<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <atom:link href="https://www.zerodayinitiative.com/rss/published/" rel="self" type="application/xml" />
    <title><![CDATA[ZDI: Published Advisories]]></title>
    <link>http://www.zerodayinitiative.com/advisories/published/</link>
    <description><![CDATA[The following is a list of publicly disclosed vulnerabilities discovered by
                   Zero Day Initiative researchers. While the affected vendor is working on a patch for these
                   vulnerabilities, TrendAI customers are protected from exploitation by security filters
                   delivered ahead of public disclosure. All security vulnerabilities that are acquired by the
                   Zero Day Initiative are handled according to the ZDI Disclosure Policy.
        ]]></description>
    <pubDate>Mon, 25 May 2026 11:24:44 -0500</pubDate>
    <copyright>Trend Micro, all rights reserved</copyright>
    <language>en</language>
    
    <item>
      <title><![CDATA[ZDI-13-288: (Pwn2Own) Adobe Flash RTMP Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1826</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-288/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-2555.]]></description>
      <pubDate>Fri, 18 Sep 2015 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-287: (Mobile Pwn2Own) Samsung Apps/WatchON WebView JavaScript Bridge Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-2052</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-287/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Apps and Samsung WatchOn. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-7396.]]></description>
      <pubDate>Tue, 31 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-286: (Mobile Pwn2Own) Apple iOS Safari DocumentOrderedMap Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-2071</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-286/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Webkit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5228.]]></description>
      <pubDate>Fri, 20 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-285: IBM Rational Focal Point RequestAccessController Servlet Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1949</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-285/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Rational Focal Point. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-5398.]]></description>
      <pubDate>Fri, 20 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-284: IBM Rational Focal Point LoginController Servlet Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1948</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-284/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Rational Focal Point. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-5397.]]></description>
      <pubDate>Fri, 20 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-283: EMC Connectrix Manager Converged Network Edition inmservlets.war SoftwareFileUploadMoreInfoServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1751</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-283/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-282: EMC Connectrix Manager Converged Network Edition inmservlets.war Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1749</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-282/</link>
      <description><![CDATA[This vulnerability allows remote attackers to read arbitrary text files on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-281: EMC Connectrix Manager Converged Network Edition inmservlets.war UnifiedFileUploadMoreInfoServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1748</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-281/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-280: EMC Connectrix Manager Converged Network Edition inmservlets.war FileUploadController Servlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1747</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-280/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-279: EMC Connectrix Manager Converged Network Edition FileUploadController Servlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1746</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-279/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition.  Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-278: EMC Connectrix Manager Converged Network Edition inmservlets.war BootFileUploadMoreInfoServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1750</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-278/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2013-6810.]]></description>
      <pubDate>Wed, 18 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-277: Ecava IntegraXor Project Directory Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1988</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-277/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ecava IntegraXor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-276: Cisco WAAS Mobile Server ReportReceiver CAB Processing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1862</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-276/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of CISCO WAAS Mobile Server. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5554.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-275: Adobe Flash Player Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1997</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-275/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5330.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-274: IBM Forms Viewer &#x27;fontname&#x27; Stack Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1976</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-274/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Forms Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5447.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-273: Microsoft Internet Explorer CObjectElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1986</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-273/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5049.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-272: Microsoft Internet Explorer CMarkup::Insert Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1985</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-272/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-5047.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-271: Microsoft Internet Explorer Unitialized Variable Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1980</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-271/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-5048.]]></description>
      <pubDate>Sun, 15 Dec 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-270: ABB MicroSCADA Wserver wserver.exe EXECUTE Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1785</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-270/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ABB MicroSCADA Wserver. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-269: Valve Steam User Chat Message Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1975</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-269/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Valve Steam. No action is necessary on the part of the vulnerable Steam user other than signing on to the Steam service.  The ZDI has assigned a CVSS rating of 6.5.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-268: ABB MicroSCADA Wserver wserver.exe Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1772</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-268/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ABB MicroSCADA Wserver. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-267: Microsoft Internet Explorer CHTMLEditor Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1972</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-267/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3917.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-266:  Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1947</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-266/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3912.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-265: Microsoft Internet Explorer CEditAdorner Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1944</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-265/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3911.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-264: Microsoft Internet Explorer CSelectTracker Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1933</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-264/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3910.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-263: HP SiteScope issueSiebelCmd SOAP Request Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1765</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-263/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP SiteScope. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4835.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-262: HP Application Lifecycle Management GossipService SOAP Request Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1759</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-262/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Application Lifecycle Management. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-4836.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-261: HP Virtual User Generator EmulationAdmin Service getReport Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1851</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-261/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Virtual User Generator. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-4839.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-260: HP Virtual User Generator EmulationAdmin Service saveCodeRuleFile Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1850</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-260/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Virtual User Generator. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4838.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-259: HP Virtual User Generator EmulationAdmin Service copyFileToServer Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1832</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-259/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Virtual User Generator. