<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>

<title>DOE-CIRC Updates</title>
<description>CIRC's latest security bulletins.</description>
<link>http://www.doecirc.energy.gov/index.html</link>

<item>
  <title>T-267: Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment</title>
  <description>Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-267.shtml</link>
  <pubDate>6 Nov 2009 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-266: Sun Solaris SCTP 'sctp(7P)' and SDP 'sdp(7D)' Sockets Local Denial Of Service Vulnerability</title>
  <description>Sun Solaris SCTP 'sctp(7P)' and SDP 'sdp(7D)' Sockets Local Denial Of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-266.shtml</link>
  <pubDate>5 Nov 2009 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-265: BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability</title>
  <description>BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-265.shtml</link>
  <pubDate>4 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-264: VMware Products Directory Traversal Vulnerability</title>
  <description>VMware Products Directory Traversal Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-264.shtml</link>
  <pubDate>3 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-263: KDE Multiple Input Validation Vulnerabilities</title>
  <description>KDE Multiple Input Validation Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-263.shtml</link>
  <pubDate>2 Nov 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-262: Drupal Workflow Module Multiple HTML Injection Vulnerabilities</title>
  <description>Drupal Workflow Module Multiple HTML Injection Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-262.shtml</link>
  <pubDate>30 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-261: Solaris Trusted Extensions Weakness May Let Users Gain Elevated Privileges </title>
  <description>Solaris Trusted Extensions Weakness May Let Users Gain Elevated Privileges </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-261.shtml</link>
  <pubDate>29 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-260: Mozilla Firefox and SeaMonkey MFSA 2009-52 through -64 Multiple Vulnerabilities</title>
  <description>Mozilla Firefox and SeaMonkey MFSA 2009-52 through -64 Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-260.shtml</link>
  <pubDate>28 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-259: Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability</title>
  <description>Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-259.shtml</link>
  <pubDate>27 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-258: Multiple Security Vulnerabilities in Adobe Reader and Acrobat</title>
  <description>Multiple Security Vulnerabilities in Adobe Reader and Acrobat</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-258.shtml</link>
  <pubDate>26 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-257: MapServer Multiple Security Vulnerabilities</title>
  <description>MapServer Multiple Security Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-257.shtml</link>
  <pubDate>23 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-256: Pidgin OSCAR Plugin Invalid Memory Access Denial Of Service Vulnerability</title>
  <description>Pidgin OSCAR Plugin Invalid Memory Access Denial Of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-256.shtml</link>
  <pubDate>22 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-255: Oracle Critical Patch Update Advisory</title>
  <description>Oracle Critical Patch Update Advisory</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-255.shtml</link>
  <pubDate>21 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-254: Cisco IOS Software Authentication Proxy Vulnerability</title>
  <description>Cisco IOS Software Authentication Proxy Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-254.shtml</link>
  <pubDate>20 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-253: Cisco Unified Presence Denial of Service Vulnerabilities</title>
  <description>Cisco Unified Presence Denial of Service Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-253.shtml</link>
  <pubDate>19 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-252: Xpdf Multiple Integer Overflow Vulnerabilities</title>
  <description>Xpdf Multiple Integer Overflow Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-252.shtml</link>
  <pubDate>16 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-251: Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability</title>
  <description>Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-251.shtml</link>
  <pubDate>15 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-250: Microsoft Patch Tuesday Reminder</title>
  <description>Microsoft Patch Tuesday Reminder</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-250.shtml</link>
  <pubDate>14 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-249: Sun VirtualBox VBoxNetAdpCtl Configuration Tool Local Privilege Escalation Vulnerability</title>
  <description>Sun VirtualBox VBoxNetAdpCtl Configuration Tool Local Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-249.shtml</link>
  <pubDate>13 Oct 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-248: Adobe Acrobat Reader Remote Code Execution Vulnerability</title>
  <description>Adobe Acrobat Reader Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-248.shtml</link>
  <pubDate>9 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-247: Multiple HP JetDirect Printers Multiple Cross Site Scripting Vulnerabilities</title>
  <description>Multiple HP JetDirect Printers Multiple Cross Site Scripting Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-247.shtml</link>
  <pubDate>8 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-246: IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability</title>
  <description>IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-246.shtml</link>
  <pubDate>6 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-245: VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host </title>
  <description>VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-245.shtml</link>
  <pubDate>5 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-244: Solaris IP(7P) Module and STREAMS Framework Denial of Service Vulnerabilities</title>
  <description>Solaris IP(7P) Module and STREAMS Framework Denial of Service Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-244.shtml</link>
  <pubDate>2 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-243: Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability</title>
  <description>Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-243.shtml</link>
  <pubDate>1 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-242: Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability</title>
  <description>Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-242.shtml</link>
  <pubDate>30 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-241: Blackberry OS NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certficates </title>
  <description>Blackberry OS NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certficiates</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-241.shtml</link>
  <pubDate>29 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-240: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-240.shtml</link>
  <pubDate>28 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-239: Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vulnerability</title>
  <description>Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-239.shtml</link>
  <pubDate>25 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-238: Cisco Unified Communications Manager SIP Message Denial of Service Vulnerability</title>
  <description>Cisco Unified Communications Manager SIP Message Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-238.shtml</link>
  <pubDate>24 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-237: Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability</title>
  <description>Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-237.shtml</link>
  <pubDate>23 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-236: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-236.shtml</link>
  <pubDate>22 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-235: IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability</title>
  <description>IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-235.shtml</link>
  <pubDate>21 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-234: Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-234.shtml</link>
  <pubDate>18 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-233: Wireshark 1.2.1 Multiple Vulnerabilities</title>
  <description>Wireshark 1.2.1 Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-233.shtml</link>
  <pubDate>17 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-232: VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities</title>
  <description>VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-232.shtml</link>
  <pubDate>16 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-231: HP StorageWorks Remote Management Interface Vulnerability</title>
  <description>HP StorageWorks Remote Management Interface Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-231.shtml</link>
  <pubDate>15 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-230: Solaris Heap Overflow Vulnerability in w(1) Utility</title>
  <description>Solaris Heap Overflow Vulnerability in w(1) Utility</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-230.shtml</link>
  <pubDate>14 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-229: Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities</title>
  <description>Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-229.shtml</link>
  <pubDate>11 Sep 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-228: Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability</title>
  <description>Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-228.shtml</link>
  <pubDate>10 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-227: Microsoft Patch Tuesday Reminder</title>
  <description>Microsoft Patch Tuesday Reminder</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-227.shtml</link>
  <pubDate>9 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-226: Debian devscripts 'uscan' Input Validation Vulnerability</title>
  <description>Debian devscripts 'uscan' Input Validation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-226.shtml</link>
  <pubDate>8 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-225: Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability</title>
  <description>Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-225.shtml</link>
  <pubDate>4 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-224: OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities</title>
  <description>OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-224.shtml</link>
  <pubDate>3 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-223: Autonomy KeyView Module Excel Document Processing Buffer Overflow Vulnerability</title>
  <description>Autonomy KeyView Module Excel Document Processing Buffer Overflow</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-223.shtml</link>
  <pubDate>2 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-222: Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability</title>
  <description>Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-222.shtml</link>
  <pubDate>1 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-221: Multiple Browser HTTP Resource in HTTPS Context Security Bypass Vulnerability</title>
  <description>Multiple Browser HTTP Resource in HTTPS Context Security Bypass Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-221.shtml</link>
  <pubDate>31 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-220: Sun Java System Access Manager Debug Files Local Information Disclosure Vulnerability</title>
  <description>Sun Java System Access Manager Debug Files Local Information Disclosure Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-220.shtml</link>
  <pubDate>28 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-219: Sun Virtual Desktop Infrastructure (VDI) Secure LDAP Vulnerability</title>
  <description>Sun Virtual Desktop Infrastructure (VDI) Secure LDAP Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-219.shtml</link>
  <pubDate>27 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-218: Cisco Lightweight Access Point Over-the-Air Provisioning Manipulation Vulnerability</title>
  <description>Cisco Lightweight Access Point Over-the-Air Provisioning Manipulation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-218.shtml</link>
  <pubDate>26 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-217: Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability</title>
  <description>Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-217.shtml</link>
  <pubDate>25 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-216: Multiple Vulnerabilities With Adobe Flash Player, Adobe Reader and Acrobat</title>
  <description>Multiple Vulnerabilities With Adobe Flash Player, Adobe Reader and Acrobat</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-216.shtml</link>
  <pubDate>24 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-215: Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability</title>
  <description>Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-215.shtml</link>
  <pubDate>21 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-214: Solaris Kernel Filesystem and Virtual Memory Subsystems Vulnerability</title>
  <description>Solaris Kernel Filesystem and Virtual Memory Subsystems Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-214.shtml</link>
