<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>JC3-CIRC Updates</title>
<description>CIRC's latest security bulletins.</description>
<link>http://circ.jc3.doe.gov/index.html</link>
<item>
  <title>U-170: Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-170.shtml</link>
  <pubDate>16 May 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-169: Sympa Multiple Security Bypass Vulnerabilities</title>
  <description>Sympa Multiple Security Bypass Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-169.shtml</link>
  <pubDate>15 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-168: EMC Documentum Information Rights Management Server Bugs Let Remote Authenticated Users Deny Service</title>
  <description>EMC Documentum Information Rights Management Server Bugs Let Remote Authenticated Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-168.shtml</link>
  <pubDate>14 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-167: OpenSSL Invalid TLS/DTLS Record Processing Lets Remote Users Deny Service</title>
  <description>OpenSSL Invalid TLS/DTLS Record Processing Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-167.shtml</link>
  <pubDate>11 May 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-166: Adobe Shockwave Player Memory Corruption Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Shockwave Player Memory Corruption Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-166.shtml</link>
  <pubDate>10 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-165: Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Spoof Address Bar URLs</title>
  <description>Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Spoof Address Bar URLs</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-165.shtml</link>
  <pubDate>09 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-164: Microsoft Security Bulletin Advance Notification for May 2012</title>
  <description>Microsoft Security Bulletin Advance Notification for May 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-164.shtml</link>
  <pubDate>08 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-163: PHP Command Parameter Bug Lets Remote Users Obtain Potentially Sensitive Information and Execute Arbitrary Code</title>
  <description>PHP Command Parameter Bug Lets Remote Users Obtain Potentially Sensitive Information and Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-163.shtml</link>
  <pubDate>07 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-162: Drupal Multiple Vulnerabilities</title>
  <description>Drupal Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-162.shtml</link>
  <pubDate>04 May 2012 07:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-161: Citrix Provisioning Services Unspecified Flaw Lets Remote Users Execute Arbitrary Code</title>
  <description>Citrix Provisioning Services Unspecified Flaw Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-161.shtml</link>
  <pubDate>03 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-160: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-160.shtml</link>
  <pubDate>02 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-159: Red Hat Enterprise MRG Messaging Qpid Bug Lets Certain Remote Users Bypass Authentication</title>
  <description>Red Hat Enterprise MRG Messaging Qpid Bug Lets Certain Remote Users Bypass Authentication</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-159.shtml</link>
  <pubDate>01 May 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-158: HP NonStop Server Java Multiple Vulnerabilities</title>
  <description>HP NonStop Server Java Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-158.shtml</link>
  <pubDate>30 Apr 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-157: Ruby Mail Gem Directory Traversal and Shell Command Injection Vulnerabilities</title>
  <description>Ruby Mail Gem Directory Traversal and Shell Command Injection Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-157.shtml</link>
  <pubDate>27 Apr 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-156: Red Hat update for JBoss Enterprise Portal Platform</title>
  <description>Red Hat update for JBoss Enterprise Portal Platform</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-156.shtml</link>
  <pubDate>26 Apr 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-155: WebCalendar Access Control and File Inclusion Bugs Let Remote Users Potentially Execute Arbitrary Code</title>
  <description>WebCalendar Access Control and File Inclusion Bugs Let Remote Users Potentially Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-155.shtml</link>
  <pubDate>25 Apr 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-154: IBM Rational ClearQuest ActiveX Control Buffer Overflow Vulnerability</title>
  <description>IBM Rational ClearQuest ActiveX Control Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-154.shtml</link>
  <pubDate>24 Apr 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-153: EMC Data Protection Advisor Server and Collector Bugs Let Remote Users Deny Service</title>
  <description>EMC Data Protection Advisor Server and Collector Bugs Let Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-153.shtml</link>
  <pubDate>23 Apr 2012 04:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-152: OpenSSL Data Processing Vulnerability</title>
  <description>OpenSSL Data Processing Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-152.shtml</link>
  <pubDate>20 Apr 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-151: Bugzilla Cross-Site Request Forgery Vulnerability </title>
  <description>Bugzilla Cross-Site Request Forgery Vulnerability </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-151.shtml</link>
  <pubDate>19 Apr 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-150: Oracle Critical Patch Update Advisory - April 2012</title>
  <description>Oracle Critical Patch Update Advisory - April 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-150.shtml</link>
  <pubDate>18 Apr 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-149: Apache OFBiz Cross-Site Scripting and Code Execution Vulnerabilities</title>
  <description>Apache OFBiz Cross-Site Scripting and Code Execution Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-149.shtml</link>
  <pubDate>17 Apr 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-148: ActiveScriptRuby GRScript18.dll ActiveX Control</title>
  <description>ActiveScriptRuby GRScript18.dll ActiveX Control</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-148.shtml</link>
  <pubDate>16 Apr 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-147: Red Hat Enterprise MRG Grid Input Validation Flaw</title>
  <description>Red Hat Enterprise MRG Grid Input Validation Flaw</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-147.shtml</link>
  <pubDate>13 Apr 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-146: Adobe Reader/Acrobat Multiple Vulnerabilities</title>
  <description>Adobe Reader/Acrobat Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-146.shtml</link>
  <pubDate>12 Apr 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-145: Microsoft Security Bulletin Summary for April 2012</title>
  <description>Microsoft Security Bulletin Summary for April 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-145.shtml</link>
  <pubDate>11 Apr 2012 07:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-144: Juniper Secure Access Input Validation Flaw Permits Cross-Site Scripting Attacks</title>
  <description>Juniper Secure Access Input Validation Flaw Permits Cross-Site Scripting Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-144.shtml</link>
  <pubDate>10 Apr 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-143: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-143.shtml</link>
  <pubDate>09 Apr 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-142: HP Onboard Administrator Bugs Let Remote Users Gain Access</title>
  <description>HP Onboard Administrator Bugs Let Remote Users Gain Access</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-142.shtml</link>
  <pubDate>06 Apr 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-141: Sourcefire Defense Center Bugs</title>
  <description>Sourcefire Defense Center Bugs</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-141.shtml</link>
  <pubDate>05 Apr 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-140: HP-UX Unspecified Flaw in DCE Lets Remote Users Execute Arbitrary Code</title>
  <description>HP-UX Unspecified Flaw in DCE Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-140.shtml</link>
  <pubDate>04 Apr 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-139: IBM Tivoli Directory Server Input Validation Flaw</title>
  <description>IBM Tivoli Directory Server Input Validation Flaw</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-139.shtml</link>
  <pubDate>03 Apr 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-138: Cisco IOS IPSec IKE Unspecified Denial of Service Vulnerability</title>
  <description>Cisco IOS IPSec IKE Unspecified Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-138.shtml</link>
  <pubDate>02 Apr 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-137: HP Performance Manager Unspecified Bug Lets Remote Users Execute Arbitrary Codes</title>
  <description>HP Performance Manager Unspecified Bug Lets Remote Users Execute Arbitrary Codes</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-137.shtml</link>
  <pubDate>30 Mar 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-136: Adobe Flash Player Lets Remote Users Execute Arbitrary Code</title>
  <description>Adobe Flash Player Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-136.shtml</link>
  <pubDate>29 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-135: HP WBEM Discloses Diagnostic Data to Remote and Local Users</title>
  <description>HP WBEM Discloses Diagnostic Data to Remote and Local Users</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-135.shtml</link>
  <pubDate>28 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-134: Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service</title>
  <description>Apache Traffic Server Host Header Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-134.shtml</link>
  <pubDate>27 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-133: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-133.shtml</link>
  <pubDate>26 Mar 2012 07:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-132: Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks</title>
  <description>Apache Wicket Input Validation Flaw in 'wicket:pageMapName' Parameter Permits Cross-Site Scripting Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-132.shtml</link>
  <pubDate>23 Mar 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-131: Adobe Photoshop TIFF Image Heap Overflow Lets Remote Users Execute Arbitrary Code</title>
  <description>Adobe Photoshop TIFF Image Heap Overflow Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-131.shtml</link>
  <pubDate>22 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-130: JBoss Operations Network LDAP Authentication Bug Lets Remote Users Bypass Authentication</title>
  <description>JBoss Operations Network LDAP Authentication Bug Lets Remote Users Bypass Authentication</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-130.shtml</link>
  <pubDate>21 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-129: RSA enVision Bugs Permit Cross-Site Scripting, SQL Injection, and Directory Traversal Attacks</title>
  <description>RSA enVision Bugs Permit Cross-Site Scripting, SQL Injection, and Directory Traversal Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-129.shtml</link>
  <pubDate>20 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-128: VMware ESX/ESXi Buffer Overflow and Null Pointer Dereference Lets Local Users Gain Elevated Privileges</title>
  <description>VMware ESX/ESXi Buffer Overflow and Null Pointer Dereference Lets Local Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-128.shtml</link>
  <pubDate>19 Mar 2012 04:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-127: Microsoft Security Bulletin MS12-020 - Critical</title>
  <description>Microsoft Security Bulletin MS12-020 - Critical</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-127.shtml</link>
  <pubDate>17 Mar 2012 01:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-126: Cisco Adaptive Security Appliances Port Forwarder ActiveX Control Buffer Overflow Vulnerability</title>
  <description>Cisco Adaptive Security Appliances Port Forwarder ActiveX Control Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-126.shtml</link>
  <pubDate>16 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-125:  Cisco ASA Multiple Bugs Let Remote Users Deny Service </title>
  <description> Cisco ASA Multiple Bugs Let Remote Users Deny Service </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-125.shtml</link>
  <pubDate>15 Mar 2012 07:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-124: Microsoft Security Bulletin Advance Notification for March 2012</title>
  <description>Microsoft Security Bulletin Advance Notification for March 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-124.shtml</link>
  <pubDate>14 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-123: OpenSSL S/MIME Parsing Null Pointer Dereference Lets Remote Users Deny Service </title>
  <description>OpenSSL S/MIME Parsing Null Pointer Dereference Lets Remote Users Deny Service </description>
  <link>http://www.doecirc.energy.gov/bulletins/U-123.shtml</link>
  <pubDate>13 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-122: Google Chrome Two Code Execution Vulnerabilities</title>
  <description>Google Chrome Two Code Execution Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-122.shtml</link>
  <pubDate>12 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-121: Apple iOS Bugs Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information </title>
  <description>Apple iOS Bugs Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-121.shtml</link>
  <pubDate>09 Mar 2012 08:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-120: RSA SecurID Software Token Converter Unspecified Buffer Overflow Vulnerability</title>
  <description>RSA SecurID Software Token Converter Unspecified Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-120.shtml</link>
  <pubDate>08 Mar 2012 09:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-119: Blackberry PlayBook Unspecified WebKit Bug Lets Remote Users Execute Arbitrary Code</title>
  <description>Blackberry PlayBook Unspecified WebKit Bug Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-119.shtml</link>
  <pubDate>07 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-118: Adobe Flash Player Bugs Let Remote Users Execute Arbitrary Code and Obtain Information</title>
  <description>Adobe Flash Player Bugs Let Remote Users Execute Arbitrary Code and Obtain Information</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-118.shtml</link>
  <pubDate>06 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-117: Potential security vulnerability has been identified with certain HP printers and HP digital senders. </title>
  <description>Potential security vulnerability has been identified with certain HP printers and HP digital senders. </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-117.shtml</link>
  <pubDate>05 Mar 2012 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-116: IBM Tivoli Provisioning Manager Express for Software Distribution Multiple Vulnerabilites</title>
  <description>IBM Tivoli Provisioning Manager Express for Software Distribution Multiple Vulnerabilites</description>
  <link>http://www.doecirc.energy.gov/bulletins/U-116.shtml</link>
  <pubDate>05 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-115: Novell GroupWise Client Address Book Processing Buffer Overflow Vulnerability</title>
  <description>Novell GroupWise Client Address Book Processing Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-115.shtml</link>
  <pubDate>02 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-114: IBM Personal Communications WS File Processing Buffer Overflow Vulnerability</title>
  <description>IBM Personal Communications WS File Processing Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-114.shtml</link>
  <pubDate>01 Mar 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-113: OpenSSL S/MIME Parsing Null Pointer Dereference Lets Remote Users Deny Service</title>
  <description>OpenSSL S/MIME Parsing Null Pointer Dereference Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-113.shtml</link>
  <pubDate>29 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-112: PostgreSQL Bugs Let Remote Authenticated Users Gain Elevated Privileges, Inject SQL Commands, and Spoof Certificates</title>
  <description>PostgreSQL Bugs Let Remote Authenticated Users Gain Elevated Privileges, Inject SQL Commands, and Spoof Certificates</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-112.shtml</link>
  <pubDate>28 Feb 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-111: IBM AIX ICMP Processing Flaw Lets Remote Users Deny Service</title>
  <description>IBM AIX ICMP Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-111.shtml</link>
  <pubDate>27 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-110: Samba Bug Lets Remote Users Execute Arbitrary Code</title>
  <description>Samba Bug Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-110.shtml</link>
  <pubDate>24 Feb 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-109: Bugzilla Cross-Site Request Forgery Vulnerability </title>
  <description>Bugzilla Cross-Site Request Forgery Vulnerability </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-109.shtml</link>
  <pubDate>23 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-108: Net4Switch ipswcom ActiveX Control Buffer Overflow Vulnerability</title>
  <description>Net4Switch ipswcom ActiveX Control Buffer Overflow Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-108.shtml</link>
  <pubDate>22 Feb 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-107: Cisco NX-OS IP Packet Processing Flaw Lets Remote Users Deny Service</title>
  <description>Cisco NX-OS IP Packet Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-107.shtml</link>
  <pubDate>21 Feb 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-106: Citrix XenServer Multiple Flaws in Web Self Service Have Unspecified Impact</title>
  <description>Citrix XenServer Multiple Flaws in Web Self Service Have Unspecified Impact</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-106.shtml</link>
  <pubDate>17 Feb 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-105: Oracle Java SE Critical Patch Update Advisory</title>
  <description>Oracle Java SE Critical Patch Update Advisory</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-105.shtml</link>
  <pubDate>16 Feb 2012 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-104: Adobe Flash Player Multiple Vulnerabilities</title>
  <description>Adobe Flash Player Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-104.shtml</link>
  <pubDate>16 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-103: Microsoft Security Bulletin Advance Notification for February 2012</title>
  <description>Microsoft Security Bulletin Advance Notification for February 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-103.shtml</link>
  <pubDate>15 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-102: Cisco IronPort Encryption Appliance Input Validation Flaw Permits Cross-Site Scripting Attacks</title>
  <description>Cisco IronPort Encryption Appliance Input Validation Flaw Permits Cross-Site Scripting Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-102.shtml</link>
  <pubDate>14 Feb 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-101: Mozilla Firefox / Thunderbird / SeaMonkey XBL Binding Use-After-Free Vulnerability</title>
  <description>Mozilla Firefox / Thunderbird / SeaMonkey XBL Binding Use-After-Free Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-101.shtml</link>
  <pubDate>13 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-100: Google Chrome Multiple Vulnerabilities </title>
  <description>Google Chrome Multiple Vulnerabilities </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-100.shtml</link>
  <pubDate>10 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-099: MySQL Unspecified Code Execution Vulnerability</title>
  <description>MySQL Unspecified Code Execution Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-099.shtml</link>
  <pubDate>09 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-098: ISC BIND Deleted Domain Name Resolving Vulnerability</title>
  <description>ISC BIND Deleted Domain Name Resolving Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-098.shtml</link>
  <pubDate>08 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-097: PHP php_register_variable_ex Code Execution Vulnerability </title>
  <description>PHP php_register_variable_ex Code Execution Vulnerability </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-097.shtml</link>
  <pubDate>07 Feb 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-096: IBM AIX TCP Large Send Offload Bug Lets Remote Users Deny Service</title>
  <description>IBM AIX TCP Large Send Offload Bug Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-096.shtml</link>
  <pubDate>06 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-095: HP Data Protector Media Operations Lets Remote Users Execute Arbitrary Code </title>
  <description>HP Data Protector Media Operations Lets Remote Users Execute Arbitrary Code </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-095.shtml</link>
  <pubDate>03 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-094: EMC Documentum Content Server Lets Local Administrative Users Gain Elevated Privileges</title>
