Voice Sample Rate Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-320</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-069/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. The following CVEs are assigned: CVE-2009-0555.]]></description>
      <pubDate>Tue, 13 Oct 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-068: EMC RepliStor Server Service DoASOCommand Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-452</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-068/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC RepliStor. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1120.]]></description>
      <pubDate>Tue, 07 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-067: Novell NetWare NFS Portmapper and RPC Module Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-497</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-067/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware NFS Portmapper daemon. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Wed, 30 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-066: Adobe RoboHelp Server Arbitrary File Upload and Execute Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-504</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-066/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerability installations of Adobe RoboHelp Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-3068.]]></description>
      <pubDate>Wed, 23 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-065: Mozilla Firefox TreeColumns Dangling Pointer Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-536</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-065/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-3077.]]></description>
      <pubDate>Thu, 10 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-064: Apple QuickTime FlashPix Sector Size Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-524</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-064/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-2798.]]></description>
      <pubDate>Thu, 10 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-063: Apple QuickTime H.264 Nal Unit Length Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-500</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-063/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-2799.]]></description>
      <pubDate>Thu, 10 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-062: Microsoft Internet Explorer JScript arguments Invocation Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-482</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-062/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1920.]]></description>
      <pubDate>Tue, 08 Sep 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-061: Symantec Multiple Product Intel Alert Originator Service Invalid Length Check Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-246</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-061/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec AntiVirus Corporate Edition, Symantec Client Security and Symantec Endpoint Protection. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1430.]]></description>
      <pubDate>Tue, 28 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-060: Symantec Multiple Product Intel Alert Originator Service Command Execution Vulnerabilty]]></title>
      <guid isPermaLink="false">ZDI-CAN-174</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-060/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec AntiVirus Corporate Edition, Symantec Client Security and Symantec Endpoint Protection. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1429.]]></description>
      <pubDate>Tue, 28 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-442</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-059/</link>
      <description><![CDATA[This vulnerability allows remote attackers to inject arbitrary commands on vulnerable installations of Oracle Secure Backup. User interaction is not required to exploit this vulnerability but an attacker must be authenticated. The following CVEs are assigned: CVE-2009-1978.]]></description>
      <pubDate>Tue, 18 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-443</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-058/</link>
      <description><![CDATA[This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Oracle Secure Backup. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1977.]]></description>
      <pubDate>Tue, 18 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-057: Microsoft Remote Desktop Client Arbitrary Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-301</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-057/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft&#x27;s Remote Desktop Client. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1133.]]></description>
      <pubDate>Tue, 11 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-056: Microsoft Office OWC10.Spreadsheet ActiveX BorderAround() Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-273</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-056/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-2496.]]></description>
      <pubDate>Tue, 11 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-055: Microsoft Office OWC10 ActiveX Control Loading and Unloading Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-186</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-055/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-0562.]]></description>
      <pubDate>Tue, 11 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-054: Microsoft Office OWC10.Spreadsheet ActiveX msDataSourceObject() Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-175</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-054/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1136.]]></description>
      <pubDate>Tue, 11 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-053: Microsoft Windows WINS Service Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-437</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-053/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. Authentication is not required to exploit this vulnerability.  The following CVEs are assigned: CVE-2009-1923.]]></description>
      <pubDate>Tue, 11 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-052: CA Unicenter Software Delivery dtscore.dll Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-233</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-052/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates Unicenter Software Delivery. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-2026.]]></description>
      <pubDate>Fri, 07 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-051: EMC Replication Manager Client Control Service Remove Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-451</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-051/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the EMC Replication Manager Client. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Fri, 07 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-050: Sun Java Web Start JPEG Header Parsing Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-460</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-050/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.]]></description>
      <pubDate>Wed, 05 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-049: Sun Java Pack200 Decoding Inner Class Count Integer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-475</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-049/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Sun Java Runtime. User interaction is required in that a target must visit a malicious web page or open a malicious JNLP file. The following CVEs are assigned: CVE-2009-2675.]]></description>
      <pubDate>Wed, 05 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-048: Microsoft Internet Explorer CSS Behavior Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-484</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-048/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1919.]]></description>
      <pubDate>Wed, 05 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-047: Microsoft Internet Explorer getElementsByTagName Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-483</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-047/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1918.]]></description>