  <pubDate>20 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-213: Cisco IOS XR Software Border Gateway Protocol Vulnerability</title>
  <description>Cisco IOS XR Software Border Gateway Protocol Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-213.shtml</link>
  <pubDate>19 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-212: Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability</title>
  <description>Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-212.shtml</link>
  <pubDate>18 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-211: Memcached Multiple Heap Based Buffer Overflow Vulnerability</title>
  <description>Memcached Multiple Heap Based Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-211.shtml</link>
  <pubDate>17 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-210: Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities</title>
  <description>Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-210.shtml</link>
  <pubDate>14 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-209: NTP 'ntpq' Stack Buffer Overflow Vulnerability</title>
  <description>NTP 'ntpq' Stack Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-209.shtml</link>
  <pubDate>13 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-208: Apple Safari Code Execution and Security Bypass Vulnerabilities</title>
  <description>Apple has released Safari 4.0.3 for Windows and Mac OS X to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof a website.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-208.shtml</link>
  <pubDate>12 Aug 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-207: Microsoft Patch Tuesday Reminder</title>
<description></description>
<link>http://www.doecirc.energy.gov/bulletins/t-207.shtml</link>
<pubDate>12 Aug 2009 00:00 GMT</pubDate>
<category>New Bulletin </category>
</item>
<item>
  <title>T-206: Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability</title>
  <description>Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-206.shtml</link>
  <pubDate>10 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-205: Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-205.shtml</link>
  <pubDate>7 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-204: Apple Mac OS X 2009-003 Multiple Security Vulnerabilities</title>
  <description>Apple Mac OS X 2009-003 Multiple Security Vulnerabilities.  Apple Mac OS X Code Execution and Security Bypass Vulnerabilities.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-204.shtml</link>
  <pubDate>06 August 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-203: Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability</title>
  <description>Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability.  Sun Java Runtime Environment (JRE) is prone to a privilege-escalation vulnerability.  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-203.shtml</link>
  <pubDate>05 August 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-202: Mozilla Firefox Error Page Address Bar URL Spoofing Vulnerability</title>
  <description>Mozilla Firefox Error Page Address Bar URL Spoofing Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-202.shtml</link>
  <pubDate>4 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-201: Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability</title>
  <description>Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-201.shtml</link>
  <pubDate>3 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-200: Absolute Software Computrace LoJack for Laptops Security Bypass Vulnerability</title>
  <description>Absolute Software Computrace LoJack for Laptops Security Bypass Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-200.shtml</link>
  <pubDate>31 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-199: Mozilla Firefox NULL Character CA SSL Certificate Validation Security Bypass Vulnerability</title>
  <description>Mozilla Firefox NULL Character CA SSL Certificate Validation Security Bypass Vulnerability.  Mozilla Firefox before 3.5 and NSS before 3.12.3 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-199.shtml</link>
  <pubDate>31 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-198: Squid Multiple Remote Denial of Service Vulnerabilities</title>
  <description>Squid Multiple Remote Denial of Service Vulnerabilities.  Squid proxy server contains multiple remote denial of service vulnerabilities.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-198.shtml</link>
  <pubDate>30 July 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-197: ISC BIND Denial of Service Vulnerability</title>
  <description>ISC BIND Denial of Service Vulnerability.  ISC BIND has a vulnerability that could allow remote unauthenticated users to cause a denial of service.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-197.shtml</link>
  <pubDate>29 July 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-196: Critical Cumulative Security Update for Internet Explorer</title>
  <description>Critical Cumulative Security Update for Internet Explorer</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-196.shtml</link>
  <pubDate>29 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-195: Remote Jail Breakout Vulnerability via Symlink Traversal in NcFTPd</title>
  <description>Remote Jail Breakout Vulnerability via Symlink Traversal in NcFTPd</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-195.shtml</link>
  <pubDate>28 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-194: Multiple Vulnerabilities in Cisco Wireless LAN Controllers</title>
  <description>Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

For Public Release 2009 July 27 1600 UTC (GMT)

- ---------------------------------------------------------------------

Summary

Multiple vulnerabilities exist in the Cisco Wireless LAN Controller
(WLC) platforms. This security advisory outlines the details of the following vulnerabilities:

  * Malformed HTTP or HTTPS authentication response denial of service
    vulnerability
  * SSH connections denial of service vulnerability
  * Crafted HTTP or HTTPS request denial of service vulnerability
  * Crafted HTTP or HTTPS request unauthorized configuration
    modification vulnerability

Cisco has released free software updates that address these vulnerabilities.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-194.shtml</link>
  <pubDate>27 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-193: Sun Solaris Auditing Extended File Attributes (fsattr(5)) Local Denial Of Service Vulnerability</title>
  <description>Sun Solaris Auditing Extended File Attributes (fsattr(5)) Local Denial Of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-193.shtml</link>
  <pubDate>24 Jul 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-192: Microsoft Office Web Components ActiveX Control 'msDataSourceObject' is vulnerable to Code Execution</title>
  <description>Microsoft Office Web Components ActiveX Control 'msDataSourceObject' is vulnerable to Code Execution</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-192.shtml</link>
  <pubDate>24 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-191: Vulnerability in Adobe Acrobat, Reader, and Flash Player</title>
  <description>Vulnerability in Adobe Acrobat, Reader, and Flash Player</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-191.shtml</link>
  <pubDate>23 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-190: Buffer Overflow in NASA Common Data Format (CDF) Library</title>
  <description>Buffer Overflow in NASA Common Data Format (CDF) Library</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-190.shtml</link>
  <pubDate>22 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-189: Directory Traversal Vulnerability in the Administration Interface in Cisco Customer Response Solutions</title>
  <description>Directory Traversal Vulnerability in the Administration Interface in Cisco Customer Response Solutions</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-189.shtml</link>
  <pubDate>21 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-188: Linked XSS Vulnerability found in Oracle BEA Weblogic Server</title>
  <description>Linked XSS Vulnerability found in Oracle BEA Weblogic Server</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-188.shtml</link>
  <pubDate>20 Jul 2009 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-187: Security Vulnerability in Solaris NFSv4 Kernel Module May Panic an NFSv4 Client System </title>
  <description>Security Vulnerability in Solaris NFSv4 Kernel Module May Panic an NFSv4 Client System</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-187.shtml</link>
  <pubDate>17 Jul 2009 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-186: Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-186.shtml</link>
  <pubDate>17 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-185: Two Remote Code Execution Vulnerabilities in Firefox</title>
  <description>Two Remote Code Execution Vulnerabilities in Firefox.  Firefox has vulnerabilities in the Unicode Data and Tracemonkey components. Successful exploit of either could result in the attacker running code in the context of the logged in user.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-185.shtml</link>
  <pubDate>16 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-184: Microsoft Monthly Updates</title>
  <description>Microsoft Monthly Updates.  Microsoft has released updates that address vulnerabilities in, Microsoft Windows, Windows Server, DirectShow, Virtual PC and Server, Office Publisher, and ISA Server.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-184.shtml</link>
  <pubDate>15 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-183: Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution </title>
  <description>Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-183.shtml</link>
  <pubDate>14 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-182: Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability</title>
  <description>Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability.  Nagios is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-182.shtml</link>
  <pubDate>13 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-181: Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Vulnerability</title>
  <description>Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-181.shtml</link>
  <pubDate>10 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-180: Citrix XenCenterWeb Multiple Input Validation Vulnerabilities</title>
  <description>Citrix XenCenterWeb Multiple Input Validation Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-180.shtml</link>
  <pubDate>09 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-179: Ubuntu Linux TIFF Image Library Vulnerability</title>
  <description>Ubuntu Linux TIFF Image Library Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-179.shtml</link>
  <pubDate>8 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-178: Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote Memory Corruption Vulnerability</title>
  <description>Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote Memory Corruption Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-178.shtml</link>
  <pubDate>7 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-177: FCKeditor input sanitization errors</title>
  <description>FCKeditor input sanitization errors</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-177.shtml</link>
  <pubDate>6 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-176: Sun Kernel udp(7p) Denial of Service Vulnerability</title>
  <description>Sun Kernel udp(7p) Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-176.shtml</link>
  <pubDate>6 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-175: Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability</title>
  <description>Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-175.shtml</link>
  <pubDate>02 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-174: MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability</title>
  <description>MIT Kerberos fails to handle an error condition which allows for memory corruption.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-174.shtml</link>
  <pubDate>01 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-173: phpMyAdmin 'db' Parameter Cross Site Scripting Vulnerability</title>
  <description>phpMyAdmin 'db' Parameter Cross Site Scripting Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-173.shtml</link>
  <pubDate>30 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-172: Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability</title>
  <description>Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability.  The Linux kernel is vulnerable to a denial of service attack.  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-172.shtml</link>
  <pubDate>29 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-171: Samba Format String And Security Bypass Vulnerabilities</title>
  <description>Samba Format String And Security Bypass Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-171.shtml</link>
  <pubDate>26 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-170: Cisco Physical Access Gateway Malformed Packet Remote Denial of Service Vulnerability</title>
  <description>Cisco Physical Access Gateway Malformed Packet Remote Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-170.shtml</link>
  <pubDate>25 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-169: Adobe Shockwave Player Unspecified Security Vulnerability</title>
  <description>Adobe Shockwave Player Unspecified Security Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-169.shtml</link>
  <pubDate>24 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-168: IrfanView 'TIFF' File Handling Remote Integer Overflow Vulnerability</title>