  <description>EMC Documentum Content Server Lets Local Administrative Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-094.shtml</link>
  <pubDate>02 Feb 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-093: Mozilla Firefox Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site Scripting Attacks </title>
  <description>Mozilla Firefox Multiple Flaws Permit Remote Code Execution, Information Disclosure, and Cross-Site Scripting Attacks </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-093.shtml</link>
  <pubDate>01 Feb 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-092: Sudo Format String Bug Lets Local Users Gain Elevated Privileges</title>
  <description>Sudo Format String Bug Lets Local Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-092.shtml</link>
  <pubDate>31 Jan 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-091: cURL Lets Remote Users Decrypt SSL/TLS Traffic </title>
  <description>cURL Lets Remote Users Decrypt SSL/TLS Traffic </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-091.shtml</link>
  <pubDate>30 Jan 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-090: RSA enVision Discloses Environment Variable Information to Remote Users</title>
  <description>RSA enVision Discloses Environment Variable Information to Remote Users</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-090.shtml</link>
  <pubDate>27 Jan 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-089: U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands</title>
  <description>U-089:Apache Struts ParameterInterceptor() Flaw Lets Remote Users Execute Arbitrary Commands</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-089.shtml</link>
  <pubDate>26 Jan 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-088: Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Symantec pcAnywhere Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-088.shtml</link>
  <pubDate>25 Jan 2012 10:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-087: HP-UX update for Java</title>
  <description>HP-UX update for Java</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-087.shtml</link>
  <pubDate>24 Jan 2012 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-086: Linux Kernel /proc//mem Privilege Escalation Vulnerability</title>
  <description>Linux Kernel /proc//mem Privilege Escalation Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-086.shtml</link>
  <pubDate>23 Jan 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-085: OpenSSL DTLS Bug Lets Remote Users Deny Service</title>
  <description>OpenSSL DTLS Bug Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-085.shtml</link>
  <pubDate>20 Jan 2012 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-084: Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges</title>
  <description>Cisco Digital Media Manager Lets Remote Authenticated Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-084.shtml</link>
  <pubDate>19 Jan 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-083: Oracle Critical Patch Update Advisory - January 2012</title>
  <description>Oracle Critical Patch Update Advisory - January 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-083.shtml</link>
  <pubDate>18 Jan 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-082: PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service</title>
  <description>PHP Null Pointer Dereference in zend_strndup() Lets Local Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-082.shtml</link>
  <pubDate>17 Jan 2012 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-081: McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code</title>
  <description>McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-081.shtml</link>
  <pubDate>13 Jan 2012 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-080: Linux Kernel XFS Heap Overflow May Let Remote Users Execute Arbitrary Code</title>
  <description>Linux Kernel XFS Heap Overflow May Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-080.shtml</link>
  <pubDate>12 Jan 2012 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-079: Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-079.shtml</link>
  <pubDate>11 Jan 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-078: Microsoft Security Bulletin Advance Notification for January 2012</title>
  <description>Microsoft Security Bulletin Advance Notification for January 2012</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-078.shtml</link>
  <pubDate>10 Jan 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-077: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-077.shtml</link>
  <pubDate>09 Jan 2012 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-076: OpenSSL Bugs Let Remote Users Deny Service, Obtain Information, and Potentially Execute Arbitrary Code</title>
  <description>OpenSSL Bugs Let Remote Users Deny Service, Obtain Information, and Potentially Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-076.shtml</link>
  <pubDate>06 Jan 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-075: Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code</title>
  <description>Apache Struts Bug Lets Remote Users Overwrite Files and Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-075.shtml</link>
  <pubDate>05 Jan 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-074: Microsoft .NET Bugs Let Remote Users Execute Arbitrary Commands, Access User Accounts, and Redirect Users</title>
  <description>Microsoft .NET Bugs Let Remote Users Execute Arbitrary Commands, Access User Accounts, and Redirect Users</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-074.shtml</link>
  <pubDate>04 Jan 2012 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-073: Bugzilla Flaws Permit Cross-Site Scripting and Cross-Site Request Forgery Attacks</title>
  <description>Bugzilla Flaws Permit Cross-Site Scripting and Cross-Site Request Forgery Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-073.shtml</link>
  <pubDate>03 Jan 2012 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-072: Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service</title>
  <description>Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-072.shtml</link>
  <pubDate>30 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-071: HP Database Archiving Software Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>HP Database Archiving Software Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-071.shtml</link>
  <pubDate>29 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-070: Redhat krb5 Critical Security Update</title>
  <description>Redhat krb5 Critical Security Update</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-070.shtml</link>
  <pubDate>28 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-069: Telnet code execution vulnerability: FreeBSD and Kerberos</title>
  <description>Telnet code execution vulnerability: FreeBSD and Kerberos</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-069.shtml</link>
  <pubDate>27 Dec 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-068: Linux Kernel SG_IO ioctl Bug Lets Local Users Gain Elevated Privileges</title>
  <description>Linux Kernel SG_IO ioctl Bug Lets Local Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-068.shtml</link>
  <pubDate>23 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-067: WebSVN Input Validation Flaw in getLog() Permits Cross-Site Scripting Attacks</title>
  <description>WebSVN Input Validation Flaw in getLog() Permits Cross-Site Scripting Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-067.shtml</link>
  <pubDate>22 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-066: Mozilla Firefox / Thunderbird Multiple Vulnerabilities</title>
  <description>Mozilla Firefox / Thunderbird Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-066.shtml</link>
  <pubDate>21 Dec 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-065: Microsoft Windows win32k.sys Memory Corruption Vulnerability</title>
  <description>Microsoft Windows win32k.sys Memory Corruption Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-065.shtml</link>
  <pubDate>20 Dec 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-064: Adobe Acrobat/Reader PRC Memory Corruption Error Lets Remote Users Execute Arbitrary Code</title>
  <description>Adobe Acrobat/Reader PRC Memory Corruption Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-064.shtml</link>
  <pubDate>19 Dec 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-063: RSA SecurID Software Token for Windows DLL Loading Error Lets Remote Users Execute Arbitrary Code</title>
  <description>RSA SecurID Software Token for Windows DLL Loading Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-063.shtml</link>
  <pubDate>16 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-062: Pidgin SILC (Secure Internet Live Conferencing) Protocol Denial of Service Vulnerability</title>
  <description>Pidgin SILC (Secure Internet Live Conferencing) Protocol Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-062.shtml</link>
  <pubDate>15 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-061: RSA Adaptive Authentication Bugs Let Remote Users Bypass Certain Security Controls</title>
  <description>RSA Adaptive Authentication Bugs Let Remote Users Bypass Certain Security Controls</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-061.shtml</link>
  <pubDate>14 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-060: Security update: Hotfix available for ColdFusion</title>
  <description>Security update: Hotfix available for ColdFusion</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-060.shtml</link>
  <pubDate>13 Dec 2011 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-059: Blackberry PlayBook File Sharing Option Lets Local Users Gain Elevated Privileges</title>
  <description>Blackberry PlayBook File Sharing Option Lets Local Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-059.shtml</link>
  <pubDate>13 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-058: Apache Struts Conversion Error OGNL Expression Injection Vulnerability</title>
  <description>Apache Struts Conversion Error OGNL Expression Injection Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-058.shtml</link>
  <pubDate>12 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-057: Microsoft Security Bulletin Advance Notification for December 2011</title>
  <description>Microsoft Security Bulletin Advance Notification for December 2011</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-057.shtml</link>
  <pubDate>09 Dec 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-056: Linux Kernel HFS Buffer Overflow Lets Local Users Gain Root Privileges</title>
  <description>Linux Kernel HFS Buffer Overflow Lets Local Users Gain Root Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-056.shtml</link>
  <pubDate>09 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-055: Adobe Flash Player Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Flash Player Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-055.shtml</link>
  <pubDate>08 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-054: Security Advisory for Adobe Reader and Acrobat</title>
  <description>Security Advisory for Adobe Reader and Acrobat</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-054.shtml</link>
  <pubDate>07 Dec 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-053: Linux kexec Bugs Let Local and Remote Users Obtain Potentially Sensitive Information</title>
  <description>Linux kexec Bugs Let Local and Remote Users Obtain Potentially Sensitive Information</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-053.shtml</link>
  <pubDate>07 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-052: HP Protect Tools Device Access Manager Unspecified Bug Lets Remote Users Deny Service and Execute Arbitrary Code</title>
  <description>HP Protect Tools Device Access Manager Unspecified Bug Lets Remote Users Deny Service and Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-052.shtml</link>
  <pubDate>06 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-051: Skype Discloses IP Addresses to Remote Users</title>
  <description>Skype Discloses IP Addresses to Remote Users</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-051.shtml</link>
  <pubDate>05 Dec 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-050: Adobe Flex SDK Input Validation Flaw Permits Cross-Site Scripting Attacks</title>
  <description>Adobe Flex SDK Input Validation Flaw Permits Cross-Site Scripting Attacks</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-050.shtml</link>
  <pubDate>02 Dec 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-049: IBM Tivoli Netcool Reporter CGI Bug Lets Remote Users Inject Commands on the Target System</title>
  <description>IBM Tivoli Netcool Reporter CGI Bug Lets Remote Users Inject Commands on the Target System</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-049.shtml</link>
  <pubDate>01 Dec 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-048: HP LaserJet Printers Unspecified Flaw Lets Remote Users Update Firmware with Arbitrary Code</title>
  <description>HP LaserJet Printers Unspecified Flaw Lets Remote Users Update Firmware with Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-048.shtml</link>
  <pubDate>30 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-047: Siemens Automation License Manager Bugs Let Remote Users Deny Service or Execute Arbitrary Code</title>
  <description>Siemens Automation License Manager Bugs Let Remote Users Deny Service or Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-047.shtml</link>
  <pubDate>29 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-046: Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers</title>
  <description>Apache mod_proxy/mod_rewrite Bug Lets Remote Users Access Internal Servers</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-046.shtml</link>
  <pubDate>28 Nov 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-045: Windows Win32k.sys Keyboard Layout Bug Lets Local Users Deny Service </title>
  <description>Windows Win32k.sys Keyboard Layout Bug Lets Local Users Deny Service </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-045.shtml</link>
  <pubDate>25 Nov 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-044: HP Operations Agent and Performance Agent Lets Local Users Access a Restricted Directory</title>
  <description>HP Operations Agent and Performance Agent Lets Local Users Access a Restricted Directory</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-044.shtml</link>
  <pubDate>23 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-043: Attachmate Reflection Buffer Overflow in FTP Client Lets Remote Servers Execute Arbitrary Code</title>
  <description>Attachmate Reflection Buffer Overflow in FTP Client Lets Remote Servers Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-043.shtml</link>
  <pubDate>22 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-042: Mac RealPlayer Multiple Vulnerabilities</title>
  <description>Mac RealPlayer Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-042.shtml</link>
  <pubDate>21 Nov 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-041: Google Chrome Out-of-Bounds Write Error Lets Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Out-of-Bounds Write Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-041.shtml</link>
  <pubDate>18 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-040: HP-UX System Administration Manager Lets Local Users Gain Elevated Privileges</title>
  <description>HP-UX System Administration Manager Lets Local Users Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-040.shtml</link>
  <pubDate>17 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-039: ISC Update: BIND 9 Resolver crashes after logging an error in query.c</title>
  <description>ISC Update: BIND 9 Resolver crashes after logging an error in query.c</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-039.shtml</link>
  <pubDate>16 Nov 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-038: BIND 9 Resolver crashes after logging an error in query.c </title>
  <description>BIND 9 Resolver crashes after logging an error in query.c </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-038.shtml</link>
  <pubDate>16 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-037: Linux Kernel NFSv4 ACL Attribute Processing Error Lets Remote Users Execute Arbitrary Code</title>
  <description>Linux Kernel NFSv4 ACL Attribute Processing Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-037.shtml</link>
  <pubDate>16 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-036: Apple iOS Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Apple iOS Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-036.shtml</link>
  <pubDate>15 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-035: Adobe Flash Player Multiple Vulnerabilities</title>
  <description>Adobe Flash Player Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-035.shtml</link>
  <pubDate>14 Nov 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-034: Fraudulent Digital Certificates Could Allow Spoofing</title>
  <description>Fraudulent Digital Certificates Could Allow Spoofing</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-034.shtml</link>
  <pubDate>10 Nov 2011 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-033: Microsoft Security Bulletin Summary for November 2011</title>
  <description>Microsoft Security Bulletin Summary for November 2011</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-033.shtml</link>
  <pubDate>10 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-032: Microsoft Security Bulletin Windows TCP/IP MS11-083 - Critical</title>
  <description>Microsoft Security Bulletin Windows TCP/IP MS11-083 - Critical</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-032.shtml</link>
  <pubDate>09 Nov 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-031: Microsoft Active Directory CRL Validation Flaw Lets Remote Users Bypass Authentication</title>
  <description>Microsoft Active Directory CRL Validation Flaw Lets Remote Users Bypass Authentication</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-031.shtml</link>
  <pubDate>09 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-030: Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges</title>
  <description>Apache Tomcat Lets Untrusted Web Applications Gain Elevated Privileges</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-030.shtml</link>
  <pubDate>09 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-029: TCP/IP Services for OpenVMS POP/IMAP Service Bug Lets Remote Users Gain Unauthorized Access</title>
  <description>TCP/IP Services for OpenVMS POP/IMAP Service Bug Lets Remote Users Gain Unauthorized Access</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-029.shtml</link>
  <pubDate>08 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-028: Microsoft Windows win32k.sys TrueType Font Parsing Vulnerability</title>
  <description>Microsoft Windows win32k.sys TrueType Font Parsing Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-028.shtml</link>
  <pubDate>07 Nov 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-027: RSA Key Manager Appliance Session Logout Bug Fails to Terminate Sessions</title>
  <description>RSA Key Manager Appliance Session Logout Bug Fails to Terminate Sessions</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-027.shtml</link>
  <pubDate>04 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-026: Cisco Small Business SRP500 Series Bug Lets Remote Users Inject Commands</title>
  <description>Cisco Small Business SRP500 Series Bug Lets Remote Users Inject Commands</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-026.shtml</link>
  <pubDate>03 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-025: HP OpenView Network Node Manager Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>HP OpenView Network Node Manager Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-025.shtml</link>
  <pubDate>02 Nov 2011 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-024: IBM Lotus Sametime Configuration Servlet Lets Remote Users Obtain Configuration Data</title>
  <description>IBM Lotus Sametime Configuration Servlet Lets Remote Users Obtain Configuration Data</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-024.shtml</link>
  <pubDate>01 Nov 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-023: Debian update for phpldapadmin </title>
  <description>Debian update for phpldapadmin </description>
  <link>http://www.doecirc.energy.gov/bulletins/u-023.shtml</link>
  <pubDate>31 Oct 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-022: Apple QuickTime Multiple Vulnerabilities</title>
  <description>Apple QuickTime Multiple Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-022.shtml</link>
  <pubDate>28 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-021: Cisco Unified Communications Manager Directory Traversal Flaw Lets Remote Users Obtain Files</title>
  <description>Cisco Unified Communications Manager Directory Traversal Flaw Lets Remote Users Obtain Files</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-021.shtml</link>
  <pubDate>27 Oct 2011 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-020: McAfee Web Gateway Web Access Cross Site Scripting Vulnerability</title>
  <description>McAfee Web Gateway Web Access Cross Site Scripting Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-020.shtml</link>
  <pubDate>26 Oct 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-019: Oracle Critical Patch Update Advisory - October 2011</title>
  <description>Oracle Critical Patch Update Advisory - October 2011</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-019.shtml</link>