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4837.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-258: Novell ZENworks umaninv Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1790</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-258/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell ZENworks. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2013-1084.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-257: HP Business Process Monitor tp_bpm_admin.exe Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1802</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-257/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Business Process Monitor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2366.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-256: Cisco Data Center Network Manager downloadServlet Remote Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1768</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-256/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Data Center Network Manager. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-5487.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-255: Cisco Data Center Network Manager fileUploadServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1767</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-255/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Data Center Network Manager. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5486.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-254: Cisco Data Center Network Manager processImageSave_jsp Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1766</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-254/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Data Center Network Manager. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5486.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-253: ABB RobotStudio Tools CWGraph3D ActiveX Control Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1834</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-253/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ABB RobotStudio Tools. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-252: Cogent DataHub Heap Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1981</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-252/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cogent DataHub. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-251: MySQL yaSSL Heap Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1578</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-251/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of MySQL with yaSSL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-1492.]]></description>
      <pubDate>Sun, 24 Nov 2013 00:00:00 -0600</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-250: PANDA Security Communications Agent Service Pagent.exe &#x27;MESSAGE_FROM_REMOTE&#x27; Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1762</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-250/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PANDA Security for Business Communications. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-249: Oracle BPEL Process Manager ScriptServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1761</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-249/</link>
      <description><![CDATA[This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of Oracle BPEL Process Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-3828.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-248: Oracle Java LDAP Deserialization Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1908</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-248/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5830.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-247: Oracle Java FileImageInputStream Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1894</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-247/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5829.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-246: Oracle Java ObjectOutputStream Sandbox Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1880</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-246/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5842.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-245: Oracle Java NumberFormatter and RealTimeSequencer Sandbox Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1878</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-245/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.8. The following CVEs are assigned: CVE-2013-5783.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-244: Oracle Java LdapCtx Sandbox Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1849</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-244/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-5817.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-243: Hewlett-Packard Intelligent Management Center APM monitorId SQL Injection Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1664</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-243/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Intelligent Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-4827.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-242: Hewlett-Packard Intelligent Management Center SOM sdFileDownload Servlet Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1647</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-242/</link>
      <description><![CDATA[This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of Hewlett-Packard Intelligent Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2013-4826.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-241: Hewlett-Packard Intelligent Management Center CommonUtils Static DES/ECB Decryption Key Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1645</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-241/</link>
      <description><![CDATA[This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of Hewlett-Packard Intelligent Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2013-4825.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-240: Hewlett-Packard Intelligent Management Center SOM euAccountService Servlet Authentication Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1644</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-240/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Intelligent Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.4. The following CVEs are assigned: CVE-2013-4824.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-239: Hewlett-Packard Intelligent Management Center BIMS bimsDownload Servlet Information Disclosure Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1607</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-239/</link>
      <description><![CDATA[This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of Hewlett-Packard Intelligent Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2013-4823.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-238: Hewlett-Packard Intelligent Management Center BIMS UploadServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1606</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-238/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Intelligent Management Center. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4822.]]></description>
      <pubDate>Wed, 16 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-237: Microsoft Windows OpenType Font Parsing Persistent Denial-of-Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1754</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-237/</link>
      <description><![CDATA[This vulnerability allows remote attackers to causes a persistent Denial-of-Service on machines running vulnerable versions of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must open a vulnerable font. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2013-3128.]]></description>
      <pubDate>Fri, 11 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-236: Microsoft Internet Explorer CLayout Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1930</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-236/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3872.]]></description>
      <pubDate>Tue, 08 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-235: Microsoft Windows TTF CMAP Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1882</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-235/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.9. The following CVEs are assigned: CVE-2013-3894.]]></description>
      <pubDate>Tue, 08 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-234: Microsoft Internet Explorer CFontElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1942</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-234/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3874.]]></description>
      <pubDate>Tue, 08 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-233: Microsoft Internet Explorer HtmlLayout::SmartObject Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1941</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-233/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3873.]]></description>
      <pubDate>Tue, 08 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-232: Microsoft Internet Explorer CAnchorElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1927</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-232/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3871.]]></description>