  <description>IrfanView 'TIFF' File Handling Remote Integer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-168.shtml</link>
  <pubDate>23 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-167: OpenSSL Multiple Vulnerabilities</title>
  <description>OpenSSL Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-167.shtml</link>
  <pubDate>22 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-166: FreeBSD Direct Pipe Writes Information Disclosure Vulnerability</title>
  <description>FreeBSD Direct Pipe Writes Information Disclosure Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-166.shtml</link>
  <pubDate>19 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-165: Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability.  Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-165.shtml</link>
  <pubDate>18 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-164: Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability</title>
  <description>Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability.  Apple Java CColourUIResource Pointer Dereference Code Execution Vulnerability.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-164.shtml</link>
  <pubDate>18 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-163: Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability</title>
  <description>Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability.  Linux Kernel is vulnerable to security bypass via "NFS MAY_EXEC".</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-163.shtml</link>
  <pubDate>17 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-162: Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities</title>
  <description>Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities.  Drupal Views Module lets attackers bypass security and inject HTML and scripts into pages.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-162.shtml</link>
  <pubDate>16 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-161: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabilities.  The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-161.shtml</link>
  <pubDate>15 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-160: Microsoft Windows Print Spooler 'EnumeratePrintShares()' Remote Stack Buffer Overflow Vulnerability</title>
  <description>Microsoft Windows Print Spooler 'EnumeratePrintShares()' Remote Stack Buffer Overflow Vulnerability.  Remote exploitation of a stack buffer overflow vulnerability in Windows 2000 print spooler.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-160.shtml</link>
  <pubDate>12 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-159: Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities</title>
  <description>Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities.  Adobe Reader and Acrobat are prone to multiple remote vulnerabilities.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-159.shtml</link>
  <pubDate>11 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-158: HP OpenView Network Node Manager SNMP and MIB Unspecified Remote Code Execution Vulnerability</title>
  <description>HP OpenView Network Node Manager SNMP and MIB Unspecified Remote Code Execution Vulnerability.  HP OpenView Network Node Manager (NNM) is prone to a remote code-execution vulnerability.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-158.shtml</link>
  <pubDate>10 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-157: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities</title>
  <description>Apple Safari Prior to 4.0 Multiple Security Vulnerabilities</description>   
  <link>http://www.doecirc.energy.gov/bulletins/t-157.shtml</link>
  <pubDate>09 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-156: GNOME Evolution S/MIME Email Signature Verification Vulnerability</title>
  <description>GNOME Evolution S/MIME Email Signature Verification Vulnerability.  GNOME Evolution contains a vulnerability that allows an attacker to change a signed S/MIME message without detection.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-156.shtml</link>
  <pubDate>08 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-155: OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerability.  OpenSSL is prone to a denial-of-service vulnerability caused by a NULL-pointer dereference condition. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-155.shtml</link>
  <pubDate>05 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-154: Sun Solaris Kerberos Credential Management Security Bypass Vulnerability</title>
  <description>Sun Solaris Kerberos Credential Management Security Bypass Vulnerability.  Solaris Kerberos is prone to a security-bypass vulnerability that affects the Kerberos credential cache management.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-154.shtml</link>
  <pubDate>05 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-153: Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness</title>
  <description>Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-153.shtml</link>
  <pubDate>04 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-152: Apple QuickTime JP2 Image Handling Heap Buffer Overflow Vulnerability</title>
  <description>Apple QuickTime JP2 Image Handling Heap Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-152.shtml</link>
  <pubDate>04 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-151: Microsoft Windows Desktop Wall Paper System Parameter Local Denial Of Service Vulnerability</title>
  <description>Microsoft Windows Desktop Wall Paper System Parameter Local Denial Of Service Vulnerability.  Microsoft Windows Desktop Wall Paper System contains a local denial of service vulnerability.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-151.shtml</link>
  <pubDate>03 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-150: VMware Hosted products and ESX and ESXi  security issues</title>
  <description>VMware Hosted products and ESX and ESXi  security issues</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-150.shtml</link>
  <pubDate>02 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-149: Apache 'Options' and 'AllowOverride' Security Directives Vulnerability</title>
  <description>Apache 'Options' and 'AllowOverride' Security Directives Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-149.shtml</link>
  <pubDate>01 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-148: Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vulnerability</title>
  <description>Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-148.shtml</link>
  <pubDate>29 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-147: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-147.shtml</link>
  <pubDate>29 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-146: BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities</title>
  <description>BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities.  BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-146.shtml</link>
  <pubDate>28 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-145: Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability</title>
  <description>Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-145.shtml</link>
  <pubDate>28 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-144: FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability</title>
  <description>FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability.  FreeBSD 'telnetd' Daemon allows remote code execution.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-144.shtml</link>
  <pubDate>27 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-143: Pidgin Multiple Buffer Overflow Vulnerabilities</title>
  <description>Pidgin Multiple Buffer Overflow Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-143.shtml</link>
  <pubDate>26 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-142: Basic Analysis and Security Engine Cross-Site Scripting Vulnerability</title>
  <description>Basic Analysis and Security Engine Cross-Site Scripting Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-142.shtml</link>
  <pubDate>26 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-141: Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities</title>
  <description>Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities Multiple vulnerabilities have been identified in Novell GroupWise, which could be exploited by remote attackers to bypass security restrictions, conduct phishing attacks, cause a denial of service or compromise a vulnerable system. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-141</link>
  <pubDate>22 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-140: CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability</title>
  <description>CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-140.shtml</link>
  <pubDate>21 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-139: Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-139.shtml</link>
  <pubDate>20 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-138: NTP 'ntpd' Autokey and ntpq Stack Buffer Overflow Vulnerability</title>
  <description>NTP 'ntpd' Autokey and ntpq Stack Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-138.shtml</link>
  <pubDate>19 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-137: Microsoft IIS 6.0 WebDAV Remote Authentication Bypass</title>
  <description>Microsoft IIS 6.0 WebDAV Remote Authentication Bypass</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-137.shtml</link>
  <pubDate>18 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-136: Apple Mac OS X PICT Image Handling Integer Overflow Vulnerability</title>
  <description>Apple Mac OS X PICT Image Handling Integer Overflow Vulnerability.  Apple Mac OS X is prone to an integer-overflow vulnerability when handling PICT image files. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-136.shtml</link>
  <pubDate>15 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-135: Apple Mac OS X Help Viewer HTML Document Remote Code Execution Vulnerability</title>
  <description>Apple Mac OS X Help Viewer HTML Document Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-135.shtml</link>
  <pubDate>14 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-134: Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-134.shtml</link>
  <pubDate>13 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-133: Little CMS Monochrome Profiles Null Pointer Dereference Denial of Service Vulnerability</title>
  <description>Little CMS Monochrome Profiles Null Pointer Dereference Denial of Service Vulnerability.  Little CMS is prone to a remote denial-of-service vulnerability.  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-133.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-132: Multiple Trend Micro Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple Trend Micro Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple Trend Micro products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-132.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-131: Multiple AVG Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple AVG Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple AVG products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-131.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-130: F-PROT Products CAB File Scan Evasion Vulnerability</title>
  <description>F-PROT Products CAB File Scan Evasion Vulnerability.  Multiple F-Prot products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-130.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-129: HP OpenView Network Node Manager 'ovalarmsrv.exe' Remote Code Execution Vulnerability</title>
  <description>HP OpenView Network Node Manager 'ovalarmsrv.exe' Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-129.shtml</link>
  <pubDate>8 May 2009</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-128: Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability</title>
  <description>Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-128.shtml</link>
  <pubDate>08 May 2009</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-127: Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple F-Secure products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-127.shtml</link>
  <pubDate>07 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-126: Insight Control Suite For Linux (ICE-LX) Multiple Remote Vulnerabilities In Nagios</title>
  <description>Release Date: 2009-05-05
Last Updated: 2009-05-05

Potential Security Impact: Multiple remote vulnerabilities in Nagios

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with Insight Control suite for Linux (ICE-LX) running Nagios.
The vulnerabilities could be remotely exploited via cross-site request forgery (CSRF) and remote authentication bypass.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-126.shtml</link>
  <pubDate>06 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-125: The Linux kernel is prone to a local privilege-escalation vulnerability via ptrace_attach().</title>
  <description>The Linux kernel is prone to a local privilege-escalation vulnerability via ptrace_attach(). Currently we are not aware of any working exploits. A fix is available in the GIT repository. http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d84f4f992cbd76e8f39c488cf0c5d123843923b1
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-125.shtml</link>
  <pubDate>05 May 2009</pubDate>
  <category></category>
</item>
<item>
  <title>T-124: Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-124.shtml</link>
  <pubDate>04 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-123: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities</title>
  <description>A remote attacker can exploit a buffer overflow to gain apache privileges, or cause a denial of service.