  <pubDate>25 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-018: Oracle AutoVue ActiveX Control Insecure Method Vulnerabilities</title>
  <description>Oracle AutoVue ActiveX Control Insecure Method Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-018.shtml</link>
  <pubDate>25 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-017: HP MFP Digital Sending Software Lets Local Users Obtain Potentially Sensitive Information</title>
  <description>HP MFP Digital Sending Software Lets Local Users Obtain Potentially Sensitive Information</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-017.shtml</link>
  <pubDate>24 Oct 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-016: Cisco IOS Software HTTP Service Loading Denial of Service Vulnerability</title>
  <description>Cisco IOS Software HTTP Service Loading Denial of Service Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-016.shtml</link>
  <pubDate>21 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-015: CiscoWorks Common Services Home Page Input Validation Flaw Lets Remote Users Execute Arbitrary Commands</title>
  <description>CiscoWorks Common Services Home Page Input Validation Flaw Lets Remote Users Execute Arbitrary Commands</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-015.shtml</link>
  <pubDate>20 Oct 2011 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-014: Oracle Java Runtime Environment (JRE) Multiple Flaws Let Remote Users Execute Arbitrary Code and Deny Service</title>
  <description>Oracle Java Runtime Environment (JRE) Multiple Flaws Let Remote Users Execute Arbitrary Code and Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-014.shtml</link>
  <pubDate>19 Oct 2011 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-013: HP Data Protector Multiple Unspecified Vulnerabilities</title>
  <description>HP Data Protector Multiple Unspecified Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-013.shtml</link>
  <pubDate>18 Oct 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-012: BlackBerry Enterprise Server Collaboration Service Bug Lets Remote Users Impersonate Intra-organization Messages</title>
  <description>BlackBerry Enterprise Server Collaboration Service Bug Lets Remote Users Impersonate Intra-organization Messages</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-012.shtml</link>
  <pubDate>17 Oct 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-011: Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability</title>
  <description>Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-011.shtml</link>
  <pubDate>14 Oct 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-010: HP Onboard Administrator Unspecified Flaw Lets Remote Users Gain Access</title>
  <description>HP Onboard Administrator Unspecified Flaw Lets Remote Users Gain Access</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-010.shtml</link>
  <pubDate>13 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-009: Microsoft Security Bulletin Summary for October 2011</title>
  <description>Microsoft Security Bulletin Summary for October 2011</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-009.shtml</link>
  <pubDate>12 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-008: Symantec Data Loss Prevention Bugs in KeyView Filter Lets Remote Users Deny Service</title>
  <description>Symantec Data Loss Prevention Bugs in KeyView Filter Lets Remote Users Deny Service</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-008.shtml</link>
  <pubDate>11 Oct 2011 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-007: IBM Rational AppScan Import/Load Function Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>IBM Rational AppScan Import/Load Function Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-007.shtml</link>
  <pubDate>10 Oct 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-006: Cisco Network Admission Control Manager Directory Traversal Flaw Lets Remote Users Obtain Potentially Sensitive Information</title>
  <description>Cisco Network Admission Control Manager Directory Traversal Flaw Lets Remote Users Obtain Potentially Sensitive Information</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-006.shtml</link>
  <pubDate>07 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-005: Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers</title>
  <description>Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-005.shtml</link>
  <pubDate>06 Oct 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-004: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-004.shtml</link>
  <pubDate>05 Oct 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-003: RPM Package Manager security update</title>
  <description>RPM Package Manager security update</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-003.shtml</link>
  <pubDate>04 Oct 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-002: Adobe Photoshop Elements Multiple Memory Corruption Vulnerabilities</title>
  <description>Adobe Photoshop Elements Multiple Memory Corruption Vulnerabilities</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-002.shtml</link>
  <pubDate>04 Oct 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>U-001: Symantec IM Manager Input Validation Flaws</title>
  <description>Symantec IM Manager Input Validation Flaws</description>
  <link>http://www.doecirc.energy.gov/bulletins/u-001.shtml</link>
  <pubDate>03 Oct 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-731: Symantec IM Manager Code Injection Vulnerability</title>
  <description>Symantec IM Manager Code Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-731.shtml</link>
  <pubDate>30 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-730: Vulnerability in Citrix Provisioning Services could result in Arbitrary Code Execution</title>
  <description>Vulnerability in Citrix Provisioning Services could result in Arbitrary Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-730.shtml</link>
  <pubDate>29 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-729: Mozilla Code Installation Through Holding Down Enter</title>
  <description>Mozilla Code Installation Through Holding Down Enter</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-729.shtml</link>
  <pubDate>29 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-728: Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks</title>
  <description>Apache Tomcat HTTP DIGEST Authentication Weaknesses Let Remote Users Conduct Bypass Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-728.shtml</link>
  <pubDate>28 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-727: Microsoft Windows SSL/TLS Protocol Flaw Lets Remote Users Decryption Sessions</title>
  <description>Microsoft Windows SSL/TLS Protocol Flaw Lets Remote Users Decryption Sessions</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-727.shtml</link>
  <pubDate>27 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-726: Linux-2.6 privilege escalation/denial of service/information leak</title>
  <description>Linux-2.6 privilege escalation/denial of service/information leak</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-726.shtml</link>
  <pubDate>26 Sep 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-725: Cisco Unified Service Monitor and Cisco Unified Operations Manager Remote Code Execution Vulnerabilitiry Code</title>
  <description>Cisco Unified Service Monitor and Cisco Unified Operations Manager Remote Code Execution Vulnerabilitiry Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-725.shtml</link>
  <pubDate>23 Sep 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-724: Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing</title>
  <description>Microsoft Security Advisory: Fraudulent digital certificates could allow spoofing</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-724.shtml</link>
  <pubDate>22 Sep 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-723: Adobe Flash Player Multiple Bugs Let Remote Users Obtain Information, Conduct Cross-Site Scripting Attacks, and Execute Arbitrary Code</title>
  <description>Adobe Flash Player Multiple Bugs Let Remote Users Obtain Information, Conduct Cross-Site Scripting Attacks, and Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-723.shtml</link>
  <pubDate>22 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-722: IBM WebSphere Commerce Edition Input Validation Holes Permit Cross-Site Scripting Attacks</title>
  <description>IBM WebSphere Commerce Edition Input Validation Holes Permit Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-722.shtml</link>
  <pubDate>21 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-721: Mac OS X Directory Services Lets Local Users View User Password Hashes</title>
  <description>Mac OS X Directory Services Lets Local Users View User Password Hashes</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-721.shtml</link>
  <pubDate>20 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-720: Blue Coat Director HTTP Trace Processing Flaw Permits Cross-Site Scripting Attacks</title>
  <description>Blue Coat Director HTTP Trace Processing Flaw Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-720.shtml</link>
  <pubDate>19 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-719: Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service </title>
  <description>Apache mod_proxy_ajp HTTP Processing Error Lets Remote Users Deny Service </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-719.shtml</link>
  <pubDate>16 Sep 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-718: Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Acrobat/Reader Multiple Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-718.shtml</link>
  <pubDate>15 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-717: Microsoft Security Bulletin Summary for September 2011</title>
  <description>Microsoft Security Bulletin Summary for September 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-717.shtml</link>
  <pubDate>14 Sep 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-716: Google SketchUp v8.x - '.DAE' File Memory Corruption Vulnerability</title>
  <description>Google SketchUp v8.x - '.DAE' File Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-716.shtml</link>
  <pubDate>14 Sep 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-715: Microsoft SharePoint Multiple Flaws Permit Cross-Site Scripting Attacks </title>
  <description>Microsoft SharePoint Multiple Flaws Permit Cross-Site Scripting Attacks </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-715.shtml</link>
  <pubDate>13 Sep 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-714: Wireshark OpenSafety and CSN.1 Dissector Bugs </title>
  <description>Wireshark OpenSafety and CSN.1 Dissector Bugs </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-714.shtml</link>
  <pubDate>12 Sep 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-713: Blue Coat Reporter Directory Traversal Flaw </title>
  <description>Blue Coat Reporter Directory Traversal Flaw </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-713.shtml</link>
  <pubDate>09 Sep 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-712: Red Hat Enterprise MRG Grid 2.0 security, bug fix and enhancement update</title>
  <description>Red Hat Enterprise MRG Grid 2.0 security, bug fix and enhancement update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-712.shtml</link>
  <pubDate>08 Sep 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-711: Fraudulent Google Digital Certificates Could Allow Man-in-the-Middle Attacks</title>
  <description>Fraudulent Google Digital Certificates Could Allow Man-in-the-Middle Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-711.shtml</link>
  <pubDate>07 Sep 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-710: Apache HTTP Server Overlapping Ranges Denial of Service Vulnerability</title>
  <description>Apache HTTP Server Overlapping Ranges Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-710.shtml</link>
  <pubDate>06 Sep 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-709: Mac OS X Keychain Certificate Settings Can Be Bypassed By Remote Users</title>
  <description>Mac OS X Keychain Certificate Settings Can Be Bypassed By Remote Users</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-709.shtml</link>
  <pubDate>02 Sep 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-708: Pidgin Bugs Let Remote Users Deny Service and Potentially Execute Arbitrary Code</title>
  <description>Pidgin Bugs Let Remote Users Deny Service and Potentially Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-708.shtml</link>
  <pubDate>01 Sep 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-707: Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information </title>
  <description>Apache Tomcat AJP Protocol Processing Bug Lets Remote Users Bypass Authentication or Obtain Information </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-707.shtml</link>
  <pubDate>31 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-706: Microsoft Fraudulent Digital Certificate Issued by DigiNotar</title>
  <description>Microsoft Fraudulent Digital Certificate Issued by DigiNotar</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-706.shtml</link>
  <pubDate>30 Aug 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-705: Linux Kernel Weakness in Sequence Number Generation Facilitates Packet Injection Attacks</title>
  <description>Linux Kernel Weakness in Sequence Number Generation Facilitates Packet Injection Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-705.shtml</link>
  <pubDate>30 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-704: RSA enVision Lets Remote Users View Files and Remote Authenticated Users Obtain Password</title>
  <description>RSA enVision Lets Remote Users View Files and Remote Authenticated Users Obtain Password</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-704.shtml</link>
  <pubDate>29 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-703: Cisco Unified Communications Manager Open Query Interface Lets Remote Users Obtain Database Contents</title>
  <description>Cisco Unified Communications Manager Open Query Interface Lets Remote Users Obtain Database Contents</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-703.shtml</link>
  <pubDate>26 Aug 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-702: Apache web servers that allows a DOS attack</title>
  <description>Apache web servers that allows a DOS attack</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-702.shtml</link>
  <pubDate>25 Aug 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-701: Citrix Access Gateway Enterprise Edition Input Validation Flaw in Logon Portal Permits Cross-Site Scripting Attacks </title>
  <description>Citrix Access Gateway Enterprise Edition Input Validation Flaw in Logon Portal Permits Cross-Site Scripting Attacks </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-701.shtml</link>
  <pubDate>25 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-700: Red Hat: kernel security, bug fix, and enhancement update </title>
  <description>Red Hat: kernel security, bug fix, and enhancement update </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-700.shtml</link>
  <pubDate>24 Aug 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-699: EMC AutoStart Buffer Overflows Let Remote Users Execute Arbitrary Code</title>
  <description>EMC AutoStart Buffer Overflows Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-699.shtml</link>
  <pubDate>23 Aug 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-698: Adobe ColdFusion Input Validation Flaw in 'probe.cfm' Permits Cross-Site Scripting Attacks</title>
  <description>Adobe ColdFusion Input Validation Flaw in 'probe.cfm' Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-698.shtml</link>
  <pubDate>22 Aug 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-697: Google Chrome Prior to 13.0.782.107 Multiple Security Vulnerabilities</title>
  <description>Google Chrome Prior to 13.0.782.107 Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-697.shtml</link>
  <pubDate>19 Aug 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-696: RSA Adaptive Authentication Has Unspecified Remote Authenticated Session Re-use Flaw</title>
  <description>RSA Adaptive Authentication Has Unspecified Remote Authenticated Session Re-use Flaw</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-696.shtml</link>
  <pubDate>18 Aug 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-695: Avaya Aura Application Server Buffer Overflow in 'cstore.exe' Lets Remote Users Execute Arbitrary Code</title>
  <description>Avaya Aura Application Server Buffer Overflow in 'cstore.exe' Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-695.shtml</link>
  <pubDate>17 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-694: IBM Tivoli Federated Identity Manager Products Multiple Vulnerabilities</title>
  <description>IBM Tivoli Federated Identity Manager Products Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-694.shtml</link>
  <pubDate>16 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-693: Symantec Endpoint Protection Manager Input Validation Hole Permits Cross-Site Scripting and Cross-Site Request Forgery Attacks</title>
  <description>Symantec Endpoint Protection Manager Input Validation Hole Permits Cross-Site Scripting and Cross-Site Request Forgery Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-693.shtml</link>
  <pubDate>15 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-692: VMware vFabric tc Server Lets Remote Users Login Using Obfuscated Passwords</title>
  <description>VMware vFabric tc Server Lets Remote Users Login Using Obfuscated Passwords</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-692.shtml</link>
  <pubDate>12 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-691: Adobe Flash Player Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Flash Player Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-691.shtml</link>
  <pubDate>11 Aug 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-690: Check Point Endpoint Security On-Demand Client Lets Remote Users Execute Arbitrary Code Bulletin Released for August 2011</title>
  <description>Check Point Endpoint Security On-Demand Client Lets Remote Users Execute Arbitrary Code Bulletin Released for August 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-690.shtml</link>
  <pubDate>10 Aug 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-689: Microsoft Security Bulletin Released for August 2011</title>
  <description>Microsoft Security Bulletin Released for August 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-689.shtml</link>
  <pubDate>10 Aug 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-688: McAfee Security Bulletin - McAfee SaaS Endpoint Protection update fixes multiple ActiveX issues </title>
  <description>McAfee Security Bulletin - McAfee SaaS Endpoint Protection update fixes multiple ActiveX issues </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-688.shtml</link>
  <pubDate>09 Aug 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-687: Microsoft Security Bulletin Advance Notification for August 2011</title>
  <description>Microsoft Security Bulletin Advance Notification for August 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-687.shtml</link>
  <pubDate>08 Aug 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-686: IBM Tivoli Integrated Portal Java Double Literal Denial of Service Vulnerability </title>
  <description>IBM Tivoli Integrated Portal Java Double Literal Denial of Service Vulnerability </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-686.shtml</link>
  <pubDate>08 Aug 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-685: Cisco Warranty CD May Load Malware From a Remote Site</title>
  <description>Cisco Warranty CD May Load Malware From a Remote Site</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-685.shtml</link>
  <pubDate>05 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-684: Apple QuickTime Buffer Overflows Let Remote Users Execute Arbitrary Code</title>
  <description>Apple QuickTime Buffer Overflows Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-684.shtml</link>
  <pubDate>04 Aug 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-683: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-683.shtml</link>
  <pubDate>03 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-682: Double free vulnerability in MapServer</title>
  <description>Double free vulnerability in MapServer</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-682.shtml</link>
  <pubDate>02 Aug 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-681: IBM Lotus Symphony Multiple Unspecified Vulnerabilities</title>
  <description>IBM Lotus Symphony Multiple Unspecified Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-681.shtml</link>
  <pubDate>01 Aug 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-680: Samba SWAT user Field Cross Site Scripting Vulnerability</title>
  <description>Samba SWAT 'user' Field Cross Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-680.shtml</link>
  <pubDate>01 Aug 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-679: VMware Security Advisory</title>
  <description>VMware Security Advisory - VMSA-2011-0010</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-679.shtml</link>
  <pubDate>29 Jul 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-678: Red Hat Enterprise Virtualization Hypervisor VLAN Packet Processing Flaw Lets Remote Users Deny Service</title>
  <description>Red Hat Enterprise Virtualization Hypervisor VLAN Packet Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-678.shtml</link>
  <pubDate>28 Jul 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-677: F5 BIG-IP BIND Negative Caching RRSIG RRsets Denial of Service Vulnerability</title>