      <pubDate>Wed, 05 Aug 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-046: Novell Privileged User Manager Remote DLL Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-493</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-046/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Novell&#x27;s Privileged User Manager. Authentication is not required to exploit this vulnerability.]]></description>
      <pubDate>Tue, 21 Jul 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-389</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-045/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a target must visit a malicious page or open a malicious video file. The following CVEs are assigned: CVE-2009-1539.]]></description>
      <pubDate>Tue, 14 Jul 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-044: Adobe Shockwave Player Director File Parsing Pointer Overwrite Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-327</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-044/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe&#x27;s Shockwave Player. User interaction is required in that a user must visit a malicious web site. The following CVEs are assigned: CVE-2009-1860.]]></description>
      <pubDate>Wed, 24 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-043: Apple Java CColourUIResource Pointer Dereference Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-416</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-043/</link>
      <description><![CDATA[his vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Java HotSpot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1719.]]></description>
      <pubDate>Tue, 16 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-042: Adobe Reader U3D RHAdobeMeta Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-433</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-042/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious web address or open a malicious file. The following CVEs are assigned: CVE-2009-1855.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-041: Microsoft Internet Explorer 8 Rows Property Dangling Pointer Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-463</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-041/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer 8. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1532.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-040: Microsoft Office Excel QSIR Record Pointer Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-454</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-040/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires user interaction in that a victim must open a malicious XLS file. The following CVEs are assigned: CVE-2009-1134.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-039: Microsoft Internet Explorer onreadystatechange Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-429</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-039/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1531.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-038: Microsoft Internet Explorer Event Handler Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-428</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-038/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1530.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-037: Microsoft Internet Explorer Concurrent Ajax Request Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-426</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-037/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1528.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-036: Microsoft Internet Explorer setCapture Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-425</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-036/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1529.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-035: Microsoft Word Document Stack Based Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-365</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-035/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious e-mail, or open a malicious file. The following CVEs are assigned: CVE-2009-0563.]]></description>
      <pubDate>Wed, 10 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-034: Apple Safari SVG Set.targetElement() Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-401</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-034/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1709.]]></description>
      <pubDate>Mon, 08 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-033: Apple WebKit dir Attribute Freeing Dangling Object Pointer Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-430</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-033/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable software utilizing the Apple WebKit library. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1701.]]></description>
      <pubDate>Mon, 08 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-032: Apple WebKit attr() Invalid Attribute Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-441</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-032/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1698.]]></description>
      <pubDate>Mon, 08 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-031: Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-424</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-031/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of messaging applications that make use of the libpurple library. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1376.]]></description>
      <pubDate>Mon, 08 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-030: Apple Quicktime PICT Opcode 0x71 Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-413</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-030/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0010.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-029: Apple QuickTime Jpeg2000 Marker Size Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-480</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-029/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0957.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-028: Apple QuickTime CRGN Atom Parsing Heap Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-414</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-028/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of QuickTime Player. User interaction is required to exploit this vulnerability in that the target must either open a malicious file, or visit a malicious web page. The following CVEs are assigned: CVE-2009-0954.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-027: Apple Quicktime PICT Opcode 0x8201 Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-412</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-027/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0953.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-026: Apple QuickTime Packed-bit Decoding Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-469</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-026/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0952.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-025: Apple Quicktime Picture Viewer FLC Delta-Encoded Frame Decompression Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-402</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-025/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of QuickTime Player. User interaction is required to exploit this vulnerability in that the target must either open a malicious file, or visit a malicious web page. The following CVEs are assigned: CVE-2009-0951.]]></description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-024: Safenet SoftRemote IKE Service Remote Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-399</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-024/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Safenet Softremote IKE VPN service. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1943.]]></description>
      <pubDate>Mon, 01 Jun 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-023: Apple OS X ATSServer Compact Font Format Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-462</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-023/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple OS X. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0154.]]></description>
      <pubDate>Wed, 13 May 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-022: Apple Safari Malformed SVGList Parsing Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-464</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-022/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-0945.]]></description>