      <pubDate>Tue, 08 Oct 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-231: Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1925</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-231/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3846.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-230: Adobe Reader U3D PCX Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1931</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-230/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Reader.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3358.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-229: HP PCM+ and Application Lifecycle Management JBoss Invoker Servlets Marshalled Object Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1760</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-229/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus and Application Lifecycle Management. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4810.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-228: HP PCM+ AgentController Servlet Command Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1745</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-228/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4813.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-227: HP PCM+ GetEventsServlet SQL Injection Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1744</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-227/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4809.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-226: HP PCM+ SNAC Registration Server UpdateDomainControllerServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1743</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-226/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4811.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-225: HP PCM+ SNAC Registration Server UpdateCertificatesServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1742</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-225/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4812.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-224: Microsoft Internet Explorer CHtmParse Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1863</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-224/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3201.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-223: Microsoft Internet Explorer Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1926</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-223/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3203.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-222: Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1924</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-222/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3845.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-221: Microsoft Internet Explorer CSegment Object Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1913</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-221/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3209.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-220: Microsoft Internet Explorer CAtomTable Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1917</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-220/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3208.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-219: Microsoft Internet Explorer CBlockElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1912</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-219/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3207.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-218: Microsoft Internet Explorer CWindow Destructor Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1893</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-218/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3206.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-217: Microsoft Internet Explorer CCaret Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1907</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-217/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3205.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-216: Microsoft Internet Explorer CTreePos Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1909</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-216/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3202.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-215: Microsoft Visio Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1799</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-215/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3863.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-214: IBM Quickr for Domino ActiveX Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1812</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-214/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Quickr for Domino. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3026.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-213: IBM Lotus iNotes ActiveX Control Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1971</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-213/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus iNotes. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3027.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-212: Adobe Reader ToolButton Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1601</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-212/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3346.]]></description>
      <pubDate>Wed, 11 Sep 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-211: (0Day) (Mobile Pwn2Own) Polaris Viewer DOCX VML Shape Tag Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1658</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-211/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable Polaris Viewer. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The ZDI has assigned a CVSS rating of 8.3.]]></description>
      <pubDate>Thu, 29 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-210: ISC BIND rdata Denial Of Service Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1911</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-210/</link>
      <description><![CDATA[This vulnerability allows remote attackers to cause a denial of service condition on vulnerable installations of ISC BIND. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2013-4854.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-209: Hewlett-Packard LoadRunner lrLRIServices ActiveX Control SetOutputDirectory Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1736</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-209/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-4801.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-208: Hewlett-Packard LoadRunner Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1734</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-208/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.6. The following CVEs are assigned: CVE-2013-4799.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-207: Hewlett-Packard LoadRunner lrFileIOService ActiveX Control WriteFileString Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1705</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-207/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-4798.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-206: Hewlett-Packard LoadRunner LrWebIEBrowserMgr.dll ActiveX Control FlushSnapshotToFile Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1690</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-206/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-4797.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-205: Hewlett-Packard SiteScope SOAP Call runOMAgentCommand Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1678</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-205/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP SiteScope. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2367.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-204: Hewlett-Packard System Management iprange Parameter Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1676</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-204/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP System Management. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2362.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-203: Hewlett-Packard LoadRunner lrFileIOService ActiveX Control CreateFileCont Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1670</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-203/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2369.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-202: Hewlett-Packard LoadRunner micWebAjax.dll ActiveX Control NotifyEvent Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1669</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-202/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2368.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-201: Hewlett-Packard Network Node Manager I pmd.exe Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1566</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-201/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Network Node Manager i. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2351.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-200: Hewlett-Packard Application Lifecycle Management Quality Center Multiple Cross-Site Scripting Vulnerabilities]]></title>
      <guid isPermaLink="false">ZDI-CAN-1565</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-200/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of HP Application Lifecycle Management Quality Center. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-4802.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-199: Oracle Database Server SQL QName Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1560</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-199/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Database. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3751.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-198: Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1867</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-198/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3194.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-197: Microsoft Internet Explorer Undo Command Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1859</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-197/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3199.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-196: Microsoft Internet Explorer selectAll/RemoveFormat execCommand Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1858</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-196/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3193.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-195: Microsoft Internet Explorer CFlatMarkupPointer Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1861</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-195/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3184.