  <description>F5 BIG-IP BIND Negative Caching RRSIG RRsets Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-677.shtml</link>
  <pubDate>27 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-676: Apple iOS Certificate Chain Validation Flaw Lets Certain Remote Users Access or Modify SSL/TLS Sessions</title>
  <description>Apple iOS Certificate Chain Validation Flaw Lets Certain Remote Users Access or Modify SSL/TLS Sessions</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-676.shtml</link>
  <pubDate>26 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-675: Apple Laptop Battery Interface Lets Local Users Deny Service</title>
  <description>Apple Laptop Battery Interface Lets Local Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-675.shtml</link>
  <pubDate>25 Jul 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-674: Drupal Secure Password Hashes Module Security Bypass Vulnerability</title>
  <description>Drupal Secure Password Hashes Module Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-674.shtml</link>
  <pubDate>22 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-673: Apple Safari Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks</title>
  <description>Apple Safari Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-673.shtml</link>
  <pubDate>21 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-672: Oracle Critical Patch Update Advisory - July 2011</title>
  <description>Oracle Critical Patch Update Advisory - July 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-672.shtml</link>
  <pubDate>20 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-671: Red Hat system-config-firewall Lets Local Users Gain Root Privileges </title>
  <description>Red Hat system-config-firewall Lets Local Users Gain Root Privileges </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-671.shtml</link>
  <pubDate>19 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-670: Skype Input Validation Flaw in 'mobile phone' Profile Entry Permits Cross-Site Scripting Attacks </title>
  <description>Skype Input Validation Flaw in 'mobile phone' Profile Entry Permits Cross-Site Scripting Attacks </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-670.shtml</link>
  <pubDate>18 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-669: Linux Kernel GFS2 Allocation Error Lets Local Users Deny Service </title>
  <description>Linux Kernel GFS2 Allocation Error Lets Local Users Deny Service </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-669.shtml</link>
  <pubDate>15 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-668: Vulnerability in a BlackBerry Enterprise Server component could allow information disclosure and partial denial of service</title>
  <description>Vulnerability in a BlackBerry Enterprise Server component could allow information disclosure and partial denial of service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-668.shtml</link>
  <pubDate>14 Jul 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-667: Red Hat Enterprise Linux kernel security and bug fix update</title>
  <description>Red Hat Enterprise Linux kernel security and bug fix update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-667.shtml</link>
  <pubDate>13 Jul 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-666: Microsoft Security Bulletin MS11-054 - Important</title>
  <description>Microsoft Security Bulletin MS11-054 - Important</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-666.shtml</link>
  <pubDate>12 Jul 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-665: Microsoft Security Bulletin Advance Notification for July 2011</title>
  <description>Microsoft Security Bulletin Advance Notification for July 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-665.shtml</link>
  <pubDate>11 Jul 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-664: Apache Santuario Buffer Overflow Lets Remote Users Deny Service</title>
  <description>Apache Santuario Buffer Overflow Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-664.shtml</link>
  <pubDate>08 Jul 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-663: Cisco Content Services Gateway ICMP Processing Flaw Lets Remote Users Deny</title>
  <description>Cisco Content Services Gateway ICMP Processing Flaw Lets Remote Users Deny</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-663.shtml</link>
  <pubDate>07 Jul 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-662: ISC BIND Packet Processing Flaw Lets Remote Users Deny Service</title>
  <description>ISC BIND Packet Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-662.shtml</link>
  <pubDate>06 Jul 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-661: ColdFusion Security Hotfix | APSB11-14, ColdFusion Important Update</title>
  <description>ColdFusion Security Hotfix | APSB11-14, ColdFusion Important Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-661.shtml</link>
  <pubDate>05 Jul 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-660: OpenSSH on FreeBSD Has Buffer Overflow in pam_thread() That Lets Remote Users Execute Arbitrary Code</title>
  <description>OpenSSH on FreeBSD Has Buffer Overflow in pam_thread() That Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-660.shtml</link>
  <pubDate>05 Jul 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-659: Update support for RSA Authentication Manager</title>
  <description>Update support for RSA Authentication Manager</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-659.shtml</link>
  <pubDate>01 Jul 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-658: Java for Mac OS X 10.6 Update 5, Java for Mac OS X 10.5 Update 10</title>
  <description>T-658: Java for Mac OS X 10.6 Update 5, Java for Mac OS X 10.5 Update 10</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-658.shtml</link>
  <pubDate>30 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-657: Drupal Prepopulate - Multiple vulnerabilities</title>
  <description>Drupal Prepopulate - Multiple vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-657.shtml</link>
  <pubDate>29 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-656: Microsoft Office Visio DXF File Handling Arbitrary Code Execution Vulnerability</title>
  <description>Microsoft Office Visio DXF File Handling Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-656.shtml</link>
  <pubDate>28 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-655: Mozilla Firefox CVE-2011-2369 HTML Injection Vulnerability</title>
  <description>Mozilla Firefox CVE-2011-2369 HTML Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-655.shtml</link>
  <pubDate>27 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-654: Apple QuickTime Multiple Bugs Let Remote Users Execute Arbitrary</title>
  <description>Apple QuickTime Multiple Bugs Let Remote Users Execute Arbitrary</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-654.shtml</link>
  <pubDate>24 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-653: Linux Kernel sigqueueinfo() Process Lets Local Users Send Spoofed Signals</title>
  <description>Linux Kernel sigqueueinfo() Process Lets Local Users Send Spoofed Signals</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-653.shtml</link>
  <pubDate>23 Jun 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-652: Mozilla Thunderbird Bugs Let Remote Users Obtain Cookies and Execute Arbitrary Code </title>
  <description>Mozilla Thunderbird Bugs Let Remote Users Obtain Cookies and Execute Arbitrary Code </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-652.shtml</link>
  <pubDate>22 Jun 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-651: Blue Coat ProxySG Discloses Potentially Sensitive Information in Core Files</title>
  <description>Blue Coat ProxySG Discloses Potentially Sensitive Information in Core Files</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-651.shtml</link>
  <pubDate>21 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-650: Microsoft Word Unspecified Flaw Lets Remote Users Execute Arbitrary Code</title>
  <description>Microsoft Word Unspecified Flaw Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-650.shtml</link>
  <pubDate>20 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-649: Red Hat Network Satellite Server Request Validation Flaw Permits Cross-Site Request Forgery Attacks</title>
  <description>Red Hat Network Satellite Server Request Validation Flaw Permits Cross-Site Request Forgery Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-649.shtml</link>
  <pubDate>17 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-648: Avaya IP Office Manager TFTP Server Lets Remote Users Traverse the Directory</title>
  <description>Avaya IP Office Manager TFTP Server Lets Remote Users Traverse the Directory</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-648.shtml</link>
  <pubDate>16 Jun 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-647: PHP File Upload Bug May Let Remote Users Overwrite Files on the Target System</title>
  <description>PHP File Upload Bug May Let Remote Users Overwrite Files on the Target System</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-647.shtml</link>
  <pubDate>15 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-646: Debian fex authentication bypass</title>
  <description>Debian fex authentication bypass</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-646.shtml</link>
  <pubDate>14 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-645: Microsoft Security Bulletin Advance Notification</title>
  <description>Microsoft Security Bulletin Advance Notification</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-645.shtml</link>
  <pubDate>13 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-644: Prenotification Security Advisory - Adobe Acrobat, Adobe Reader Updates</title>
  <description>Prenotification Security Advisory - Adobe Acrobat, Adobe Reader Updates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-644.shtml</link>
  <pubDate>10 Jun 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-643: HP OpenView Storage Data Protector Unspecified Code Execution Vulnerability</title>
  <description>HP OpenView Storage Data Protector Unspecified Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-643.shtml</link>
  <pubDate>09 Jun 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-642: RSA SecurID update to Customers</title>
  <description>RSA SecurID update to Customers</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-642.shtml</link>
  <pubDate>09 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-641: Oracle Java SE Critical Patch Update Advisory - June 2011</title>
  <description>Oracle Java SE Critical Patch Update Advisory - June 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-641.shtml</link>
  <pubDate>08 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-640: RSA Access Manager Server CVE-2011-0322 Update</title>
  <description>RSA Access Manager Server CVE-2011-0322 Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-640.shtml</link>
  <pubDate>07 Jun 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-639: Debian update for libxml2</title>
  <description>Debian update for libxml2</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-639.shtml</link>
  <pubDate>07 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-638: Security update available for Adobe Flash Player</title>
  <description>Security update available for Adobe Flash Player</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-638.shtml</link>
  <pubDate>06 Jun 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-637: VMSA-2011-0009 VMware hosted product updates, ESX patches and VI, and Client update resolve multiple</title>
  <description>VMSA-2011-0009 VMware hosted product updates, ESX patches and VI, and Client update resolve multiple</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-637.shtml</link>
  <pubDate>06 Jun 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-636: Wireshark Multiple Flaws Let Remote Users Deny Service </title>
  <description>Wireshark Multiple Flaws Let Remote Users Deny Service </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-636.shtml</link>
  <pubDate>03 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-635: Cisco AnyConnect Secure Mobility Client Lets Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privilege</title>
  <description>Cisco AnyConnect Secure Mobility Client Lets Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privilege</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-635.shtml</link>
  <pubDate>02 Jun 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-634: Apple Mac OS X MacDefender Fake Antivirus Malicious Software</title>
  <description>Apple Mac OS X MacDefender Fake Antivirus Malicious Software</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-634.shtml</link>
  <pubDate>01 Jun 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-633: BIND RRSIG RRsets Negative Caching Off-by-one Bug Lets Remote Users Deny Service</title>
  <description>BIND RRSIG RRsets Negative Caching Off-by-one Bug Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-633.shtml</link>
  <pubDate>31 May 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-632: Google Chrome OS before R12 0.12.433.38 Beta Update</title>
  <description>Google Chrome OS before R12 0.12.433.38 Beta Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-632.shtml</link>
  <pubDate>27 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-631: Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability</title>
  <description>Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-631.shtml</link>
  <pubDate>26 May 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-630: Security update available for Adobe Flash Player</title>
  <description>Security update available for Adobe Flash Player</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-630.shtml</link>
  <pubDate>25 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-629: Avaya WinPDM Multiple Buffer Overflow Vulnerabilities</title>
  <description>Avaya WinPDM Multiple Buffer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-629.shtml</link>
  <pubDate>24 May 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-628: Debian APR Library Security Update </title>
  <description>Debian APR Library Security Update </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-628.shtml</link>
  <pubDate>23 May 2011 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-627: Adobe Flash Player Memory Corruption</title>
  <description>Adobe Flash Player Memory Corruption</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-627.shtml</link>
  <pubDate>20 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-626: Xen Multiple Buffer Overflow and Integer Overflow Vulnerabilities</title>
  <description>Xen Multiple Buffer Overflow and Integer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-626.shtml</link>
  <pubDate>19 May 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-625: Opera Frameset Handling Memory Corruption Vulnerability</title>
  <description>Opera Frameset Handling Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-625.shtml</link>
  <pubDate>18 May 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-624: Novell eDirectory LDAP-SSL Memory Allocation Error Lets Remote Users Deny Service</title>
  <description>Novell eDirectory LDAP-SSL Memory Allocation Error Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-624.shtml</link>
  <pubDate>17 May 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-623: HP Business Availability Center Input Validation Hole Permits Cross-Site Scripting Attacks</title>
  <description>HP Business Availability Center Input Validation Hole Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-623.shtml</link>
  <pubDate>16 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-622: Adobe Acrobat and Reader Unspecified Memory Corruption Vulnerability</title>
  <description>Adobe Acrobat and Reader Unspecified Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-622.shtml</link>
  <pubDate>13 May 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-621: Citrix XenServer Lets Local Administrative Users on the Guest OS Deny Service</title>
  <description>Citrix XenServer Lets Local Administrative Users on the Guest OS Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-621.shtml</link>
  <pubDate>12 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-620: Microsoft Security Bulletin Advance Notification for May 2011</title>
  <description>Microsoft Security Bulletin Advance Notification for May 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-620.shtml</link>
  <pubDate>10 May 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-619: Skype for Mac Message Processing Code Execution Vulnerability</title>
  <description>Skype for Mac Message Processing Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-619.shtml</link>
  <pubDate>10 May 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-618: Debian update for exim4: Mail Transport Agent</title>
  <description>Debian update for exim4: Mail Transport Agent</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-618.shtml</link>
  <pubDate>09 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-617: BIND RPZ Processing Flaw Lets Remote Users Deny Service</title>
  <description>BIND RPZ Processing Flaw Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-617.shtml</link>
  <pubDate>06 May 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-616: T-616: PHP Stream Component Remote Denial of Service Vulnerability</title>
  <description>T-616: PHP Stream Component Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-616.shtml</link>
  <pubDate>05 May 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-615: IBM Rational System Architect ActiveBar ActiveX Control Lets Remote Users Execute Arbitrary Code</title>
  <description>IBM Rational System Architect ActiveBar ActiveX Control Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-615.shtml</link>
  <pubDate>04 May 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-614: Cisco Unified Communications Manager Database Security Vulnerability</title>
  <description>Cisco Unified Communications Manager Database Security Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-614.shtml</link>
  <pubDate>03 May 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-613: T-613: Microsoft Excel Axis Properties Remote Code Execution Vulnerability</title>
  <description>T-613: Microsoft Excel Axis Properties Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-613.shtml</link>
  <pubDate>02 May 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-612: False Positive Detection Generic File in DAT 6329</title>
  <description>False Positive Detection Generic File in DAT 6329</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-612.shtml</link>
  <pubDate>29 Apr 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-611: Cisco IOS OCSP Revoked Certificate Security Issue</title>
  <description>Cisco IOS OCSP Revoked Certificate Security Issue</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-611.shtml</link>
  <pubDate>27 Apr 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-610: Red Hat kdenetwork security update</title>
  <description>Red Hat kdenetwork security update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-610.shtml</link>
  <pubDate>26 Apr 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-609: Adobe Acrobat/Reader Memory Corruption Error in CoolType Library Lets Remote Users Execute Arbitrary Code</title>
  <description>Adobe Acrobat/Reader Memory Corruption Error in CoolType Library Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-609.shtml</link>
  <pubDate>25 Apr 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-608: HP Virtual Server Environment Lets Remote Authenticated Users Gain Elevated Privileges</title>
  <description>HP Virtual Server Environment Lets Remote Authenticated Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-608.shtml</link>
  <pubDate>22 Apr 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-607: Update: Adobe Acrobat, Reader, and Flash Player SWF File Processing Arbitrary Code Execution Vulnerability</title>
  <description>Update: Adobe Acrobat, Reader, and Flash Player SWF File Processing Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-607.shtml</link>
  <pubDate>21 Apr 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-606: Sun Java System Access Manager Lets Remote Users Partially Modify Data and Remote Authenticated Users Partially Access Data</title>
  <description>Sun Java System Access Manager Lets Remote Users Partially Modify Data and Remote Authenticated Users Partially Access Data</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-606.shtml</link>
  <pubDate>20 Apr 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-605: Oracle Critical Patch Update Advisory - April 2011</title>
  <description>Oracle Critical Patch Update Advisory - April 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-605.shtml</link>
  <pubDate>19 Apr 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-604: Google Chrome updated version of the Adobe Flash player</title>
  <description>Google Chrome updated version of the Adobe Flash player</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-604.shtml</link>
  <pubDate>15 Apr 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-603: Mac OS X Includes Some Invalid Comodo Certificates</title>
  <description>Mac OS X Includes Some Invalid Comodo Certificates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-603.shtml</link>
  <pubDate>15 Apr 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-602: BlackBerry Enterprise Server Input Validation Flaw in BlackBerry Web Desktop Manager Permits Cross-Site Scripting Attacks</title>