      <pubDate>Wed, 13 May 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-021: Apple QuickTime PICT Unspecified Tag Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-470</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-021/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0010.]]></description>
      <pubDate>Wed, 13 May 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-020: Microsoft Office PowerPoint Notes Container Heap Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-355</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-020/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office&#x27;s PowerPoint. User interaction is required to exploit this vulnerability in that the target must open up a malicious file. The following CVEs are assigned: CVE-2009-1130.]]></description>
      <pubDate>Tue, 12 May 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-019: Microsoft Office PowerPoint OutlineTextRefAtom Parsing Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-299</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-019/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office PowerPoint. Exploitation requires that the attacker coerce the target into opening a malicious .PPT file. The following CVEs are assigned: CVE-2009-0556.]]></description>
      <pubDate>Tue, 12 May 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-018: Symantec Multiple Product Intel Alert Originator Service Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-226</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-018/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec AntiVirus Corporate Edition, Symantec Client Security and Symantec Endpoint Protection. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1430.]]></description>
      <pubDate>Tue, 28 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-017: Oracle Applications Server 10g Format String Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-248</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-017/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Applications Server. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-0993.]]></description>
      <pubDate>Tue, 14 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-016: Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-397</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-016/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. A valid IPC$ connection must be established in order to exploit this vulnerability. The following CVEs are assigned: CVE-2009-1350.]]></description>
      <pubDate>Mon, 06 Apr 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-015: Mozilla Firefox XUL _moveToEdgeShift() Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-465</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-015/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-1044.]]></description>
      <pubDate>Mon, 30 Mar 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-014: Adobe Acrobat getIcon() Stack Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-362</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-014/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required in that a user must visit a malicious web site or open a malicious file. The following CVEs are assigned: CVE-2009-0927.]]></description>
      <pubDate>Tue, 24 Mar 2009 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-013: Mozilla Firefox XUL Linked Clones Double Free Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-423</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-013/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-0775.]]></description>
      <pubDate>Thu, 05 Mar 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-012: Microsoft Internet Explorer Malformed CSS Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-400</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-012/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-0076.]]></description>
      <pubDate>Tue, 10 Feb 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-011: Microsoft Internet Explorer CFunctionPointer Memory Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-391</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-011/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The following CVEs are assigned: CVE-2009-0075.]]></description>
      <pubDate>Tue, 10 Feb 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-010: Novell Netware Groupwise GWIA RCPT Command Buffer Overflow Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-384</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-010/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware Groupwise SMTP daemon. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-0410.]]></description>
      <pubDate>Mon, 02 Feb 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-009: EMC AutoStart Backbone Engine Trusted Pointer Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-364</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-009/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of EMC AutoStart. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2009-0311.]]></description>
      <pubDate>Fri, 23 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-008: Apple QuickTime STSD JPEG Atom Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-352</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-008/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2009-0007.]]></description>
      <pubDate>Wed, 21 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-344</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-007/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The following CVEs are assigned: CVE-2009-0006.]]></description>
      <pubDate>Wed, 21 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-006: Apple QuickTime AVI Header nBlockAlign Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-393</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-006/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0003.]]></description>
      <pubDate>Wed, 21 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-005: Apple QuickTime VR Track Header Atom Heap Corruption Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-382</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-005/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple Quicktime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The following CVEs are assigned: CVE-2009-0002.]]></description>
      <pubDate>Wed, 21 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-004: Oracle TimesTen evtdump Remote Format String Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-300</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-004/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle TimesTen. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5440.]]></description>
      <pubDate>Wed, 14 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-003: Oracle Secure Backup exec_qr() Command Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-224</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-003/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Secure Backup. Authentication is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-5448.]]></description>
      <pubDate>Wed, 14 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-002: Microsoft SMB NT Trans2 Request Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-379</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-002/</link>
      <description><![CDATA[This vulnerability allows remote attackers to trigger a denial of service condition on vulnerable installations of Microsoft Windows; remote code execution is also theoretically possible. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4835.]]></description>
      <pubDate>Tue, 13 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-09-001: Microsoft SMB NT Trans Request Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-354</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-09-001/</link>
      <description><![CDATA[This vulnerability allows remote attackers to trigger a denial of service condition on vulnerable installations of Microsoft Windows; remote code execution is also theoretically possible. User interaction is not required to exploit this vulnerability. The following CVEs are assigned: CVE-2008-4834.]]></description>
      <pubDate>Tue, 13 Jan 2009 00:00:00 -0600</pubDate>
    </item>
    
  </channel>
</rss>