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-194: Microsoft Internet Explorer CreateMarkupPointer2 Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1922</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-194/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3184.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-193: (Pwn2Own) Microsoft Internet Explorer Protected Mode Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1871</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-193/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 9.3.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-192: (Pwn2Own) Microsoft Windows Shared Data ASLR Security Feature Bypass Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1836</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-192/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-2556.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-191: Oracle Endeca Server attachDataStore SOAP Request Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1787</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-191/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Endeca Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2013-3764.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-190: Oracle Endeca Server createDataStore SOAP Request Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1784</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-190/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Endeca Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2013-3763.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-189: Novell iPrint Client op-client-interface-version Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1533</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-189/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell iPrint Client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2012-0411.]]></description>
      <pubDate>Tue, 13 Aug 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-188: (0Day) PineApp Mail-SeCure test_li_connection.php Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1886</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-188/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-187: (0Day) PineApp Mail-SeCure confpremenu.php Export Log Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1887</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-187/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-186: (0Day) PineApp Mail-SeCure confpremenu.php Install License Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1888</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-186/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-185: (0Day) PineApp Mail-SeCure ldapsyncnow.php Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1889</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-185/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-184: (0Day) PineApp Mail-SeCure livelog.html Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1890</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-184/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-183: (0Day) PineApp Mail-SeCure conflivelog.pl Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1868</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-183/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of PineApp Mail-SeCure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-182: Hewlett-Packard LoadRunner lrFileIOService ActiveX Control WriteFileBinary Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1671</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-182/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2370.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-181: GE Proficy CIMPLICITY CimWebServer Broadcase/Init Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1624</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-181/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of GE Proficy CIMPLICITY. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2785.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-180: GE Proficy CIMPLICITY CimWebServer Password Decode Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1621</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-180/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of GE Proficy CIMPLICITY. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-2785.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-179: Hewlett-Packard LeftHand Virtual SAN Appliance Hydra Login Remote Command Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1510</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-179/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LeftHand Virtual SAN Appliance. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2343.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-178: Cogent Datahub Stack Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1915</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-178/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cogent Datahub. Authentication is not required to exploit this vulnerability.  The ZDI has assigned a CVSS rating of 10.0.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-177: Adobe Flash Player Integer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1879</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-177/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3347.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-176: Microsoft Internet Explorer column-count Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1841</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-176/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3146.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-175: Microsoft Internet Explorer CSpanElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1842</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-175/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3145.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-174: Microsoft Internet Explorer BubbleBecomeCurrent Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1838</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-174/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3147.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-173: Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1837</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-173/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3149.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-172: Microsoft Internet Explorer CTreeNode Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1818</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-172/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3144.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-171: Microsoft Windows win32k.sys Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1873</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-171/</link>
      <description><![CDATA[This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Windows.  User interaction is required to exploit this vulnerability in that the target must run a malicious executable. The ZDI has assigned a CVSS rating of 6.2. The following CVEs are assigned: CVE-2013-1345.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-170: (Pwn2Own) Microsoft Windows NtUserMessageCall Privilege Escalation Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1891</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-170/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.9. The following CVEs are assigned: CVE-2013-1300.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-169: Hewlett-Packard LoadRunner Stack Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1735</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-169/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP LoadRunner. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2013-4800.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-168: Microsoft Windows Media Player WMV Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1592</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-168/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Windows Media Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3127.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-167: Microsoft Internet Explorer RemoveSplice Use-After-Free Remote Code Execution Vulnerabliity]]></title>
      <guid isPermaLink="false">ZDI-CAN-1854</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-167/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3153.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-166: Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1805</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-166/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3152.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-165: Microsoft Internet Explorer CTreeNode Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1847</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-165/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3151.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-164: Microsoft Internet Explorer CElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1848</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-164/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3150.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-163: Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1770</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-163/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3143.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-162: Microsoft Internet Explorer CMshtmlEd Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1843</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-162/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3148.]]></description>
      <pubDate>Fri, 26 Jul 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-161: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 227 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1733</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-161/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2335.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-160: Oracle Java Sequencer Security Manager Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1795</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-160/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6. The following CVEs are assigned: CVE-2013-2448.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-159: Oracle Java ManagedObjectManagerFactory Security Manager Bypass Remote Code Execution Vulnerabillity]]></title>