  <description>BlackBerry Enterprise Server Input Validation Flaw in BlackBerry Web Desktop Manager Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-602.shtml</link>
  <pubDate>14 Apr 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-601: Windows Kernel win32k.sys Lets Local Users Gain Elevated Privileges</title>
  <description>Windows Kernel win32k.sys Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-601.shtml</link>
  <pubDate>13 Apr 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-600: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</title>
  <description>Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-600.shtml</link>
  <pubDate>12 Apr 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-599: Microsoft April 2011 Security Bulletin Release</title>
  <description>Microsoft April 2011 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-599.shtml</link>
  <pubDate>11 Apr 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-598: Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users</title>
  <description>Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-598.shtml</link>
  <pubDate>08 Apr 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-597: T-597: WordPress Multiple Security Vulnerabilities</title>
  <description>T-597: WordPress Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-597.shtml</link>
  <pubDate>07 Apr 2011 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-597:: T-597</title>
  <description>T-597</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-597: WordPress Multiple Security Vulnerabilities</link>
  <pubDate>07 Apr 2011 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-596: 0-Day Windows Network Interception Configuration Vulnerability</title>
  <description>0-Day Windows Network Interception Configuration Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-596.shtml</link>
  <pubDate>06 Apr 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-595: OpenSUSE aaabase-filename-privilege-escalation</title>
  <description>OpenSUSE aaabase-filename-privilege-escalation</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-595.shtml</link>
  <pubDate>05 Apr 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-594: IBM solidDB Password Hash Authentication Bypass Vulnerability</title>
  <description>IBM solidDB Password Hash Authentication Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-594.shtml</link>
  <pubDate>04 Apr 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-593: Microsoft Internet Explorer unspecified code execution</title>
  <description>Microsoft Internet Explorer unspecified code execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-593.shtml</link>
  <pubDate>01 Apr 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-592: Cisco Security Advisory: Cisco Secure Access Control System Unauthorized Password Change Vulnerability</title>
  <description>Cisco Security Advisory: Cisco Secure Access Control System Unauthorized Password Change Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-592.shtml</link>
  <pubDate>31 Mar 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-591: VMware vmrun Utility Lets Local Users Gain Elevated Privileges</title>
  <description>VMware vmrun Utility Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-591.shtml</link>
  <pubDate>30 Mar 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-590: HP Diagnostics Input Validation Hole Permits Cross-Site Scripting Attacks</title>
  <description>HP Diagnostics Input Validation Hole Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-590.shtml</link>
  <pubDate>29 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-589: Citrix XenApp and Citrix Presentation Server Bug</title>
  <description>Citrix XenApp and Citrix Presentation Server Bug</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-589.shtml</link>
  <pubDate>28 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-588: HP Virtual SAN Appliance Stack Overflow</title>
  <description>HP Virtual SAN Appliance Stack Overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-588.shtml</link>
  <pubDate>25 Mar 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-587: Firefox Blocking Fraudulent Certificates</title>
  <description>Firefox Blocking Fraudulent Certificates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-587.shtml</link>
  <pubDate>24 Mar 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-586: Microsoft Advisory about fraudulent SSL Certificates</title>
  <description>Microsoft Advisory about fraudulent SSL Certificates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-586.shtml</link>
  <pubDate>23 Mar 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-585: Mac OS X v10.6.7 Security Update 2011-001</title>
  <description>Mac OS X v10.6.7 Security Update 2011-001</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-585.shtml</link>
  <pubDate>22 Mar 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-584: Microsoft March 2011 Security Bulletin Release</title>
  <description>Microsoft March 2011 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-584.shtml</link>
  <pubDate>21 Mar 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-583: Linux Kernel OSF Partition Table Buffer Overflow Lets Local Users Obtain Information</title>
  <description>Linux Kernel OSF Partition Table Buffer Overflow Lets Local Users Obtain Information</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-583.shtml</link>
  <pubDate>18 Mar 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-582: RSA systems has resulted in certain information being extracted from RSA systems that relates to RSA.s SecurID</title>
  <description>RSA systems has resulted in certain information being extracted from RSA systems that relates to RSA.s SecurID</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-582.shtml</link>
  <pubDate>18 Mar 2011 03:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-581: Novell Access Manager Java Double Literal Denial of Service Vulnerability</title>
  <description>Novell Access Manager Java Double Literal Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-581.shtml</link>
  <pubDate>17 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-580: Apache Tomcat May Ignore @ServletSecurity Annotation Protections</title>
  <description>Apache Tomcat May Ignore @ServletSecurity Annotation Protections</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-580.shtml</link>
  <pubDate>16 Mar 2011 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-579: BlackBerry Device Software Bug in WebKit Lets Remote Users Execute Code</title>
  <description>BlackBerry Device Software Bug in WebKit Lets Remote Users Execute Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-579.shtml</link>
  <pubDate>15 Mar 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-578: Vulnerability in MHTML Could Allow Information Disclosure</title>
  <description>Vulnerability in MHTML Could Allow Information Disclosure</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-578.shtml</link>
  <pubDate>15 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-577: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</title>
  <description>Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-577.shtml</link>
  <pubDate>14 Mar 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-576: Oracle Solaris Adobe Flash Player Multiple Vulnerabilities</title>
  <description>Oracle Solaris Adobe Flash Player Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-576.shtml</link>
  <pubDate>14 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-575: OpenLDAP back-ndb Lets Remote Users Authenticate Without a Valid Password</title>
  <description>OpenLDAP back-ndb Lets Remote Users Authenticate Without a Valid Password</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-575.shtml</link>
  <pubDate>11 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-574: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-574.shtml</link>
  <pubDate>10 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-573: Windows Remote Desktop Client DLL Loading Error Lets Remote Users Execute Arbitrary Code</title>
  <description>Windows Remote Desktop Client DLL Loading Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-573.shtml</link>
  <pubDate>09 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-572: VMware ESX/ESXi SLPD denial of service vulnerabilitys</title>
  <description>VMware ESX/ESXi SLPD denial of service vulnerabilitys</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-572.shtml</link>
  <pubDate>08 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-571: Linux Kernel dns_resolver Key Processing Error Lets Local Users Deny Services</title>
  <description>Linux Kernel dns_resolver Key Processing Error Lets Local Users Deny Services</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-571.shtml</link>
  <pubDate>07 Mar 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-570: HP Security Bulletin - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code, Denial of Service (DoS), Authentication Bypass</title>
  <description>HP Security Bulletin - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code, Denial of Service (DoS), Authentication Bypass</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-570.shtml</link>
  <pubDate>04 Mar 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-569: Adobe Flash SWF File Processing Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Adobe Flash SWF File Processing Memory Corruption Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-569.shtml</link>
  <pubDate>03 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-568: Mozilla Firefox Bugs Let Remote Users Conduct Cross-Site Request Forgery Attacks and Execute Arbitrary Code</title>
  <description>Mozilla Firefox Bugs Let Remote Users Conduct Cross-Site Request Forgery Attacks and Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-568.shtml</link>
  <pubDate>02 Mar 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-567: Linux Kernel Buffer Overflow in ldm_frag_add() May Let Local Users Gain Elevated Privileges</title>
  <description>Linux Kernel Buffer Overflow in ldm_frag_add() May Let Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-567.shtml</link>
  <pubDate>01 Mar 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-566: Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege Vulnerability</title>
  <description>Citrix Secure Gateway Unspecified Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-566.shtml</link>
  <pubDate>28 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-565: Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege Vulnerability</title>
  <description>Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-565.shtml</link>
  <pubDate>25 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-564: Vulnerabilities in Citrix Licensing administration components</title>
  <description>Vulnerabilities in Citrix Licensing administration components</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-564.shtml</link>
  <pubDate>24 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-563: Red Hat Directory Server Bugs Let Local Users Gain Elevated Privileges and Remote and Local Users Deny Service</title>
  <description>Red Hat Directory Server Bugs Let Local Users Gain Elevated Privileges and Remote and Local Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-563.shtml</link>
  <pubDate>23 Feb 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-562: Novell ZENworks Configuration Management novell-tftp.exe Buffer Overflow</title>
  <description>Novell ZENworks Configuration Management novell-tftp.exe Buffer Overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-562.shtml</link>
  <pubDate>22 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-561: IBM and Oracle Java Binary Floating-Point Number Conversion Denial of Service Vulnerability</title>
  <description>IBM and Oracle Java Binary Floating-Point Number Conversion Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-561.shtml</link>
  <pubDate>21 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-560: Cisco Security Advisory: Management Center for Cisco Security Agent Remote Code Execution Vulnerability</title>
  <description>Cisco Security Advisory: Management Center for Cisco Security Agent Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-560.shtml</link>
  <pubDate>18 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-559 Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote execution</title>
  <description>Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-559.shtml</link>
  <pubDate>17 Feb 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-558: Oracle Java SE and Java for Business Critical Patch Update Advisory - February 2011</title>
  <description>Oracle Java SE and Java for Business Critical Patch Update Advisory - February 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-558.shtml</link>
  <pubDate>16 Feb 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-557: Microsoft Office Excel Office Art Object Parsing Remote Code Execution Vulnerability</title>
  <description>Microsoft Office Excel Office Art Object Parsing Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-557.shtml</link>
  <pubDate>15 Feb 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-556: BMC PATROL Agent Service Daemon stack-based buffer overflow</title>
  <description>BMC PATROL Agent Service Daemon stack-based buffer overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-556.shtml</link>
  <pubDate>14 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-555: Adobe Acrobat and Reader Image Parsing Arbitrary Code Execution Vulnerability</title>
  <description>Adobe Acrobat and Reader Image Parsing Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-555.shtml</link>
  <pubDate>11 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-554: Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code</title>
  <description>Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-554.shtml</link>
  <pubDate>10 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-553: Microsoft February 2011 Security Bulletin Release</title>
  <description>Microsoft February 2011 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-553.shtml</link>
  <pubDate>09 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-552: Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi</title>
  <description>Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-552.shtml</link>
  <pubDate>08 Feb 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-551: Cisco Security Advisory: Multiple Cisco WebEx Player Vulnerabilities</title>
  <description>Cisco Security Advisory: Multiple Cisco WebEx Player Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-551.shtml</link>
  <pubDate>07 Feb 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-550: Apache Denial of Service Vulnerability</title>
  <description>Apache Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-550.shtml</link>
  <pubDate>04 Feb 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-549: Adobe ColdFusion 9.0.1 CHF1 and earlier</title>
  <description>Adobe ColdFusion 9.0.1 CHF1 and earlier</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-549.shtml</link>
  <pubDate>03 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-548: Novell ZENworks Handheld Management (ZHM) ZfHIPCnd.exe buffer overflow</title>
  <description>Novell ZENworks Handheld Management (ZHM) ZfHIPCnd.exe buffer overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-548.shtml</link>
  <pubDate>02 Feb 2011 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-547: Microsoft Windows Human Interface Device (HID) Vulnerability</title>
  <description>Microsoft Windows Human Interface Device (HID) Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-547.shtml</link>
  <pubDate>01 Feb 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-546: Microsoft MHTML Input Validation Hole May Permit Cross-Site Scripting Attacks Arbitrary Code</title>
  <description>Microsoft MHTML Input Validation Hole May Permit Cross-Site Scripting Attacks Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-546.shtml</link>
  <pubDate>31 Jan 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-545: RealPlayer Heap Corruption Error in 'vidplin.dll' Lets Remote Users Execute Arbitrary Code</title>
  <description>RealPlayer Heap Corruption Error in 'vidplin.dll' Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-545.shtml</link>
  <pubDate>28 Jan 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-544: Cisco Security Advisory: Cisco Content Services Gateway Vulnerabilities</title>
  <description>Cisco Security Advisory: Cisco Content Services Gateway Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-544.shtml</link>
  <pubDate>27 Jan 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-543: Wireshark 0.8.20 through 1.2.8 Multiple Vulnerabilities</title>
  <description>Wireshark 0.8.20 through 1.2.8 Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-543.shtml</link>
  <pubDate>26 Jan 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-542: SAP Crystal Reports Server Multiple Vulnerabilities</title>
  <description>SAP Crystal Reports Server Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-542.shtml</link>
  <pubDate>25 Jan 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-541: Citrix Provisioning Services Unspecified Flaw Let's Remote Users Execute Arbitrary Code</title>
  <description>Citrix Provisioning Services Unspecified Flaw Let's Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-541.shtml</link>
  <pubDate>24 Jan 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-540: Sybase EAServer Multiple Vulnerabilities</title>
  <description>Sybase EAServer Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-540.shtml</link>
  <pubDate>24 Jan 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-539: Adobe Acrobat, Reader, and Flash Player Arbitrary Code Execution Vulnerability</title>
  <description>Adobe Acrobat, Reader, and Flash Player Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-539.shtml</link>
  <pubDate>21 Jan 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-538: HP OpenView Storage Data Protector Bug Lets Remote Users Execute Arbitrary Code</title>
  <description>HP OpenView Storage Data Protector Bug Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-538.shtml</link>
  <pubDate>20 Jan 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-537: Oracle Critical Patch Update Advisory - January 2011</title>
  <description>Oracle Critical Patch Update Advisory - January 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-537.shtml</link>
  <pubDate>19 Jan 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-536: Cisco ASA Multiple Flaws Let Remote Users Deny Service and Bypass Security Controls</title>
  <description>Cisco ASA Multiple Flaws Let Remote Users Deny Service and Bypass Security Controls</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-536.shtml</link>
  <pubDate>18 Jan 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-535: Oracle Critical Patch Update Pre-Release Announcement - January 2011</title>
  <description>Oracle Critical Patch Update Pre-Release Announcement - January 2011</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-535.shtml</link>
  <pubDate>14 Jan 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-534: Vulnerability in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server</title>
  <description>Vulnerability in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-534.shtml</link>
  <pubDate>13 Jan 2011 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-533: Microsoft January 2011 Security Bulletin Release</title>
  <description>Microsoft January 2011 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-533.shtml</link>
  <pubDate>12 Jan 2011 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item> 
  <title>T-532: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution</title>
  <description>Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-532.shtml</link>
  <pubDate>11 Jan 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-531: The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500</title>
  <description>The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-531.shtml</link>
  <pubDate>10 Jan 2011 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-530: VMware ESX 4.0, Patch ESX400-201101401-SG: Updates VMkernel,CIM,Scripts, VMware Tools, hostd, and VMX</title>
  <description>VMware ESX 4.0, Patch ESX400-201101401-SG: Updates VMkernel,CIM,Scripts, VMware Tools, hostd, and VMX</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-530.shtml</link>
  <pubDate>07 Jan 2011 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-529: Apple Mac OS PackageKit Distribution Script Remote Code Execution Vulnerability</title>
  <description>Apple Mac OS PackageKit Distribution Script Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-529.shtml</link>
  <pubDate>06 Jan 2011 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-528: Mozilla Firefox/Thunderbird/SeaMonkey Multiple HTML Injection Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey Multiple HTML Injection Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-528.shtml</link>
  <pubDate>05 Jan 2011 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-527: OpenSC Smart Card Serial Number Multiple Buffer Overflow Vulnerabilities</title>
  <description>OpenSC Smart Card Serial Number Multiple Buffer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-527.shtml</link>
  <pubDate>04 Jan 2011 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-526: Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability</title>
  <description>Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-526.shtml</link>