CA ARCserve Backup on Solaris, Tru64, HP-UX, and AIX contains multiple vulnerabilities in the Apache HTTP Server version
as shipped with ARCserve Backup. CA has issued updates that contain version 2.0.63 of the Apache HTTP Server to address
the vulnerabilities. Refer to the References section for a list of resolved issues by CVE identifier.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-123.shtml</link>
  <pubDate>01 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-122: McAfee Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description></description>
  <link>http://www.doecirc.energy.gov/bulletins/t-122.shtml</link>
  <pubDate>30 Apr 09</pubDate>
  <category></category>
</item>
<item>
  <title>T-121: Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability</title>
  <description>This is a root compromise, privilege escalation exploit. A local attacker can exploit this issue to execute arbitrary code with superuser privileges. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-121.shtml</link>
  <pubDate>29 April 2009</pubDate>
  <category>New Bulletin</category>
</item>
<item>
  <title>T-120: Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability</title>
  <description>Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-120.shtml</link>
  <pubDate>28 APR 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-119: Symantec Brightmail Gateway Appliance Cross-site Scripting and Elevation of Privilege</title>
  <description>Symantec Brightmail Gateway Appliance Cross-site Scripting and Elevation of Privilege.  Symantec Brightmail Gateway is prone to a remote privilege-escalation vulnerability.  Remote authorized attackers who have access to the targeted host's local network can exploit this issue to gain elevated access. Successful exploits may compromise the affected computer and may aid in other attacks.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-119.shtml</link>
  <pubDate>28 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-118: GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities</title>
  <description>GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities.  The GNOME glib library is
prone to multiple integer-overflow vulnerabilities related to encoding and decoding Base64 data.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-118.shtml</link>
  <pubDate>27 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-117: Sun Java System Delegated Administrator HTTP Response Splitting Vulnerability</title>
  <description>Sun Java System Delegated Administrator HTTP Response Splitting Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-117.shtml</link>
  <pubDate>24 APR 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-116: Symantec Ghost EasySetup Wizard Lets Remote Users Deny Service </title>
  <description>Symantec Norton Ghost 'EasySetupInt.dll' ActiveX Multiple Remote Denial of Service Vulnerabilities. This vulnerability can cause Denial of service via network. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-xxx.shtml</link>
  <pubDate>24 Apr 09</pubDate>
  <category></category>
</item>
<item>
  <title>T-115: Multiple Vulnerabilities in Firefox, Thunderbird and Seamonkey</title>
  <description>Multiple vulnerabilities in Firefox, Thunderbird and Seamonkey: Multiple newly disclosed vulnerabilities in Firefox, Thunderbird and Seamonkey could result in disclosure of information, crashing the application or the running of inserted javascript. One vulnerability results in memory corruption and could conceivably be used to run arbitrary code.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-115.shtml</link>
  <pubDate>23 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-114: Xpdf JBIG2 Processing Multiple Security Vulnerabilities</title>
  <description>Xpdf JBIG2 Processing Multiple Security Vulnerabilities. Failed exploit attempts will likely cause denial-of-service conditions. Currently we are not aware of any working exploits. Updates are available. Please see the references for more information.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-114.shtml</link>
  <pubDate>22 April 2009</pubDate>
  <category></category>
</item>
<item>
  <title>T-113: udev Netlink Message Validation Local Privilege Escalation Vulnerability</title>
  <description>udev Netlink Message Validation Local Privilege Escalation Vulnerability.  udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-113.shtml</link>
  <pubDate>21 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-112: CUPS Integer Overflow in Processing TIFF Images Lets Remote Users Execute Arbitrary Code </title>
  <description>CUPS Integer Overflow in Processing TIFF Images Lets Remote Users Execute Arbitrary Code </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-112.shtml</link>   
  <pubDate>17 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-111: Oracle April 2009 Critical Patch Update</title>
  <description>Oracle April 2009 Critical Patch Update Multiple Vulnerabilities. Oracle has released the April 2009 critical patch update that addresses 43 vulnerabilities.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-111.shtml</link>
  <pubDate>16 Apr 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-110: OpenBSD PF Remote Denial of Service Vulnerability</title>
  <description>OpenBSD PF Remote Denial Of Service Vulnerability Exploiting this issue allows remote attackers to cause a kernel panic on affected computers, denying further service to legitimate users.
OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
OpenBSD OpenBSD 4.4
   OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
OpenBSD OpenBSD 4.5
    OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-110.shtml</link>
  <pubDate>16 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-109: Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)</title>
  <description>Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)
This security update resolves a publicly disclosed vulnerability in the Windows SearchPath function that could allow elevation of privilege if a user downloaded a specially crafted file to a specific location, then opened an application that could load the file under certain circumstances.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-109.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-108: Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause De</title>
  <description>Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (961759)
This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE).</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-108.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-107: Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)</title>
  <description>Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)
This security update resolves four publicly disclosed vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker is allowed to log on to the system and then run a specially crafted application.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-107.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-106: Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)</title>
  <description>Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)
This security update resolves a privately reported and a publicly disclosed vulnerability.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-106.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-105: Critical Cumulative Security Update for Internet Explorer (963027)</title>
  <description>Cumulative Security Update for Internet Explorer (963027)
This security update resolves four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-105.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-104: Vulnerabilities in Windows HTTP services could allow remote code execution</title>
  <description>Vulnerabilities in Windows HTTP services could allow remote code execution</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-104.shtml</link>
  <pubDate>15 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-103: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution</title>
  <description>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution. This security update resolves a privately reported vulnerability in Microsoft DirectX. The vulnerability could allow remote code execution if user opened a specially crafted MJPEG file. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-103.shtml</link>
  <pubDate>15 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-102: Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution</title>
  <description>Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-102.shtml</link>
  <pubDate>15 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-101: Vmware Flaw in Multiple Products Allows Compromise of Host System</title>
  <description>Vmware Flaw in Multiple Products Allows Compromise of Host System.  A local user can exploit a flaw in the virtual machine display function to execute arbitrary code on the target host system.  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-101.shtml</link>
  <pubDate>14 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-100: Tor Security Bypass And Privilege Escalation Weaknesses</title>
  <description>Tor Security Bypass And Privilege Escalation Weaknesses.  Tor is prone to multiple weaknesses that may allow attackers to exploit other vulnerabilities that facilitate privilege-escalation and security-bypass attacks.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-100.shtml</link>
  <pubDate>13 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-099: Linux Kernel CIFS Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel CIFS Remote Buffer Overflow Vulnerability.  An attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-099.shtml</link>
  <pubDate>10 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-098: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</title>
  <description>Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances.  Cisco has announced multiple vulnerabilities in its ASA Adaptive Security Appliance and PIX Security Appliance. Most result in DoS, to allow an attacker to bypass VPN authentication or bypass ACL rules.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-098.shtml</link>
  <pubDate>09 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-097: Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability
ZDI-09-016</title>
  <description>Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability ZDI-09-016: April 6th, 2009 CVE ID. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. A valid IPC$ connection must be established in order to exploit this vulnerability.
  </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-097.shtml</link>
  <pubDate>06 April 2009</pubDate>
  <category>New Bulletin </category>
</item> 
<item>
  <title>T-096: Clam AV 0.94 and below Rar Evasion Vulnerability</title>
  <description>Clam AV 0.94 and below Rar Evasion Vulnerability.  ClamAV AntiVirus is prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-096.shtml</link>
  <pubDate>07 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-095: Microsoft Office PowerPoint code execution vulnerability</title>
  <description>Microsoft Office PowerPoint code execution vulnerability.  Unspecified vulnerability in MS Powerpoint could allow a remote attacker to execute arbitrary code on the system.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-095.shtml</link>
  <pubDate>06 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-094: Wireshark PN-DCP Data Format String Vulnerability</title>
  <description>Wireshark could allow a remote attacker to execute arbitrary code on the system, caused by a format string vulnerability in the PN-DCP dissector.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-094.shtml</link>
  <pubDate>02 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-093: Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</title>
  <description>Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities.  Security Vulnerabilities in the Java Runtime Environment (JRE) LDAP Implementation may Allow a Denial of Service (DoS) and Malicious Code to be Executed Vulnerability affects LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-093.shtml</link>
  <pubDate>01 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-092: Mozilla Firefox '_moveToEdgeShift' Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox '_moveToEdgeShift' Remote Code Execution Vulnerability.  This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-092.shtml</link>
  <pubDate>31 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-091: Conficker Worm Targets Microsoft Windows Systems</title>
  <description>Conficker Worm Targets Microsoft Windows Systems.  Public reports indicate a widespread infection of the Conficker worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across a network if the host is not patched with MS08-067.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-091.shtml</link>
  <pubDate>30 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-090: Squid Web Proxy Cache HTTP Version Number Parsing Denial of Service Vulnerability</title>
  <description>Squid Web Proxy Cache HTTP Version Number Parsing Denial of Service Vulnerability.  
Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to handle certain HTTP requests.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-090.shtml</link>
  <pubDate>27 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-089: pam-krb5 Local Privilege Escalation Vulnerability</title>
  <description>pam-krb5 Local Privilege Escalation Vulnerability.  pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-089.shtml</link>
  <pubDate>26 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-088: HP-UX VERITAS File System and VERITAS Oracle Disk Manager Local Privilege Escalation Vulnerability</title>
  <description>HP-UX VERITAS File System and VERITAS Oracle Disk Manager Local Privilege Escalation Vulnerability
HP-UX is prone to a local privilege-escalation vulnerability affecting VERITAS File System (VRTSvxfs) and VERITAS Oracle Disk Manager (VRTSodm).</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-088.shtml</link>
  <pubDate>25 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-087: Sun Solaris NFS Daemon (nfsd(1M)) Security Bypass Vulnerability</title>
  <description></description>
  <link>http://www.doecirc.energy.gov/bulletins/t-087.shtml</link>
  <pubDate>24 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-086: Linux Kernel 'readlink' Local Privilege Escalation Vulnerability</title>
  <description>Linux Kernel 'readlink' Local Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-086.shtml</link>
  <pubDate>23 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-085: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-085.shtml</link>
  <pubDate>20 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-084: Tasklist Drupal Module Unspecified SQL Injection Vulnerability</title>
  <description>Tasklist Drupal Module Unspecified SQL Injection Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-084.shtml</link>
  <pubDate>19 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-083: Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</title>
  <description>Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-083.shtml</link>
  <pubDate>18 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-082: Opera Web Browser HTML Parsing Heap-Based Remote Code Execution Vulnerability</title>
  <description>Opera Web Browser HTML Parsing Heap-Based Remote Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-082.shtml</link>
  <pubDate>17 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-081: Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerabilities</title>
  <description>The 'libpng' library is prone to multiple memory-corruption vulnerabilities because it fails to properly initialize data structures.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-081.shtml</link>
  <pubDate>16 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-080: Hewlett-Packard WMI Mapper for HP Systems Insight Manager Unauthorized Access Vulnerabilities</title>
  <description>Hewlett-Packard WMI Mapper for HP Systems Insight Manager Unauthorized Access Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-080.shtml</link>
  <pubDate>13 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-079: Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</title>
  <description>Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-079.shtml</link>
  <pubDate>12 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-078: Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vulnerability</title>
  <description>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-078.shtml</link>
  <pubDate>11 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-077: IBM Tivoli Storage Manager HSM Buffer Overflow Vulnerability</title>
  <description>A security vulnerability exists in the IBM Tivoli Storage Manager (TSM) HSM for Windows client.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-077.shtml</link>
  <pubDate>10 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-076: OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability</title>
  <description>OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-076.shtml</link>
  <pubDate>09 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-075: VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities</title>
  <description>VMware Server and Workstation are prone to an unauthorized-access vulnerability and multiple privilege-escalation and denial-of-service vulnerabilitie</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-075.shtml</link>
  <pubDate>06 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-074: XML Data Theft Via RDFXML DataSource and Cross-Domain Redirect</title>
  <description>XML Data Theft Via RDFXML DataSource and Cross-Domain Redirect</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-074.shtml</link>
  <pubDate>05 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-073: New proftpd-dfsg packages fix SQL injection vulnerabilites </title>
  <description>Two SQL injection vulnerabilities have been found in proftpd, a virtual-hosting FTP daemon.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-073.shtml</link>
  <pubDate>04 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-072: Adobe Flash Player Invalid Object Reference Bug Lets Remote Users Execute Arbitrary Code </title>
  <description>Adobe Flash Player Invalid Object Reference Bug Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-072.shtml</link>
  <pubDate>03 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-071: Novell eDirectory Management Console Accept-Language Buffer Overflow</title>
  <description>A remotely exploitable vulnerability has been discovered in the iMonitor component of Novell eDirectory.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-071.shtml</link>
  <pubDate>02 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-070: Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</title>
  <description>Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-070.shtml</link>
  <pubDate>27 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-069: HP OpenView Network Node Manager Vulnerable to Denial of Service</title>
  <description>Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM).</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-069.shtml</link>
  <pubDate>26 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-068: Microsoft Windows AutoRun and AutoPlay Vulnerability</title>
  <description>Microsoft Windows includes an AutoRun feature, which can automatically run code when removable devices are connected to the computer.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-068.shtml</link>
  <pubDate>25 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-067: Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution</title>
  <description>Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-067.shtml</link>
  <pubDate>24 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-066: Multiple HTTP Proxy HTTP Host Header Incorrect Relay Behavior Vulnerability</title>
  <description>Multiple HTTP Proxy HTTP Host Header Incorrect Relay Behavior Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-066.shtml</link>
  <pubDate>23 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-065: Adobe Acrobat and Reader PDF File Handling Remote Code Execution Vulnerability</title>
  <description>Adobe Acrobat and Reader are prone to a remote code-execution vulnerability.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-065.shtml</link>
  <pubDate>20 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-064: BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability</title>
  <description>RIM BlackBerry Application Web Loader is prone to multiple stack-based buffer overflows.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-064.shtml</link>
  <pubDate>19 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-063: Apple Mac OS X SMB Component Unspecified Buffer Overflow Vulnerability</title>
  <description>Apple Mac OS X is prone to a buffer-overflow vulnerability that occurs in the SMB component.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-063.shtml</link>
  <pubDate>18 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-062: Unspecified Vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6</title>
  <description>Unspecified vulnerablility in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-062.shtml</link>
  <pubDate>17 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-061: pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Escalation Vulnerability</title>
  <description>pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Escalation Vulnerability. pam-krb5 is prone to a local privilege-escalation vulnerability because of a failure to properly handle setuid processes.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-061.shtml</link>
  <pubDate>13 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-060: Cumulative Security Update for Internet Explorer 7</title>
  <description>Cumulative Security Update for Internet Explorer 7. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-060.shtml</link>
  <pubDate>12 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-059: Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution </title>
  <description>Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution 
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-059.shtml</link>
  <pubDate>11 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-058: RealPlayer IVR File Processing Two Vulnerabilities</title>
  <description>Some vulnerabilities have been reported in RealPlayer, which can be exploited by malicious people to compromise a vulnerable system.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-058.shtml</link>
  <pubDate>10 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-057: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files</title>
  <description> A potential security vulnerability has been identified with certain HP LaserJet printers, HP Color LaserJet printers and HP Digital Senders. The vulnerability could be exploited remotely to gain unauthorized access to files. </description>
  <link>http://www.doecirc.energy.gov/bulletins/t-057</link>
  <pubDate>09 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-056: RealNetworks RealPlayer IVR File Parsing Multiple Vulnerabilities</title>
  <description>RealNetworks RealPlayer IVR File Parsing Multiple Vulnerabilities.  RealPlayer 11 is affected; other versions may also be vulnerable.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-056</link>
  <pubDate>06 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-055: Cisco IOS HTTP Server Multiple Cross Site Scripting Vulnerabilities</title>
  <description>Cisco IOS HTTP Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-055.shtml</link>
  <pubDate>05 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-054: Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities Bypass Same-Origin Restrictions</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities bypass same-origin restrictions.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-054.shtml</link>
  <pubDate>04 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-053: Buffer Overflows in RealNetworks Helix Server and Helix Mobile Server Allow Remote Attackers to Cause a Denial of Servic</title>
  <description>Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server allows unauthorized disclosure of information, unauthorized modification, or a disruption of service.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-053.shtml</link>
  <pubDate>03 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-052:  Sun Solaris BIND "EVP_VerifyFinal()" and "DSA_do_verify()" Spoofing Vulnerability</title>
  <description>A vulnerability in Sun Solaris could be exploited by attackers to conduct spoofing attacks.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-052.shtml.shtml</link>
  <pubDate>02 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-051: Sun Java System Access Manager User Enumeration Weakness</title>  <description>A weakness in Sun Java System Access Manager can be exploited by
remote unprivileged users to identify valid user accounts.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-051.shtml</link>
  <pubDate>30 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-050: Sun Solaris Pseudo-terminal Driver Local Denial of Service Vulnerability</title>
  <description>A vulnerability in Sun Solaris could cause a denial of service.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-050.shtml</link>
  <pubDate>29 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-049: Sun Solaris IPv6 Packet Processing Denial of Service Vulnerability</title>
  <description>A vulnerability in Sun Solaris could be exploited by a remote attacker to cause a denial of service condition.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-049.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-048: Computer Assosciates Anti-Virus Engine 'arclib.dll' Multiple Scan Evasion Vulnerabilities</title>
  <description>Vulnerabilities in various CA products could allow a remote attacker to evade detection by the Anti-Virus engine by creating a malformed archive file.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-048.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-047: Sun Solaris "libike" Library Denial of Service</title>
  <description>A vulnerability in Sun Solaris could be exploited by a remote attacker to cause a Denial of Service.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-047.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-046: Cisco Unified Communications Manager CAPF Denial of Service Vulnerability</title>
  <description>Cisco Unified Communications Manager, formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Certificate Authority Proxy Function (CAPF) service.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-046.shtml</link>
  <pubDate>27 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-045: CYV4: Linux Kernel dell_rbu Denial of Service Security Issues</title>
  <description>Linux Kernel dell_rbu Denial of Service Security Issues

Summary:    Two security issues in the Linux Kernel could be exploited by malicious, local users to
cause a DoS (Denial of Service). Versions 2.6.27.13 and 2.6.28.2 are available to address these issues.