      <guid isPermaLink="false">ZDI-CAN-1729</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-159/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2013-2455.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-158: Oracle Java AWT Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1820</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-158/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2470.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-157: Oracle Java CMMImageLayout Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1844</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-157/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2464.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-156: Oracle Java AWT Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1846</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-156/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2463.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-155: Oracle Java CMMImageLayout Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1845</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-155/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2469.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-154: Oracle Java ByteComponentRaster Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1831</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-154/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2473.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-153: Oracle Java AWT Memory Corruption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1853</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-153/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2465.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-152: Oracle Java IntegerComponentRaster Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1821</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-152/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2471.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-151: Oracle Java ShortComponentRaster Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1830</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-151/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2472.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-150: Apple QuickTime PICT Image LongComment Opcode Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1620</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-150/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-0975.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-149: Oracle Java cmmColorConvert Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1718</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-149/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-1493.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-148: Oracle Java Runtime Environment AWT mediaLib Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1698</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-148/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-0809.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-147: VMware vCenter Chargeback Manager ImageUploadServlet Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1852</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-147/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of VMware vCenter Chargeback Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-3520.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-146: Microsoft Internet Explorer CTreeNode Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1781</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-146/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3141.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-145: Microsoft Internet Explorer CEventObj Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1769</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-145/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3142.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-144: Microsoft Internet Explorer CCaret Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1819</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-144/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3123.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-143: Microsoft Internet Explorer jsdbgui Buffer Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1806</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-143/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3126.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-142: Oracle Java Image ColorConvert Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1741</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-142/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java Runtime Environment.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-1493.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-141: Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1800</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-141/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3125.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-140: Microsoft Internet Explorer SmartDispClient Type Confusion Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1822</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-140/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3124.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-139: Microsoft Internet Explorer CHtmTagStm Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1808</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-139/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3122.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-138: Microsoft Internet Explorer runtimeStyle Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1803</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-138/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3121.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-137: Microsoft Internet Explorer CSelectedControlAdorner Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1814</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-137/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-3120.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-136: Microsoft Internet Explorer CTreeNode Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1796</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-136/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3119.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-135: Microsoft Internet Explorer CSVGMaskElement Double-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1789</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-135/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3118.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-134: Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1753</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-134/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3112.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-133: Microsoft Internet Explorer CSelectionInteractButtonBehavior Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1771</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-133/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-3111.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-132: Oracle Java KeyStore SecurityManager Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1730</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-132/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Thu, 27 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-131: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 1091 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1681</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-131/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2334.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-130: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 211 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1680</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-130/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2333.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-129: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 260 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1654</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-129/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2332.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-128: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 1092 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1652</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-128/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2331.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-127: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 305 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1638</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-127/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2330.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-126: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 259 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1637</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-126/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2329.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-125: Hewlett-Packard Data Protector Cell Manager crs.exe Multiple Opcodes Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1636</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-125/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2328.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-124: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 264 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1635</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-124/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2327.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-123: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 234 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1634</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-123/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2326.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-122: Hewlett-Packard Data Protector Cell Manager crs.exe Opcode 235 Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1633</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-122/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2325.