  <pubDate>03 Jan 2011 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-525: Google Chrome prior to 8.0.552.215 Multiple Security Vulnerabilities</title>
  <description>Google Chrome prior to 8.0.552.215 Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-525.shtml</link>
  <pubDate>30 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item> 
  <title>T-524: Adobe Photoshop Insecure Library Loading Vulnerability</title>
  <description>Adobe Photoshop Insecure Library Loading Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-524.shtml</link>
  <pubDate>29 Dec 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item> 
  <title>T-523: Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability</title>
  <description>Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-523.shtml</link>
  <pubDate>28 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-522: Microsoft WMI Administrative Tools Object Viewer ActiveX Control Arbitrary Code Execution Vulnerability</title>
  <description>Microsoft WMI Administrative Tools Object Viewer ActiveX Control Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-522.shtml</link>
  <pubDate>27 Dec 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-521: Microsoft Internet Explorer Recursive CSS Import Memory Corruption Error Lets Remote Users Execute Arbitrary Code</title>
  <description>Microsoft Internet Explorer Recursive CSS Import Memory Corruption Error Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-521.shtml</link>
  <pubDate>23 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-520: VMware ESXi Update Installer SFCB Authentication Lets Remote Users Gain Access</title>
  <description>VMware ESXi Update Installer SFCB Authentication Lets Remote Users Gain Access</description>
  <link>http://circ.jc3.doe.gov/bulletins/T-520.shtml</link>
  <pubDate>22 Dec 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-519: Mozilla Firefox/Thunderbird/SeaMonkey Memory Corruption Vulnerability</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-519.shtml</link>
  <pubDate>21 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-518: Apple QuickTime FlashPix Image (CVE-2010-3801) Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Apple QuickTime FlashPix Image (CVE-2010-3801) Memory Corruption Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-518.shtml</link>
  <pubDate>20 Dec 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item> 
  <title>T-517: Microsoft Windows CVE-2010-3941 'Win32k.sys' Double Free Local Privilege Escalation Vulnerability</title>
  <description>Microsoft Windows CVE-2010-3941 'Win32k.sys' Double Free Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-517.shtml</link>
  <pubDate>17 Dec 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-516: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability Update</title>
  <description>Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-516.shtml</link>
  <pubDate>16 Dec 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-515: Microsoft Office RTF File Stack Buffer Overflow Vulnerability</title>
  <description>Microsoft Office RTF File Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-515.shtml</link>
  <pubDate>15 Dec 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-514: Microsoft December 2010 Security Bulletin Release</title>
  <description>Microsoft December 2010 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-514.shtml</link>
  <pubDate>14 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-513: RealPlayer Buffer Overflows and Memory Corruption</title>
  <description>RealPlayer Buffer Overflows and Memory Corruption</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-513.shtml</link>
  <pubDate>13 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-512: Mozilla Firefox Input Validation Flaw Lets Remote Users Bypass Cross-Site Scripting Protections</title>
  <description>Mozilla Firefox Input Validation Flaw Lets Remote Users Bypass Cross-Site Scripting Protections</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-512.shtml</link>
  <pubDate>10 Dec 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-511: Citrix Web Interface Cross-Site Scripting Vulnerability</title>
  <description>Citrix Web Interface Cross-Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-511.shtml</link>
  <pubDate>09 Dec 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-510: Apple Releases QuickTime 7.6.9 Security Update</title>
  <description>Apple Releases QuickTime 7.6.9 Security Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-510.shtml</link>
  <pubDate>08 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-509: Red Hat Enterprise Virtualization Manager Race Condition Lets Local Users Gain Elevated Privileges </title>
  <description>Red Hat Enterprise Virtualization Manager Race Condition Lets Local Users Gain Elevated Privileges </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-509.shtml</link>
  <pubDate>07 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-508: Google Chrome Multiple Flaws</title>
  <description>Google Chrome Multiple Flaws</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-508.shtml</link>
  <pubDate>06 Dec 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-507: VMware Server Multiple Vulnerabilities</title>
  <description>VMware Server Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-507.shtml</link>
  <pubDate>03 Dec 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-506: Microsoft Windows win32k.sys Driver GreEnableEUDC() Vulnerability</title>
  <description>Microsoft Windows win32k.sys Driver GreEnableEUDC() Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-506.shtml</link>
  <pubDate>02 Dec 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-505: OpenSSL TLS Server Extension Parsing Buffer Overflow Vulnerability</title>
  <description>OpenSSL TLS Server Extension Parsing Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-505.shtml</link>
  <pubDate>01 Dec 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-504: Apache Tomcat Manager application XSS vulnerability</title>
  <description>Apache Tomcat Manager application XSS vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-504.shtml</link>
  <pubDate>30 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-503: Novell ZENworks Handheld Management Buffer Overflow in 'ZfHIPCND.exe' Lets Remote Users Execute Arbitrary Code</title>
  <description>Novell ZENworks Handheld Management Buffer Overflow in 'ZfHIPCND.exe' Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-503.shtml</link>
  <pubDate>29 Nov 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-502: Internet Explorer CSS Tag Parsing Code Execution Vulnerability</title>
  <description>Internet Explorer CSS Tag Parsing Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-502.shtml</link>
  <pubDate>26 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-501: Linux Kernel 'setup_arg_pages()' Denial of Service Vulnerability</title>
  <description>Linux Kernel 'setup_arg_pages()' Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-501.shtml</link>
  <pubDate>26 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-500: Adobe Reader Heap Corruption vulnerability</title>
  <description>Adobe Reader Heap Corruption vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-500.shtml</link>
  <pubDate>24 Nov 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-499: Cisco Unified Intelligent Contact Management Buffer Overflows in 'Agent.exe' Let Remote Users Execute Arbitrary Code</title>
  <description>Cisco Unified Intelligent Contact Management Buffer Overflows in 'Agent.exe' Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-499.shtml</link>
  <pubDate>23 Nov 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-498: Joomla! Sponsor Wall Component catid SQL Injection Vulnerability</title>
  <description>Joomla! Sponsor Wall Component catid SQL Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-498.shtml</link>
  <pubDate>22 Nov 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-497: T-497: Microsoft Data Access Objects (DAO) 'dao360.dll' DLL Loading Arbitrary Code Execution</title>
  <description>T-497: Microsoft Data Access Objects (DAO) 'dao360.dll' DLL Loading Arbitrary Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-497.shtml</link>
  <pubDate>19 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-496: Microsoft Office RTF File Stack Buffer Overflow Vulnerability</title>
  <description>Microsoft Office RTF File Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-496.shtml</link>
  <pubDate>18 Nov 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-495: HP LaserJet Printer Printer Job Language (PJL) Interface Directory Traversal Flaw Lets Remote Users View Arbitrary Files</title>
  <description>HP LaserJet Printer Printer Job Language (PJL) Interface Directory Traversal Flaw Lets Remote Users View Arbitrary Files</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-495.shtml</link>
  <pubDate>17 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-494: Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User</title>
  <description>Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-494.shtml</link>
  <pubDate>16 Nov 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-493: PHP mb_strcut() May Disclose Potentially Sensitive Information</title>
  <description>PHP mb_strcut() May Disclose Potentially Sensitive Information</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-493.shtml</link>
  <pubDate>15 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-492: Flash Media Server Flaws Let Remote Users Deny Service or Execute Arbitrary Code</title>
  <description>Flash Media Server Flaws Let Remote Users Deny Service or Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-492.shtml</link>
  <pubDate>12 Nov 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-491: Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Apple QuickTime Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-491.shtml</link>
  <pubDate>11 Nov 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-490: Microsoft PowerPoint Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>Microsoft PowerPoint Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-490.shtml</link>
  <pubDate>10 Nov 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-489: Red Hat Certificate System Bugs Let Remote Users Obtain One-Time PINs and Generate Certificates</title>
  <description>Red Hat Certificate System Bugs Let Remote Users Obtain One-Time PINs and Generate Certificates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-489.shtml</link>
  <pubDate>09 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-488: PHP Null Pointer Dereference in ZipArchive:getArchiveComment() May Let Remote Users Execute Arbitrary Code</title>
  <description>PHP Null Pointer Dereference in ZipArchive:getArchiveComment() May Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-488.shtml</link>
  <pubDate>08 Nov 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-487: Adobe Reader Memory Corruption Flaw Lets Remote Users Execute Arbitrary Code</title>
  <description>Adobe Reader Memory Corruption Flaw Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-487.shtml</link>
  <pubDate>05 Nov 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-486: Adobe Flash Player Flaws Lets Remote Users Execute Arbitrary Code Code</title>
  <description>Adobe Flash Player Flaws Lets Remote Users Execute Arbitrary Code Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-486.shtml</link>
  <pubDate>05 Nov 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-485: PAM Lets Local Users Gain Elevated Privileges</title>
  <description>PAM Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-485.shtml</link>
  <pubDate>05 Nov 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-484: Linux Kernel Denial of Service Vulnerability</title>
  <description>Linux Kernel Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-484.shtml</link>
  <pubDate>04 Nov 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-483: Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
  <description>Vulnerability in Internet Explorer Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-483.shtml</link>
  <pubDate>03 Nov 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-482: Java for Mac OS X 10.5 Update 8</title>
  <description>Java for Mac OS X 10.5 Update 8</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-482.shtml</link>
  <pubDate>03 Nov 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-481: Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities</title>
  <description>Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-481.shtml</link>
  <pubDate>02 Nov 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-480: Cumulative Security Update for Internet Explorer</title>
  <description>Cumulative Security Update for Internet Explorer</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-480.shtml</link>
  <pubDate>01 Nov 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-479: Adobe Shockwave Player Has Multiple Flaws That Let Remote Users Execute Arbitrary Code</title>
  <description>Adobe Shockwave Player Has Multiple Flaws That Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-479.shtml</link>
  <pubDate>29 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-478: Oracle Critical Patch Update Advisory - October 2010</title>
  <description>Oracle Critical Patch Update Advisory - October 2010</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-478.shtml</link>
  <pubDate>29 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-477: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</title>
  <description>Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-477.shtml</link>
  <pubDate>28 Oct 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-476: Critical vulnerability in Firefox 3.5 and Firefox 3.6</title>
  <description>Critical vulnerability in Firefox 3.5 and Firefox 3.6</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-476.shtml</link>
  <pubDate>28 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-475: Adobe Shockwave Player rcsL Chunk EAX Register Memory Corruption Vulnerability</title>
  <description>Adobe Shockwave Player rcsL Chunk EAX Register Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-475.shtml</link>
  <pubDate>27 Oct 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-474: Blue Coat ProxyAV Permits Cross-Site Request Forgery Attacks</title>
  <description>Blue Coat ProxyAV Permits Cross-Site Request Forgery Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-474.shtml</link>
  <pubDate>26 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-473: Microsoft Internet Explorer 'window.onerror' Callback Lets Remote Users Obtain Information From Other Domains</title>
  <description>Microsoft Internet Explorer 'window.onerror' Callback Lets Remote Users Obtain Information From Other Domains</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-473.shtml</link>
  <pubDate>25 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-472: Mac OS X Java Command Injection Flaw in updateSharingD Lets Local Users Gain Elevated Privileges.</title>
  <description>Mac OS X Java Command Injection Flaw in updateSharingD Lets Local Users Gain Elevated Privileges.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-472.shtml</link>
  <pubDate>22 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-471: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-471.shtml</link>
  <pubDate>22 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-470: Microsoft Office Excel Ghost Record Parsing Arbitrary Code Execution Vulnerability</title>
  <description>Microsoft Office Excel Ghost Record Parsing Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-470.shtml</link>
  <pubDate>21 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-469: Linux RDS Protocol Local Privilege Escalation</title>
  <description>Linux RDS Protocol Local Privilege Escalation</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-469.shtml</link>
  <pubDate>20 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-468: Blue Coat ProxySG Lets Remote Users Bypass JavaScript Filtering.</title>
  <description>Blue Coat ProxySG Lets Remote Users Bypass JavaScript Filtering.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-468.shtml</link>
  <pubDate>19 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-467: RealPlayer Bugs Let Remote Users Execute Arbitrary Code</title>
  <description>RealPlayer Bugs Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-467.shtml</link>
  <pubDate>19 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-466: HP ProCurve Products Unspecified Privilege Escalation Vulnerability</title>
  <description>HP ProCurve Products Unspecified Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-466.shtml</link>
  <pubDate>18 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-465: Linux Kernel i915 Driver Access Control Flaw Lets Local Users Gain Elevated Privileges</title>
  <description>Linux Kernel i915 Driver Access Control Flaw Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-465.shtml</link>
  <pubDate>18 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-464: BlackBerry Enterprise Server Buffer Overflow in Attachment Service Lets Remote Users Execute Arbitrary Code</title>
  <description>BlackBerry Enterprise Server Buffer Overflow in Attachment Service Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-464.shtml</link>
  <pubDate>15 Oct 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-463: Microsoft Security Bulletin MS10-076 Critical Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution</title>
  <description>Microsoft Security Bulletin MS10-076 Critical Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-463.shtml</link>
  <pubDate>15 Oct 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-462: Microsoft Security Advisory (973811) Extended Protection for Authentication.</title>
  <description>Microsoft Security Advisory (973811) Extended Protection for Authentication.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-462.shtml</link>
  <pubDate>15 Oct 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-461: Microsoft Security Bulletin MS10-071. Critical vulnerabilities in Internet Explorer.</title>
  <description>Microsoft Security Bulletin MS10-071. Critical vulnerabilities in Internet Explorer.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-461.shtml</link>
  <pubDate>14 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-460: Oracle WebLogic Node Manager Remote Configuration Capability Lets Remote Users Execute Arbitrary Commands.</title>
  <description>Oracle WebLogic Node Manager Remote Configuration Capability Lets Remote Users Execute Arbitrary Commands.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-460.shtml</link>
  <pubDate>14 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-459: Oracle Siebel Bugs Let Remote Authenticated Users Partially Access and Modify Data and Cause Partial Denial of Service Conditions</title>
  <description>Oracle Siebel Bugs Let Remote Authenticated Users Partially Access and Modify Data and Cause Partial Denial of Service Conditions</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-459.shtml</link>
  <pubDate>13 Oct 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-458: Windows LPC Processing Flaw Lets Local Users Deny Service</title>
  <description>Windows LPC Processing Flaw Lets Local Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-458.shtml</link>
  <pubDate>12 Oct 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-457: Red Hat Enterprise MRG Messaging SSL and Persistent Message Processing Flaws Let Remote and Remote Authenticated Users Deny Service</title>
  <description>Red Hat Enterprise MRG Messaging SSL and Persistent Message Processing Flaws Let Remote and Remote Authenticated Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-457.shtml</link>
  <pubDate>08 Oct 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-456: RSA Authentication Client Access Control Flaw Lets Local Users Extract Certain Key Material</title>
  <description>RSA Authentication Client Access Control Flaw Lets Local Users Extract Certain Key Material</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-456.shtml</link>
  <pubDate>07 Oct 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-455: Security updates available for Adobe Reader and Acrobat</title>
  <description>Security updates available for Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-455.shtml</link>
  <pubDate>06 Oct 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-454: A vulnerability in the Internet Group Management Protocol (IGMP) version 3</title>
  <description>A vulnerability in the Internet Group Management Protocol (IGMP) version 3</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-454.shtml</link>
  <pubDate>05 Oct 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-453: Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service</title>
  <description>Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-453.shtml</link>
  <pubDate>04 Oct 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-452: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</title>
  <description>Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-452.shtml</link>
  <pubDate>01 Oct 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-451: Microsoft Internet Information Server (IIS) Web Server Stack Overflow</title>
  <description>Microsoft Internet Information Server (IIS) Web Server Stack Overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-451.shtml</link>
  <pubDate>01 Oct 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-450: IBM Tivoli Storage Manager Fastback Lets Remote Users Deny Service and Execute Arbitrary Code</title>