</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-045</link>
  <pubDate>26 Jan 2009 4:45 PM
</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-044: Apple QuickTime MPEG-2 Playback Component For Windows Input Validation Vulnerability</title>
  <description>Apple has published an advisory for an input validation error in the Quicktime MPEG-2 Playback Component for Windows.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-044.shtml</link>
  <pubDate>23 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-043: Apple QuickTime Memory Corruption and Buffer Overflow Vulnerabilities</title>
  <description>Multiple vulnerabilities in Apple QuickTime 7.5 and prior could allow remote attackers to cause a Denial of Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-043.shtml</link>
  <pubDate>22 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
	<title>T-042: Linux Kernel "keyctl_join_session_keyring()" Denial of Service</title>
	<description>A local denial of service vulnerability has been discovered in the Linux kernel</description>
  	<link>http://www.doecirc.energy.gov/bulletins/t-042.shtml</link>
  	<pubDate>21 Jan 2009</pubDate>
  	<category>New Bulletin </category>	
</item>
<item>
  <title>T-041: Symantec AppStream Client LaunchObj ActiveX Control Insecure Methods</title>
  <description>A vulnerability in Symantec AppStream Client could allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-041.shtml</link>
  <pubDate>20 Jan 2009</pubDate>
  <category>New Bulletin </category>

</item>
<item>
  <title>T-040: Sun SPARC Enterprise Server Authentication Bypass Vulnerability</title>
  <description>A vulnerability in certain Sun SPARC Enterprise servers could allow a remote attacker to gain root access on the target system.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-040.shtml</link>
  <pubDate>20 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-039: Sun Java System Access Manager Privilege Vulnerability And Password Security Issue</title>
  <description>A vulnerability and security issue in Sun Java System Access Manager could be exploited by an attacker to gain escalated privileges, or disclose sensitive information.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-039.shtml</link>
  <pubDate>16 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-038: Cisco ONS Platform Crafted Packet Vulnerability</title>
  <description>Certain Cisco Platforms contain a vulnerability when processing TCP traffic streams that may result in a reload of the device control card.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-038.shtml</link>
  <pubDate>15 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-037: Oracle Has Released The January 2009 Critical Patch Update.</title>
  <description>Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-037.shtml</link>
  <pubDate>14 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-036: Vulnerabilities in SMB Could Allow Remote Code Execution (MS09-001) - Critical</title>
  <description>This security update resolves two privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-036.shtml</link>
  <pubDate>13 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-035: Microsoft RPC Worm Spreads in Corporate Networks</title>
  <description>A Microsoft RPC vulnerability was patched in an out-of-band release in October, but organizations slow to deploy the update are learning the hard way how fast various RPC worm variants can spread through corporate networks.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-035.shtml</link>
  <pubDate>13 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-034: Vulnerability Discovered In XOOPS</title>
  <description>Athos has discovered a vulnerability in XOOPS, which can be exploited by malicious people to compromise a vulnerable system.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-034.shtml</link>
  <pubDate>09 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-033: OpenSSL Security Advisory</title>
  <description>A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to conduct spoofing attacks.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-033.shtml</link>
  <pubDate>08 Jan 2009</pubDate>
  <category>New Bulletin</category>
</item>
<item>
  <title>T-032: New Xterm Packages Fix Regression</title>
  <description>New xterm packages fix regression, there was a design flaw</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-032.shtml</link>
  <pubDate>07 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-031: SolucionWeb "id_area" SQL Injection Vulnerability</title>
  <description>Ehsan_Hp200 has reported a vulnerablility in SolucionWeb, which can be exploited by malicious people to conduct SQL injection attacks.</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-031.shtml</link>
  <pubDate>06 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-030:  New Ruby packages fix denial of service</title>
  <description>The regular expression engine of Ruby, a scripting language, contains a memory leak which can be triggered remotely under certain circumstances, leading to a denial of service condition (CVE-2008-3443).</description>
  <link>http://www.doecirc.energy.gov/bulletins/t-030.shtml</link>
  <pubDate>05 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-346: MySQL-dfsg-5.0 Vulnerabilities</title>
  <description>It was discovered that MySQL, a widely-deployed database server, did not properly validate optional data or index 
  directory paths given in a CREATE TABLE statement, no would it (under proper conditions) prevent two databases from using the same 
  paths for data or index files.  The risk is LOW.  This permits an authenticated user with authoriziation to create tables in one 
  database to read, write or delete data from tables subsequently created in other databases, regardless of other GRANT 
  authorizations.</description>
  <link>http://www.ciac.org/bulletins/s-346.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-345: Security Vulnerability in the Java Runtime Environment Virtual Machine</title>
  <description>A vulnerability in the Java Runtime Environment Virtual Machine may allow an untrusted application or applet that is 
  downloaded from a website to elevate its privileges.  The risk is MEDIUM.  The application or applet may grant itself permissions to 
  read and write local files or execute local applications that are accessible to the user running the untrusted application or 
  applet.</description>
  <link>http://www.ciac.org/bulletins/s-345.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-344: Ruby Security Update</title>
  <description>Multiple interger overflows to a heap overflow were discovered in the array- and string-handling code used by Ruby.  The 
  risk is MEDIUM.  An attacker could use these flaws to crash a Ruby application or, possibly, execute arbitrary code with the privileges 
  of the Ruby application using untrusted inputs in array or string operations.</description>
  <link>http://www.ciac.org/bulletins/s-344.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-343: Apple Safari 3.1.2 for Windows</title>
  <description>Apple Safari automatically executes downloaded files based on Internet Explorer zone settings, which can allow a remote attacker to execute arbitary code on a vulnerable system.  The risk is MEDIUM.  By convincing a user to visit a specially crafted web page with Apple Safari on Windows, an attacker mey be able to execute arbitrary code on a vulnerable system.</description>
  <link>http://www.ciac.org/bulletins/s-343.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-342: Popper Vulnerability</title>
  <description>It was discovered that poppler, a PDF rendering library, did not properly handle embedded fonts in PDF files, allowing 
  attackers to execute arbitrary code via a crafted font object.  The risk is MEDIUM.  </description>
  <link>http://www.ciac.org/bulletins/s-342.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-341: Multiple Cisco Products Vulnernable to DNS Cache Poisoning Attacks</title>
  <description>Multiple Cisco products are vulnerable to DNS cache poisoning attacks due to their use of insufficiently randomized DNS transaction IDs and UDP source ports in the DNS queries that they produce, which may allow an attacker to more easily forge DNS answers that can poison DNS caches.  The risk is HIGH.  Successful exploitation of the vulnerability described in this document may result in invalid hostname-to-IP address mappings in the cache of an affected DNS server. This may lead of this DNS server to contact with wrong provider of network services. </description>
  <link>http://www.ciac.org/bulletins/s-341.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-340: HP OpenView Network Node Manager (OV NNM)</title>
  <description>A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be 
  exploited remotely to gain unauthorized access to data.  The risk is LOW.   The vulnerability could be exploited remotely to gain 
  unauthorized access to data.</description>
  <link>http://www.ciac.org/bulletins/s-340.shtml</link>
  <pubDate>8 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-339: Vulnerabilities in Outlook Web Access for Exchange Server</title>
  <description>There is a cross-site scripting vulnerability in the affected versions of Outlook Web Access (OWA) for Exchange Server. 
  Exploitation of the vulnerability could lead to elevation of privilege on individual OWA clients connecting to Outlook Web Access for 
  Exchange Server.  The risk is LOW.  To exploit the vulnerability, an attacker would have to convince a user to open a specially 
  crafted e-mail that would run malicious script from within an individual OWA client. If the malicious script is executed, the script 
  would run inthe security context of the user's OWA session and could perform any action that user could perform such as reading, 
  sending, and deleting e-mail as the logged-on user.</description>
  <link>http://www.ciac.org/bulletins/s-339.shtml</link>
  <pubDate>8 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-338: Apple Security Update 2008-004 / Mac OS X 10.5.4</title>
  <description>The Apple Webkit contains a memory corruption vulnerability. This vulnerability may allow a remote, unauthenticated 
  attacker to execute arbitrary code.  The risk is MEDIUM.  A remote, unauthenticated attacker may be able to execute arbitrary 
  code.</description>
  <link>http://www.ciac.org/bulletins/s-338.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-337: Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access</title>
  <description>Microsoft is investigating active, targeted attacks leveraging a potential vulnerability in the ActiveX control for the 
  Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page.  The 
  risk is MEDIUM.  An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web 
  page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the 
  same user rights as the logged-on user.</description>
  <link>http://www.ciac.org/bulletins/s-337.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-336: PCRE3 Vulnerability</title>
  <description>It was discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when 
  compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution.  The 
  risk is MEDIUM.  May encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and 
  branches, potentially leading the arbitrary code execution.</description>
  <link>http://www.ciac.org/bulletins/s-336.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-003: Understanding Cross-Site Scripting (XSS)</title>
  <description>Cross-Site Scripting has become an increasingly prevalent attack vector that can be leveraged to perform a wide range of compromises. These compromises can range from simple popup displays within a user's browser to session and cookie capture that are used for information and identity theft. As these attacks become more mature, as well as obscure, it is imperative that we understand how they happen, how they propagate, and the ways to prevent them. By understanding the different vectors of attack and realizing and implementing simple security measures against them, we can better protect ourselves and our users now, and in the future.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-003.shtml</link>
  <pubDate>3 Jun 2008 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-002: Understanding Windows Hash Dumpers and Crackers</title>
  <description>Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract windows hashes and allow an intruder access to a system. In actuality, the hashes are there, in memory, where any admin or system level user can get at them. The tools just grab them and print them out. This paper will describe how Windows hashes are created, how the hash dumpers get at them, and what can be done with the hashes.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-002.shtml</link>
  <pubDate>21 May 2008 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-001: Understanding PHP Exploits</title>
  <description>Many websites use the PHP programming language to build web pages on the fly from individual files and from values obtained from a database. PHP based websites are widely used to create Wikis such as  MediaWiki used for Wikipedia. If the PHP programs that generate the web pages are not carefully crafted to check user input before it is used, an intruder could inject code into a page and get it executed.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-001.shtml</link>
  <pubDate>29 Jan 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech07-001: MOICE - Microsoft Office Isolated Conversion Environment</title>
  <description>A common cyber attack is to send a user an Office document 
(Word, Excel, PowerPoint) containing malicious code that 
infects the user's computer and proceeds to do the miscreant's 
bidding. Targeting of users has gotten so sophisticated that 
advice such as "don't open files from people you don't know" is 
no longer effective. 

MOICE, the Microsoft Office 
Isolated Conversion Environment opens Office documents 
before the Office application, converts it to a format that 
does not "support" malcode and then invokes the application 
with the newly cleaned document. Properly implemented, this 
could mitigate attacks using email-borne Office malcode. </description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech07-001.shtml</link>
  <pubDate>22 May 2007 23:00 GMT</pubDate>
  <category>New Revised Bulletin </category>
</item>
<item>
  <title>CIACTech06-001: Protecting Against SQL Injection Attacks</title>
  <description>SQL injection is a real threat that is being used to exploit company systems and data. 