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-121: Hewlett-Packard Data Protector Cell Manager crs.exe Multiple Opcodes Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1629</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-121/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Data Protector. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-2324.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-120: ABB DataManager National Instruments Multiple ActiveX Controls cwui.ocx ExportStyle() Method Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1554</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-120/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ABB DataManager Data Analysis. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-5021.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-119: Apple QuickTime FlashPix Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1710</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-119/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-0988.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-118: Apple QuickTime Sorenson Video mdat Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1709</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-118/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1019.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-117: Apple QuickTime H.263 Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1604</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-117/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-1016.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-116: Apple QuickTime stsd Atom Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1813</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-116/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1021.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-115: Apple QuickTime mvhd Atom Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1809</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-115/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1022.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-114: Apple QuickTime MJPEG Frame stsd Atom Heap Overflow Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1720</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-114/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1020.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-113: Apple QuickTime 3GP Parsing Remote Code Execution Vunerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1641</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-113/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-1018.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-112: Apple QuickTime TeXML textBox Element Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1628</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-112/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1015.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-111: Apple QuickTime enof Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1603</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-111/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.1. The following CVEs are assigned: CVE-2013-0986.]]></description>
      <pubDate>Tue, 11 Jun 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-110: Apple QuickTime dref Volume Name Parsing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1602</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-110/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1017.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-109: Webkit.org Webkit string.replace Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1517</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-109/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Webkit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-0999.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-108: Webkit.org Webkit string.concat() Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1516</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-108/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Webkit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-0998.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-107: Apple Safari Array Indexing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1704</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-107/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Webkit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-0997.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-106: (Pwn2Own) Adobe Reader Sandbox Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1840</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-106/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-2549, CVE-2013-2550.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-105: Adobe Reader U3D Processing Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1667</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-105/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Reader 10.1.4 on OSX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2727.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-104: Microsoft Internet Explorer CSVGTextElement Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1798</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-104/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-3187.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-103: Microsoft Internet Explorer CDOMTextNode Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1778</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-103/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1312.]]></description>
      <pubDate>Thu, 30 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-102: (Pwn2Own) Microsoft Internet Explorer VML Parsing Remote Code Execution Vulnerabillity]]></title>
      <guid isPermaLink="false">ZDI-CAN-1828</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-102/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-2551.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-101: IBM SPSS SamplePower Vsflex7l.ocx ActiveX ComboList Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1546</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-101/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM SPSS SamplePower. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2012-5947.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-100: IBM SPSS SamplePower C1sizer.ocx ActiveX TabCaption Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1545</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-100/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM SPSS SamplePower. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2012-5946.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-099: IBM SPSS SamplePower Vsflex8l.ocx ActiveX ComboList/ColComboList Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1544</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-099/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM SPSS SamplePower. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2012-5945.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-098: Microsoft Internet Explorer VML TextBox Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1807</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-098/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer.  User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1338.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-097: Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1783</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-097/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2013-0090.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-096: Novell iPrint Client IPP Response Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1715</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-096/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell iPrint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-1091.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-095: F-Secure E-mail and Server Security FSDBCom ActiveX Control GetCommand Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1692</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-095/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of F-Secure E-mail and Server Security. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-094: Oracle WebCenter Content CheckOutAndOpen.dll ActiveX coao/openWebdav Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1689</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-094/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle WebCenter Content. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2013-1559.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-093: Hewlett-Packard Managed Printing Administrator mdbBuildValueBasedSQL() Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1668</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-093/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Managed Printing Administration. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2012-5219.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-092: IBM SPSS Chart2D olch2x32.ocx ActiveX Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1576</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-092/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM SPSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-0593.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-091: Oracle Document Capture BlackIceDevMode.ocx ActiveX Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1551</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-091/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Document Capture. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2013-1516.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-090: (Pwn2Own) Mozilla Firefox nsHTMLEditRules Use-After-Free Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1825</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-090/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-0787.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
    <item>
      <title><![CDATA[ZDI-13-089: (Pwn2Own) Oracle Java DragAndDrop Sandbox Bypass Remote Code Execution Vulnerability]]></title>
      <guid isPermaLink="false">ZDI-CAN-1817</guid>
      <link>http://www.zerodayinitiative.com/advisories/ZDI-13-089/</link>
      <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2013-0401.]]></description>
      <pubDate>Wed, 29 May 2013 00:00:00 -0500</pubDate>
    </item>
    
  </channel>
</rss>