  <description>IBM Tivoli Storage Manager Fastback Lets Remote Users Deny Service and Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-450.shtml</link>
  <pubDate>30 Sep 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-449: Apache Tomcat is prone to multiple remote vulnerabilities</title>
  <description>Apache Tomcat is prone to multiple remote vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-449.shtml</link>
  <pubDate>29 Sep 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-448: Vulnerability in ASP.NET Could Allow Information Disclosure</title>
  <description>Vulnerability in ASP.NET Could Allow Information Disclosure</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-448.shtml</link>
  <pubDate>28 Sep 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-447: Red Hat Directory Server for HP-UX Lets Local Users Gain Elevated Privileges</title>
  <description>Red Hat Directory Server for HP-UX Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-447.shtml</link>
  <pubDate>27 Sep 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-446: Microsoft Security Bulletin Summary for September 2010</title>
  <description>Microsoft Security Bulletin Summary for September 2010</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-446.shtml</link>
  <pubDate>24 Sep 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-445: RSA Authentication Agent for Web Directory Traversal Vulnerability</title>
  <description>RSA Authentication Agent for Web Directory Traversal Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-445.shtml</link>
  <pubDate>23 Sep 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-444: Linux Kernel IA32 Emulation Regression Lets Local Users Gain Root Privileges</title>
  <description>Linux Kernel IA32 Emulation Regression Lets Local Users Gain Root Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-444.shtml</link>
  <pubDate>22 Sep 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-443: Microsoft Office Outlook Heap Overflow Arbitrary Code Execution Vulnerability</title>
  <description>Microsoft Office Outlook Heap Overflow Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-443.shtml</link>
  <pubDate>21 Sep 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-442: Linux kernel 64-bit Compatibility Mode Stack Pointer Underflow</title>
  <description>Linux kernel 64-bit Compatibility Mode Stack Pointer Underflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-442.shtml</link>
  <pubDate>20 Sep 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-441: HP System Management Homepage Input Validation Flaw</title>
  <description>HP System Management Homepage Input Validation Flaw</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-441.shtml</link>
  <pubDate>17 Sep 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-440: Apple Quick Time DLL Loading and ActiveX Control Bugs</title>
  <description>Apple Quick Time DLL Loading and ActiveX Control Bugs</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-440.shtml</link>
  <pubDate>16 Sep 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-439: Adobe Flash Player Zero-Day Vulnerability</title>
  <description>Adobe Flash Player Zero-Day Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-439.shtml</link>
  <pubDate>15 Sep 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-438: Microsoft Outlook Web Access Authentication Flaw</title>
  <description>Microsoft Outlook Web Access Authentication Flaw</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-438.shtml</link>
  <pubDate>15 Sep 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-437: 3Com OfficeConnect Gigabit VPN Firewall Input Validation Hole Permits Cross-Site Scripting Attacks</title>
  <description>3Com OfficeConnect Gigabit VPN Firewall Input Validation Hole Permits Cross-Site Scripting Attacks</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-437.shtml</link>
  <pubDate>15 Sep 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-436: BlackBerry Desktop Software May Load DLLs Unsafely and Remotely Execute</title>
  <description>BlackBerry Desktop Software May Load DLLs Unsafely and Remotely Execute</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-436.shtml</link>
  <pubDate>13 Sep 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-435: Apache Traffic Server Insufficient Randomization</title>
  <description>Apache Traffic Server Insufficient Randomization</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-435.shtml</link>
  <pubDate>10 Sep 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-434: Security update available for Shockwave Player</title>
  <description>Security update available for Shockwave Player</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-434.shtml</link>
  <pubDate>09 Sep 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-433: Security Advisory for Adobe Reader and Acrobat</title>
  <description>Security Advisory for Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-433.shtml</link>
  <pubDate>08 Sep 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-432: Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</title>
  <description>Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-432.shtml</link>
  <pubDate>07 Sep 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-431: Linux Kernel Null Pointer Dereference in irda_bind() May Let Local Users Gain Elevated Privileges</title>
  <description>Linux Kernel Null Pointer Dereference in irda_bind() May Let Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-431.shtml</link>
  <pubDate>03 Sep 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-430: Apple QuickTime Flaw in QTPlugin.ocx ActiveX Control Lets Remote Users Execute Arbitrary Code</title>
  <description>Apple QuickTime Flaw in QTPlugin.ocx ActiveX Control Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-430.shtml</link>
  <pubDate>02 Sep 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-429: WaspTime MS-SQL Database instance with blank password for sa account</title>
  <description>WaspTime MS-SQL Database instance with blank password for sa account</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-429.shtml</link>
  <pubDate>01 Sep 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-428: Vulnerability in Help and Support Center</title>
  <description>Vulnerability in Help and Support Center</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-428.shtml</link>
  <pubDate>31 Aug 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-427: VMWare WebAccess Vulnerability</title>
  <description>VMWare WebAccess Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-427.shtml</link>
  <pubDate>31 Aug 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-426: Microsoft Windows Shortcut 'LNK/PIF' Files Automatic File Execution Vulnerability</title>
  <description>Microsoft Windows Shortcut 'LNK/PIF' Files Automatic File Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-426.shtml</link>
  <pubDate>27 Aug 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-425: Desktop Java running in web browsers</title>
  <description>Desktop Java running in web browsers</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-425.shtml</link>
  <pubDate>26 Aug 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-424: Windows TCP/IP Stack IcmpSendEcho2Ex() Bug Lets Local Users Deny Service</title>
  <description>Windows TCP/IP Stack IcmpSendEcho2Ex() Bug Lets Local Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-424.shtml</link>
  <pubDate>25 Aug 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-423: Microsoft Security Advisory (2269637) - Insecure Library Loading Could Allow Remote Code Execution</title>
  <description>Microsoft Security Advisory (2269637) - Insecure Library Loading Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-423.shtml</link>
  <pubDate>24 Aug 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-422: Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability</title>
  <description>Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-422.shtml</link>
  <pubDate>23 Aug 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-421: Multiple CACTI Security Vulnerabilities</title>
  <description>Multiple CACTI Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-421.shtml</link>
  <pubDate>20 Aug 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-420: Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability</title>
  <description>Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-420.shtml</link>
  <pubDate>20 Aug 2010 00:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-419: PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability</title>
  <description>PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-419.shtml</link>
  <pubDate>18 Aug 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-418: Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability</title>
  <description>Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-418.shtml</link>
  <pubDate>17 Aug 2010 11:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-417: Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities</title>
  <description>Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-417.shtml</link>
  <pubDate>16 Aug 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-417: Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities</title>
  <description>Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-417.shtml</link>
  <pubDate>16 Aug 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-416: Sun Solaris Multiple Vulnerabilities</title>
  <description>Sun Solaris Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-416.shtml</link>
  <pubDate>13 Aug 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-415: SQL Injection Vulnerability in Cisco Wireless Control System</title>
  <description>SQL Injection Vulnerability in Cisco Wireless Control System</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-415.shtml</link>
  <pubDate>12 Aug 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-414: Security update available for Adobe Flash Player and Adobe AIR</title>
  <description>Security update available for Adobe Flash Player and Adobe AIR</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-414.shtml</link>
  <pubDate>11 Aug 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-413: Microsoft August 2010 Security Bulletin Release</title>
  <description>Microsoft August 2010 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-413.shtml</link>
  <pubDate>10 Aug 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-412: WebKit CSS Counters Remote Memory Corruption Vulnerability</title>
  <description>WebKit CSS Counters Remote Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-412.shtml</link>
  <pubDate>09 Aug 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-411: PHP 'SplObjectStorage' Unserializer Arbitrary Code Execution Vulnerability</title>
  <description>PHP 'SplObjectStorage' Unserializer Arbitrary Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-411.shtml</link>
  <pubDate>06 Aug 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-410: Linux Kernel 'gfs2_quota' Structure Write Local Privilege Escalation Vulnerability</title>
  <description>Linux Kernel 'gfs2_quota' Structure Write Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-410.shtml</link>
  <pubDate>05 Aug 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-409: Citrix Online Plug-In and ICA Client Heap Overflow Remote Code Execution Vulnerability</title>
  <description>Citrix Online Plug-In and ICA Client Heap Overflow Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-409.shtml</link>
  <pubDate>04 Aug 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-408: phpCAS CAS Proxy Mode Cross-Site Scripting Vulnerability</title>
  <description>phpCAS CAS Proxy Mode Cross-Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-408.shtml</link>
  <pubDate>03 Aug 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-407: W3M NULL Character CA SSL Certificate Validation Security Bypass Vulnerability</title>
  <description>W3M NULL Character CA SSL Certificate Validation Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-407.shtml</link>
  <pubDate>02 Aug 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-406: Pidgin 'X-Status' Message Denial of Service Vulnerability</title>
  <description>Pidgin 'X-Status' Message Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-406.shtml</link>
  <pubDate>30 Jul 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-405: WebKit 'font-face' and 'use' Elements Use-After-Free Remote Code Execution Vulnerability</title>
  <description>WebKit 'font-face' and 'use' Elements Use-After-Free Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-405.shtml</link>
  <pubDate>29 Jul 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-404: Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability</title>
  <description>Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-404.shtml</link>
  <pubDate>28 Jul 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-403: Mozilla Firefox Plugin Parameter Reference Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Plugin Parameter Reference Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-403.shtml</link>
  <pubDate>27 Jul 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-402: Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability</title>
  <description>Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-402.shtml</link>
  <pubDate>26 Jul 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-401: Multiple Mozilla Product Vulnerabilites</title>
  <description>Multiple Mozilla Product Vulnerabilites</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-401.shtml</link>
  <pubDate>23 Jul 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-400: HP OpenView Network Node Manager CVE-2010-2704 Multiple Code Execution Vulnerabilities</title>
  <description>HP OpenView Network Node Manager CVE-2010-2704 Multiple Code Execution Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-400.shtml</link>
  <pubDate>22 Jul 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-399: OpenLDAP 'modrdn' Request Multiple Vulnerabilities</title>
  <description>OpenLDAP 'modrdn' Request Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-399.shtml</link>
  <pubDate>20 Jul 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-398: Microsoft Windows Shortcut 'LNK' Files Automatic File Execution Vulnerability</title>
  <description>Microsoft Windows Shortcut 'LNK' Files Automatic File Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-398.shtml</link>
  <pubDate>19 Jul 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-397: ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability</title>
  <description>ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-397.shtml</link>
  <pubDate>16 Jul 2010 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-396: PostgreSQL Multiple Security Vulnerabilities</title>
  <description>PostgreSQL Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-396.shtml</link>
  <pubDate>15 Jul 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-395: Oracle Secure Backup Scheduler Service Remote Code Execution Vulnerability</title>
  <description>Oracle Secure Backup Scheduler Service Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-395.shtml</link>
  <pubDate>14 Jul 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-394: Python-cjson Unicode Character Encoding Buffer Overflow Vulnerability</title>
  <description>Python-cjson Unicode Character Encoding Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-394.shtml</link>
  <pubDate>12 Jul 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-393: iSCSI Enterprise Target Multiple Implementations iSNS Message Stack Buffer Overflow Vulnerability</title>
  <description>iSCSI Enterprise Target Multiple Implementations iSNS Message Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-393.shtml</link>
  <pubDate>08 Jul 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-392: Cisco Security Advisory: Hard-Coded SNMP Community Names in Cisco Industrial Ethernet 3000 Series Switches Vulnerability</title>
  <description>Cisco Security Advisory: Hard-Coded SNMP Community Names in Cisco Industrial Ethernet 3000 Series Switches Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-392.shtml</link>
  <pubDate>07 Jul 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-391: libpng Memory Corruption and Memory Leak Vulnerabilities</title>
  <description>libpng Memory Corruption and Memory Leak Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-391.shtml</link>
  <pubDate>01 Jul 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-390: Security updates available for Adobe Reader and Acrobat</title>
  <description>Security updates available for Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-390.shtml</link>
  <pubDate>29 Jun 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-389: LibTIFF 'TIFFroundup()' Remote Integer Overflow Vulnerability</title>
  <description>LibTIFF 'TIFFroundup()' Remote Integer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-389.shtml</link>
  <pubDate>25 Jun 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-388: ISC DHCP Server find_length() Zero-Length Client Identifier Remote Denial Of Service Vulnerability</title>
  <description>ISC DHCP Server find_length() Zero-Length Client Identifier Remote Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-388.shtml</link>
  <pubDate>24 Jun 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-387: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-26/27/28/29/30/32 Remote Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-26/27/28/29/30/32 Remote Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-387.shtml</link>
  <pubDate>23 Jun 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-386: Apple Safari Authentication Data URI Spoofing Vulnerability</title>
  <description>Apple Safari Authentication Data URI Spoofing Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-386.shtml</link>
  <pubDate>22 Jun 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-385: Apple Mac OS X CUPS Web Interface Unspecified Information Disclosure Vulnerability</title>
  <description>Apple Mac OS X CUPS Web Interface Unspecified Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-385.shtml</link>
  <pubDate>18 Jun 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-384: Sudo 'secure path' Security Bypass Vulnerability</title>
  <description>Sudo 'secure path' Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-384.shtml</link>
  <pubDate>17 Jun 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-383: Samba 'SMB1 Packet Chaining' Unspecified Remote Memory Corruption Vulnerability</title>
  <description>Samba 'SMB1 Packet Chaining' Unspecified Remote Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-383.shtml</link>
  <pubDate>16 Jun 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-382: Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities</title>
  <description>Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-382.shtml</link>
  <pubDate>14 Jun 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-381: Adobe Flash Player (CVE-2009-3793) Remote Code Execution Vulnerability</title>
  <description>Adobe Flash Player (CVE-2009-3793) Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-381.shtml</link>
  <pubDate>11 Jun 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-380: Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability</title>
  <description>Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-380.shtml</link>
  <pubDate>10 Jun 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-379: Microsoft June 2010 Security Bulletin Release</title>
  <description>Microsoft June 2010 Security Bulletin Release</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-379.shtml</link>
  <pubDate>08 Jun 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-378: Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability</title>
  <description>Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-378.shtml</link>
  <pubDate>07 Jun 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-377: Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability</title>
  <description>Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-377.shtml</link>
  <pubDate>04 Jun 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-376: OpenSSL 'ssl3_get_record()' Remote Denial of Service Vulnerability</title>
  <description>OpenSSL 'ssl3_get_record()' Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-376.shtml</link>
  <pubDate>02 Jun 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-375: Cisco Network Building Mediator HTTP Communication Remote Information Disclosure Vulnerability</title>
  <description>Cisco Network Building Mediator HTTP Communication Remote Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-375.shtml</link>
  <pubDate>01 Jun 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-374: ISC BIND 9 DNSSEC Bogus NXDOMAIN Response Remote Cache Poisoning Vulnerability</title>
  <description>ISC BIND 9 DNSSEC Bogus NXDOMAIN Response Remote Cache Poisoning Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-374.shtml</link>
  <pubDate>28 May 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-373: Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability</title>
  <description>Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-373.shtml</link>
  <pubDate>26 May 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-372: Cisco IronPort Desktop Flag Plug-in for Outlook Send Secure Information Disclosure Vulnerability</title>
  <description>Cisco IronPort Desktop Flag Plug-in for Outlook Send Secure Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-372.shtml</link>
  <pubDate>25 May 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-371: Xpdf Multiple Integer Overflow Vulnerabilities</title>