  This threat can be reduced by a combination of good programming practice, application firewalls, 
  and scanning.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech06-001.shtml</link>
  <pubDate>6 Sep 2006 21:00 GMT</pubDate>
  <revDate>28 Apr 2008 21:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>CIACTech05-001: Operation of the Sinit/Calypso Worm</title>
  <description>Many sites have detected large numbers of udp packets 
directed at the DNS port (53). These packets contain a lot of structure 
and there is concern that they are exploit or remote control packets. 
It turns out that they are discovery packets being sent to random 
IP addresses by the Sinit Calypso worm. They are invalid DNS packets 
and should be ignored by DNS servers. 
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech05-001.shtml</link>
  <pubDate>15 Nov 2004 20:00 GMT</pubDate>
</item>
<item>
  <title>CIACTech04-001: Remote Detection of the MyDoom.A Worm</title>
  <description>Before systems containing the MyDoom.A worm can be cleaned, 
       they must be detected. As running a scanner on each system can be difficult 
       and time consuming, a method of remote scanning for infected machines is needed.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech04-001.shtml</link>
  <pubDate>30 Jan 2004 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech03-001: Spamming using the Windows Messenger Service</title>
  <description>A spam engine has been released that uses the Windows Messenger Service (not the MSN Messenger instant messaging program) to send spam messages to users. The Messenger service is active on most Windows platforms.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech03-001.shtml</link>
  <pubDate>29 Oct 2002 24:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-005: Understanding Capturing Files with Microsoft Word Field Codes</title>
  <description>Several online articles have worried the problem of file capture using Microsoft Word field codes. The articles have gone so far as suggesting that Word be banned from company computers until this is changed. These articles have created undue worry among computer users about what is a relatively low risk vulnerability.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-005.shtml</link>
  <pubDate>27 Sep 2002 24:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-004: Parasite Programs; Adware, Spyware, and Stealth Networks</title>
  <description>Programs are being intentionally packaged with legitimate 
       software to display advertising on your screen, gather information on your 
       browsing habits, and to sell your unused 
       CPU cycles and disk space. Current applications are relatively benign but 
       could easily be used for an invasion of privacy or other malicious 
       purposes.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-004.shtml</link>
  <pubDate>11 Nov 2002 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-003: Office for Mac X Antipiracy Mechanism Opens Server Ports</title>
  <description>Microsoft Office for Macintosh OS X has an antipiracy mechanism that secretly opens network service ports on a Macintosh system and broadcasts version information to other systems on a single subnet. The problem is that 
       open network services provide attack points for intruders and need to be 
       controlled by users.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-003.shtml</link>
  <pubDate>26 Apr 2002 00:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-002: Microsoft Browser Helper Objects (BHO) Could Hide Malicious Code</title>
  <description>Browser Helper Objects (BHO) are Microsoft's way of attaching add-ins to Internet Explorer 4 and later. In addition to legitimate uses, BHOs are used to attach spyware to a user's web browser 
       to secretly send a user's browsing habits to a marketing site and could be used for malicious code. The problems are that there is no simple way to know what BHOs are attached to a system and no simple way to control the attachment of new ones.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-002.shtml</link>
  <pubDate>2 Apr 2002 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-001: Understanding the SSH CRC32 Exploit</title>
  <description>In recent months, many servers running ssh
       have been compromised using the SSH CRC32 Compensation Attack
       Detector. Compromised machines have either not been upgraded to
       SSH protocol 2 or have not disabled drop back to SSH protocol 1. 
       Use of this attack allows a remote user to gain root access on a server.
  </description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-001.shtml</link>
  <pubDate>9 May 2002 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-317: HP OpenView Network Node Manager (OV NNM) Vulnerabilities</title>
  <description>A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could 
  be exploited remotely to execute arbitrary code or to create a Denial of Service (DoS).  The risk is MEDIUM. The vulnerability could 
  be exploited remotely execute arbitrary code or to create a Denial of Service (DoS).</description>
  <link>http://www.ciac.org/bulletins/s-317.shtml</link>
  <pubDate>19 Jun 2008 16:00 GMT</pubDate>
  <revDate>8 Jul 2008 16:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-164: Tk Vulnerability</title>
  <description>A buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service
   and potentially the execution of arbitrary code.  The risk is MEDIUM.  Could lead to denial of service and potentially the execution of 
   arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-164.shtml</link>
  <pubDate>11 Feb 2008 18:00 GMT</pubDate>
  <revDate>27 Jun 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-316: Vulnerability in Microsoft XML Core Services</title>
  <description>A remote code execution vulnerability exists in Microsoft XML Core Services that could allow an attacker who 
  successfully exploited this vulnerability to make changes to the system with the permissions of the logged-onuser.  The risk is MEDIUM.  
  If the user is logged on with administrative user rights, an attacker could take complete control of the affected system.</description>
  <link>http://www.ciac.org/bulletins/r-316.shtml</link>
  <pubDate>14 Aug 2007 18:00 GMT</pubDate>
  <revDate>27 Jun 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-232: HP-UX Running HP CIFS Server (Samba)</title>
  <description>A potential security vulnerability has been identified with HP-UX running HP CIFS Server (Samba).  The risk is MEDIUM. 
  This vulnerability could be exploited remotely to execute arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-232.shtml</link>
  <pubDate>27 Mar 2008 14:00 GMT</pubDate>
  <revDate>27 Jun 2008 14:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-314: Vulnerability in Bluetooth Stack</title>
  <description>A remote code execution vulnerability exists in the Bluetooth stack in Microsoft Windows because the Bluetooth stack does 
  not correctly handle a large nubmer of service description requests.  The risk is MEDIUM.  The vulnerability could allow an attacker to 
  run code with elevated privileges.  An attacker who successfully exploited this vulenrability could take complete contorl of an 
  affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user 
  rights.</description>
  <link>http://www.ciac.org/bulletins/s-314.shtml</link>
  <pubDate>12 Jun 2008 14:00 GMT</pubDate>
  <revDate>27 Jun 2008 14:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-286: PHP Path Translation Vulnerability</title>
  <description>PHP contains a path translation vulnerability that may allow an attacker to execute arbitrary code.  The risk is MEDIUM.  
  An attacker may be able to execute arbitrary code in the context of an application that uses the vulnerable function. The scope of the 
  impact depends on how the affected application works. Applications that process filename input from the network, such as public-facing 
  web applications, would be vulnerable to a remote attacker.</description>
  <link>http://www.ciac.org/bulletins/s-286.shtml</link>
  <pubDate>9 May 2008 15:00 GMT</pubDate>
  <revDate>27 Jun 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-301: Samba Security and Bug Fix Update</title>
  <description>A heap-based buffer overflow flaw was found in the way Samba clients handle over-sized packets. If a client connected to a 
  malicious Samba server, it was possible to execute arbitrary code as the Samba client user.  The risk is MEDIUM.  A malicious Samba 
  server could run arbitrary code on a Samba client as the Samba client user. Alternately, a malicious client could run arbitrary code 
  on a Samba server with the permissions of the Samba server.</description>
  <link>http://www.ciac.org/bulletins/s-301.shtml</link>
  <pubDate>30 May 2008 12:00 GMT</pubDate>
  <revDate>27 Jun 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-226: Vulnerability in Microsoft Outlook (MS08-015)</title>
  <description>A remote code execution exists in Outlook.  The risk is MEDIUM.  The vulnerability could allow remote code execution if 
  Outlook is passed a specially crafted malito URI. </description>
  <link>http://www.ciac.org/bulletins/s-226.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>5 Jun 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-289: Vulnerability in Microsoft Publisher</title>
  <description>A remote code execution vulnerability exists in the way Microsoft Publisher validates object header data. An attacker 
  could exploit the vulnerability by sending a specially crafted Publisher file which could be an e-mail attachment, or hosted on a 
  specially crafted or compromised Web site.  The risk is MEDIUM.  If a user were logged on with administrative user rights, an attacker 
  who successfully exploited this vulnerability could take complete control of an affected system.</description>
  <link>http://www.ciac.org/bulletins/s-289.shtml</link>
  <pubDate>13 May 2008 20:00 GMT</pubDate>
  <revDate>5 Jun 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-290: Vulnerability in Microsoft Jet Database Engine (JET)</title>
  <description>A buffer overfun vulnerability exists in the Microsoft Jet Database Engine (JET) that could allow remote code execution on 
  an affected system.  An attacker could exploit the vulnerability by creating a specially crafted database query and sending it through 
  an application that is using Jet on an affected system.  The risk is MEDIUM.  An attacker who successfully exploited this vulnerability 
  could take complete control of an affected system.</description>
  <link>http://www.ciac.org/bulletins/s-290.shtml</link>
  <pubDate>13 May 2008 19:00 GMT</pubDate>
  <revDate>5 Jun 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-294: libvorbis Security Update</title>
  <description>Several flaws werer reported in the way libvorbis processed audio data.  The risk is MEDIUM.  An attacker could create a 
  carefully crafted OGG audio file in such a way that it could cause an application linked with libvorbis to crash, or execute arbitrary 
  code when it was opened.</description>
  <link>http://www.ciac.org/bulletins/s-294.shtml</link>
  <pubDate>15 May 2008 20:00 GMT</pubDate>
  <revDate>5 Jun 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-227: Vulnerabilities in Microsoft Excel (MS08-014)</title>
  <description>Remote code vulnerabilities exist in the way Excel:
1) processes data validation records when loading Excel files into memory;
2) handles data when importing files into Excel;
3) Style record data when opening Excel files;
4) handles malformed formulas;
5) handles rich text values when loading application data into memory;
6) handles conditional formatting values; and
7) handles macros when opening specially crafted Excel files.  The risk is MEDIUM.  An attacker could exploit the vulnerabilities by 
sending malformed files which could be hosted on a specially crafted or compromised Web site, or included as an e-mail attachment.</description>
  <link>http://www.ciac.org/bulletins/s-227.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>5 Jun 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-272: Speex Security Update</title>
  <description>The Speex library was found to not properly validate input values read from the Speex files headers, which could allow 
  arbitrary code execution.  The risk is MEDIUM. An attacker could create a malicious Speex file that would crash an application or, 
  possibly, allow arbitrary code execution with the privileges of the application calling the Speex library.</description>
  <link>http://www.ciac.org/bulletins/s-272.shtml</link>
  <pubDate>25 Apr 2008 12:00 GMT</pubDate>
  <revDate>29 May 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-297: libxslt Security Update</title>
  <description>The libxslt library did not properly process long "transformation match" conditions in the XSL stylesheet files.  The risk
  is MEDIUM.  An attacker could create a malicious XSL file that would cause a crash, or, possibly, execute and arbitrary code with the 
  privileges of the application using libxslt library to perform XSL transformations.</description>
  <link>http://www.ciac.org/bulletins/s-297.shtml</link>
  <pubDate>22 May 2008 13:00 GMT</pubDate>
  <revDate>29 May 2008 13:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-163: Simple DirectMedia Layer 1.2 Vulnerabilities</title>
  <description>Several local/remote vulnerabilities have been discovered in the image loading library for the Simple DirectMedia 
  Layer 1.2.  The risk is MEDIUM.  Could result in denial of service and potentially the execution of arbitary code.</description>
  <link>http://www.ciac.org/bulletins/s-163.shtml</link>
  <pubDate>11 Feb 2008 18:00 GMT</pubDate>
  <revDate>20 May 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-288: Vulnerabilities in Microsoft Word</title>
  <description>A remote code execution vulnerability exists in the way that Microsoft Word  handle specially crafted Word files. The 
  vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed CSS value.  The 
  risk is MEDIUM.  An attacker who successfully exploited this vulnerability could take complete control of an attected 
  system.</description>
  <link>http://www.ciac.org/bulletins/s-288.shtml</link>
  <pubDate>13 May 2008 19:00 GMT</pubDate>
  <revDate>20 May 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-224: Vulnerabilities in Microsoft Office Web Components (MS08-017)</title>
  <description>Remote code execution vulnerabilities exist in the way Microsoft Office Web Components manages memory resources.  The 
  risk is MEDIUM.  An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web 
  page, the vulnerability could allos remote code execution. </description>
  <link>http://www.ciac.org/bulletins/s-224.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>15 May 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-037: Perl-Compatible Regular Expression (PCRE) Vulnerabilities</title>
  <description>There are several security issues in PCRE library which potentially allow attackers to execute arbitrary code by compiling 
  specially crafted regular expressions.  The risk is LOW.  Could potentially allow attackers to execute arbitrary code by compiling 
  specially crafted regular expressions.</description>
  <link>http://www.ciac.org/bulletins/s-037.shtml</link>
  <pubDate>7 Nov 2007 15:00 GMT</pubDate>
  <revDate>8 May 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-295: Vulnerabilities in .NET Framework (931212)</title>
  <description>A remote code execution vulnerability exists in .NET Framework that could allow an attacker who successfully exploited this vulnerability to make changes to the system with the permissions of the logged-on user.  The risk is HIGH.  A remote code execution vulnerability exists in .NET Framework that could allow an attacker who successfully exploited this vulnerability to make changes to the system with the permissions of the logged-on user. </description>
  <link>http://www.ciac.org/bulletins/r-295.shtml</link>
  <pubDate>10 Jul 2007 20:00 GMT</pubDate>
  <revDate>8 May 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-269: kdegraphics Security Update</title>
  <description>There is a flaw in the way kpdf displayed malformed fonts embedded in PDF files which could potentially execute arbitrary 
  code.  The risk is MEDIUM. An attacker could create a malicious PDF file that would cause kpdf to crash, or potentially, execute 
  arbitrary code when opened.</description>
  <link>http://www.ciac.org/bulletins/s-269.shtml</link>
  <pubDate>25 Apr 2008 11:00 GMT</pubDate>
  <revDate>8 May 2008 11:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-282: HP-UX Running WBEM Services</title>
  <description>Potential security vulnerabilities have been identified with HP-UX running WBEM Services that could remotely execute 
  arbitrary code or gain extended privileges.  The risk is MEDIUM.  These vulnerabilities could be exploited remotely to execute 
  arbitrary code or to gain extended privileges.</description>
  <link>http://www.ciac.org/bulletins/s-282.shtml</link>
  <pubDate>1 May 2008 15:00 GMT</pubDate>
  <revDate>7 May 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-100: GNU Tar Vulnerabilities</title>
  <description>Several vulnerabilities have been discovered in GNU Tar. The risk is MEDIUM.  May lead to arbitrary code execution when 
  processing maliciously crafted archives.</description>
  <link>http://www.ciac.org/bulletins/s-100.shtml</link>
  <pubDate>3 Jan 2008 22:00 GMT</pubDate>
  <revDate>7 May 2008 22:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-355: PHP Security Update</title>
  <description>There are several vulnerabilities in PHP.  The risk is MEDIUM.  Could possibly execute arbitrary code as the apache 
  user.</description>
  <link>http://www.ciac.org/bulletins/r-355.shtml</link>
  <pubDate>20 Sep 2007 20:00 GMT</pubDate>
 <revDate>07 May 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-270: SeaMonkey Security Update</title>
  <description>A flaw was found in the processing of malformed JavaScript content which could lead to the execution of arbitrary code.  
  The risk is MEDIUM.  A web page containing such maliciuos content could cause SeaMonkey to crash or, potentially, execute arbitrary 
  code as the user running SeaMonkey.</description>
  <link>http://www.ciac.org/bulletins/s-270.shtml</link>
  <pubDate>25 Apr 2008 11:00 GMT</pubDate>
  <revDate>2 May 2008 11:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-225: Vulnerabilities in Microsoft Office (MS08-016)</title>
  <description>There are remote code execution vulnerabilities that exist in the way Microsoft Office handles specially crafted Excel 
  files and processes malformed Office files.  The risk is MEDIUM.  An attacker could exploit the vulnerability by creating a malformed 
  file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site. If a user were logged 
  on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an 
  affected system.</description>
  <link>http://www.ciac.org/bulletins/s-225.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>1 May 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-232: Vulnerability in Microsoft Office</title>
  <description>A remote code execution vulnerability exists in the way Microsoft Office handles a specially crafted drawing object.  
  The risk is MEDIUM.  Code runs in the context of the user.</description>
  <link>http://www.ciac.org/bulletins/r-232.shtml</link>
  <pubDate>9 May 2007 12:00 GMT</pubDate>
  <revDate>1 May 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-241: Multiple DLSw Denial of Service Vulnerabilities</title>
  <description>Cisco IOS contains multiple vulnerabilities in the Data-link Switching (DLSw) feature that may result in a reload or 
  memory leaks when processing specially crafted UDP or IP Protocol 91 packets.  The risk is LOW.  Successful exploitation of these 
  vulnerabilities may result in the reload of the device or memory leaks, leading to a DoS condition.</description>
  <link>http://www.ciac.org/bulletins/s-241.shtml</link>
  <pubDate>27 Mar 2008 19:00 GMT</pubDate>
  <revDate>28 Apr 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-092: Adobe Flash Player Vulnerability</title>
  <description>Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits 
  these potential vulnerabilities to take control of the affected system.  The risk is MEDIUM.  Could lead to the potential execution of 
  arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-092.shtml</link>
  <pubDate>21 Dec 2007 21:00 GMT</pubDate>
  <revDate>28 Apr 2008 21:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-257: Cumulative Security Update for Internet Explorer</title>
  <description>A remote code execution vulnerability exists in Internet Explorer because of the way that it processes data streams.  An 
  attacker could exploit the vulnerability by constructing a specially crafted Web page.  The risk is MEDIUM.  When a user views the Web 
  page, the vulnerability could allow remote code execution.  An attacker who successfully exploited this vulnerability could gain the 
  same user rights as the logged on user.</description>
  <link>http://www.ciac.org/bulletins/s-257.shtml</link>
  <pubDate>9 Apr 2008 20:00 GMT</pubDate>
  <revDate>24 Apr 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-252: Vulnerabilities in Microsoft Visio</title>
  <description>Several remote code execution vulnerabilities exists in the way Microsoft Visio validates:
1) object header data in specially crafted file; and 
2) memory allocations when loading specially-crafted .DXF files from disk into memory.  The risk is MEDIUM.  An attacker could exploit 
the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a specially crafted or 
compromised Web site.</description>
  <link>http://www.ciac.org/bulletins/s-252.shtml</link>
  <pubDate>9 Apr 2008 19:00 GMT</pubDate>
  <revDate>24 Apr 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>

</channel>
</rss>