  <description>Xpdf Multiple Integer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-371.shtml</link>
  <pubDate>24 May 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-370: PostgreSQL Multiple Security Vulnerabilities</title>
  <description>PostgreSQL Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-370.shtml</link>
  <pubDate>21 May 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-369: Oracle Sun Ray Server Software CVE-2010-0888 Remote Device Services Vulnerability</title>
  <description>Oracle Sun Ray Server Software CVE-2010-0888 Remote Device Services Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-369.shtml</link>
  <pubDate>20 May 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-368: Microsoft Visual Basic for Applications Text Parsing Stack Buffer Overflow Vulnerability</title>
  <description>Microsoft Visual Basic for Applications Text Parsing Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-368.shtml</link>
  <pubDate>18 May 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-367: VMware View URL Processing Cross-site Scripting Vulnerability</title>
  <description>VMware View URL Processing Cross-site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-367.shtml</link>
  <pubDate>17 May 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-366: Microsoft PowerPoint Viewer TextBytesAtom Record Stack Overflow Remote Code Execution Vulnerability</title>
  <description>Microsoft PowerPoint Viewer TextBytesAtom Record Stack Overflow Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-366.shtml</link>
  <pubDate>14 May 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-365: Apache mod_auth_shadow Race Condition Security Bypass Vulnerability</title>
  <description>Apache mod_auth_shadow Race Condition Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-365.shtml</link>
  <pubDate>13 May 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-364: Multiple Adobe Shockwave Player Remote Code Execution Vulnerabilities</title>
  <description>Multiple Adobe Shockwave Player Remote Code Execution Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-364.shtml</link>
  <pubDate>12 May 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-363: Microsoft Security Bulletin Summary for May 2010</title>
  <description>Microsoft Security Bulletin Summary for May 2010</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-363.shtml</link>
  <pubDate>11 May 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-362: Sun Java System Web Server WebDAV Unspecified Remote Buffer Overflow Vulnerability</title>
  <description>Sun Java System Web Server WebDAV Unspecified Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-362.shtml</link>
  <pubDate>10 May 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-361: Microsoft Paint JPEG Image Processing Integer Overflow Vulnerability</title>
  <description>Microsoft Paint JPEG Image Processing Integer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-361.shtml</link>
  <pubDate>06 May 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-360: Linux Kernel 'sctp_rcv_ootb()' Remote Denial of Service Vulnerability</title>
  <description>Linux Kernel 'sctp_rcv_ootb()' Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-360.shtml</link>
  <pubDate>04 May 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-359: ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability</title>
  <description>ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-359.shtml</link>
  <pubDate>30 Apr 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-358: MIT Kerberos 'src/kdc/do_tgs_req.c' Ticket Renewal Double Free Memory Corruption Vulnerability</title>
  <description>MIT Kerberos 'src/kdc/do_tgs_req.c' Ticket Renewal Double Free Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-358.shtml</link>
  <pubDate>28 Apr 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-357: Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability</title>
  <description>Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-357.shtml</link>
  <pubDate>27 Apr 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-356: Oracle Database Change Data Capture Remote SQL Injection Vulnerability</title>
  <description>Oracle Database Change Data Capture Remote SQL Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-356.shtml</link>
  <pubDate>26 Apr 2010 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-355: Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability</title>
  <description>Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-355.shtml</link>
  <pubDate>23 Apr 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-354: Microsoft Security Bulletin MS10-025 - Critical</title>
  <description>Microsoft Security Bulletin MS10-025 - Critical</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-354.shtml</link>
  <pubDate>22 Apr 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-353: McAfee DAT 5958 Update Causes Issues</title>
  <description>McAfee DAT 5958 Update Causes Issues</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-353.shtml</link>
  <pubDate>21 Apr 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-352: iSCSI Enterprise Target and tgt Multiple Format String Vulnerabilities</title>
  <description>iSCSI Enterprise Target and tgt Multiple Format String Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-352.shtml</link>
  <pubDate>20 Apr 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-351: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</title>
  <description>Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-351.shtml</link>
  <pubDate>19 Apr 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-350: T-350: Adobe Acrobat and Reader Denial of Service Vulnerability</title>
  <description>T-350: Adobe Acrobat and Reader Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-350.shtml</link>
  <pubDate>16 Apr 2010 22:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-349: [USN-928-1] Sudo vulnerability</title>
  <description>[USN-928-1] Sudo vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-349.shtml</link>
  <pubDate>15 Apr 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-348: Java Deployment Toolkit Performs Insufficient Validation of Parameters</title>
  <description>Java Deployment Toolkit Performs Insufficient Validation of Parameters</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-348.shtml</link>
  <pubDate>14 Apr 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-347: VMware Hosted Products 'vmware-vmx' Virtual Network Stack Information Disclosure Vulnerability</title>
  <description>VMware Hosted Products 'vmware-vmx' Virtual Network Stack Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-347.shtml</link>
  <pubDate>13 Apr 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-346: MIT Kerberos kadmind 'server_stubs.c' Remote Denial Of Service Vulnerability</title>
  <description>MIT Kerberos kadmind 'server_stubs.c' Remote Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-346.shtml</link>
  <pubDate>12 Apr 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-345: VMware Hosted Products VMSA-2010-0007 Multiple Remote Vulnerabilities</title>
  <description>VMware Hosted Products VMSA-2010-0007 Multiple Remote Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-345.shtml</link>
  <pubDate>09 Apr 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-344: Apple QuickTime FLC Encoded '.fli' Movie File Remote Heap Buffer Overflow Vulnerability</title>
  <description>Apple QuickTime FLC Encoded '.fli' Movie File Remote Heap Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-344.shtml</link>
  <pubDate>08 Apr 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-343: Oracle Java SE and Java for Business CVE-2010-0091 Remote Java Runtime Environment Vulnerability</title>
  <description>Oracle Java SE and Java for Business CVE-2010-0091 Remote Java Runtime Environment Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-343.shtml</link>
  <pubDate>07 Apr 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-342: Mozilla Firefox Cross Document DOM Node Movement Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Cross Document DOM Node Movement Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-342.shtml</link>
  <pubDate>06 Apr 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-341: Sun Java System Web Server WebDAV Unspecified Remote Buffer Overflow Vulnerability</title>
  <description>Sun Java System Web Server WebDAV Unspecified Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-341.shtml</link>
  <pubDate>05 Apr 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-340: Jabber Studio JabberD Remote Denial Of Service Vulnerability</title>
  <description>Jabber Studio JabberD Remote Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-340.shtml</link>
  <pubDate>02 Apr 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-339: Mozilla Firefox Use-After-Free Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Use-After-Free Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-339.shtml</link>
  <pubDate>02 Apr 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-338: Apple iPhone Malformed VML Data Remote Code Execution Vulnerability</title>
  <description>Apple iPhone Malformed VML Data Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-338.shtml</link>
  <pubDate>31 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-337: Cisco IOS SIP Message Remote Code Execution Vulnerability</title>
  <description>Cisco IOS SIP Message Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-337.shtml</link>
  <pubDate>30 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-336: phpCAS Cross-Site Scripting Vulnerability</title>
  <description>phpCAS Cross-Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-336.shtml</link>
  <pubDate>29 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-335: Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability</title>
  <description>Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-335.shtml</link>
  <pubDate>26 Mar 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-334: OpenSSL Multiple Vulnerabilities</title>
  <description>OpenSSL Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-334.shtml</link>
  <pubDate>25 Mar 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-333: Mozilla Firefox Heap Overflow in WOFF Decoder Lets Remote Users Execute Arbitrary Code</title>
  <description>Mozilla Firefox Heap Overflow in WOFF Decoder Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-333.shtml</link>
  <pubDate>24 Mar 2010 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-332: Libpng 'png_decompress_chunk()' Function Denial of Service Vulnerability</title>
  <description>Libpng 'png_decompress_chunk()' Function Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-332.shtml</link>
  <pubDate>23 Mar 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-331: GNU Libtool 'libltdl' Library Search Path Local Privilege Escalation Vulnerability</title>
  <description>GNU Libtool 'libltdl' Library Search Path Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-331.shtml</link>
  <pubDate>22 Mar 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-330: IBM Lotus Notes 'names.nsf' Open Redirection Vulnerability</title>
  <description>IBM Lotus Notes 'names.nsf' Open Redirection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-330.shtml</link>
  <pubDate>19 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-329: Red Hat update for java-1.4.2-ibm</title>
  <description>Red Hat update for java-1.4.2-ibm</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-329.shtml</link>
  <pubDate>18 Mar 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-328: HP Broadcom Integrated NIC Firmware Remote Code Execution Vulnerability</title>
  <description>HP Broadcom Integrated NIC Firmware Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-328.shtml</link>
  <pubDate>17 Mar 2010 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-327: GNU Tar and GNU Cpio Remote Buffer Overflow Vulnerability</title>
  <description>GNU Tar and GNU Cpio Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-327.shtml</link>
  <pubDate>16 Mar 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-326: Oracle 11gR2 Multiple Remote Privilege Escalation Vulnerabilities</title>
  <description>Oracle 11gR2 Multiple Remote Privilege Escalation Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-326.shtml</link>
  <pubDate>15 Mar 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-325: Microsoft re-release of KB973811 - attacks on Extended Protection for Authentication</title>
  <description>Microsoft re-release of KB973811 - attacks on Extended Protection for Authentication</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-325.shtml</link>
  <pubDate>11 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-324: Samba 'CAP_DAC_OVERRIDE' File Permissions Security Bypass Vulnerability</title>
  <description>Samba 'CAP_DAC_OVERRIDE' File Permissions Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-324.shtml</link>
  <pubDate>10 Mar 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-323: Microsoft Security Advisory (981374)</title>
  <description>Microsoft Security Advisory (981374)</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-323.shtml</link>
  <pubDate>09 Mar 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-322: March Patch Tuesday Notes</title>
  <description>March Patch Tuesday Notes</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-322.shtml</link>
  <pubDate>09 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-321: Energizer DUO USB battery charger software allows unauthorized remote system access</title>
  <description>Energizer DUO USB battery charger software allows unauthorized remote system access</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-321.shtml</link>
  <pubDate>08 Mar 2010 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-320: Apache 2.2.14 mod_isapi Dangling Pointer</title>
  <description>Apache 2.2.14 mod_isapi Dangling Pointer</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-320.shtml</link>
  <pubDate>08 Mar 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-319: Apache Multiple Security Vulnerabilities</title>
  <description>Apache Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-319.shtml</link>
  <pubDate>05 Mar 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-318: Drupal Prior to 6.16 and 5.22 Multiple Security Vulnerabilities</title>
  <description>Drupal Prior to 6.16 and 5.22 Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-318.shtml</link>
  <pubDate>05 Mar 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-317: Vulnerability in VBScript Could Allow Remote Code Execution</title>
  <description>Vulnerability in VBScript Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-317.shtml</link>
  <pubDate>03 Mar 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-316: Microsoft Windows Client/Server Run-time Subsystem Local Privilege Escalation Vulnerability</title>
  <description>Microsoft Windows Client/Server Run-time Subsystem Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-316.shtml</link>
  <pubDate>02 Mar 2010 21:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-315: PHP 5.2.13 Security Update</title>
  <description>PHP 5.2.13 Security Update</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-315.shtml</link>
  <pubDate>01 Mar 2010 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-314: Microsoft Windows ICMPv6 Router Advertisement Remote Code Execution Vulnerability</title>
  <description>Microsoft Windows ICMPv6 Router Advertisement Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-314.shtml</link>
  <pubDate>26 Feb 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-313: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability</title>
  <description>Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-313.shtml</link>
  <pubDate>25 Feb 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-312: Adobe Download Manager Unspecified Arbitrary File Download Vulnerability</title>
  <description>Adobe Download Manager Unspecified Arbitrary File Download Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-312.shtml</link>
  <pubDate>24 Feb 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-311: Microsoft Windows SMB Client Race Condition Remote Code Execution Vulnerability</title>
  <description>Microsoft Windows SMB Client Race Condition Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-311.shtml</link>
  <pubDate>23 Feb 2010 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-310: Mozilla Firefox Multiple Remote Memory Corruption Vulnerabilities</title>
  <description>Mozilla Firefox Multiple Remote Memory Corruption Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-310.shtml</link>
  <pubDate>22 Feb 2010 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-309: Mozilla Firefox Unspecified Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Unspecified Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-309.shtml</link>
  <pubDate>19 Feb 2010 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>  
  <title>T-308: Security update available for Adobe Flash Player and Adobe AIR</title>
  <description>T-308: Security update available for Adobe Flash Player and Adobe AIR</description>	
  <link>http://circ.jc3.doe.gov/bulletins/t-308.shtml</link>
  <pubDate>17 Feb 2010 22:30 GMT</pubDate>	
  <category>New Bulletin </category>
</item>
<item>
  <title>T-307: New Adobe Updates for Multiple Vulnerabilities</title>
  <description>T-307: New Adobe Updates for Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-307.shtml</link>
  <pubDate>17 Feb 2010 17:55 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-306: krb5-1.7 KDC denial of service</title>
  <description>T-306: krb5-1.7 KDC denial of service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-306.shtml</link>
  <pubDate>17 Feb 2010 15:05 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-305: Microsoft PowerPoint OEPlaceholderAtom Invalid Array Indexing Vulnerability</title>
  <description>T-305: Microsoft PowerPoint OEPlaceholderAtom Invalid Array Indexing Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-305.shtml</link>
  <pubDate>11 February 18:05 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-304: HP OpenView Network Node Manager Java Runtime Environment and Java Developer Kit Remote Execution of Arbitrary Code
Vulnerability</title>
  <description>T-304: HP OpenView Network Node Manager Java Runtime Environment and Java Developer Kit Remote Execution of Arbitrary Code
Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-304.shtml</link>
  <pubDate>11 February 2010 14:40 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-303: Apple Safari 4.0.4 Denial of Service</title>
  <description>T-303: Apple Safari 4.0.4 Denial of Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-303.shtml</link>
  <pubDate>05 February 2010 14:55 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-302: Red Hat Linux Kernel Routing Implementation Multiple Remote Denial of Service Vulnerabilities</title>
  <description>T-302: Red Hat Linux Kernel Routing Implementation Multiple Remote Denial of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-302.shtml</link>
  <pubDate>04 Feb 2010 14:55 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-301: Citrix XenServer Authentication Bypass Vulnerability</title>
  <description>T-301: Citrix XenServer Authentication Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-301.shtml</link>
  <pubDate>03 Feb 2010 20:15 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-300: lighttpd Slow Request Handling Remote Denial of Service Vulnerability</title>
  <description>T-300: lighttpd Slow Request Handling Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-300.shtml</link>
  <pubDate>02 Feb 2010 19:30 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-299: Multiple Sun Java Vulnerabilities</title>
  <description>T-299: Multiple Sun Java Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-299.shtml</link>
  <pubDate>01 February 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-298: Samba setuid 'mount.cifs' Verbose Option Information Disclosure Vulnerability</title>
  <description>T-298: Samba setuid 'mount.cifs' Verbose Option Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-298.shtml</link>
  <pubDate>29 Jan 2010 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-297: Multiple Vendor HTML Form Protocol Vulnerability</title>
  <description>T-297: Multiple Vendor HTML Form Protocol Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-297.shtml</link>
  <pubDate>28 Jan 2010 15:40 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-296: Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unified MeetingPlace</title>
  <description>T-296: Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unified MeetingPlace</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-296.shtml</link>
  <pubDate>27 Jan 2010 20:00 GMT</pubDate>
  <category>New Bulletin</category>
</item>
<item>
  <title>T-295: Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities</title>
  <description>T-295: Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-295.shtml</link>
  <pubDate>27 January, 2010 14:40 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-294: Microsoft Internet Explorer URI Validation Remote Code Execution Vulnerability</title>
  <description>T-294: Microsoft Internet Explorer URI Validation Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-294.shtml</link>
  <pubDate>26 January 13:21 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-293: Windows Kernel #GP Trap Handler Flaw Lets Local Users Gain Elevated Privileges</title>
  <description>T-293: Windows Kernel #GP Trap Handler Flaw Lets Local Users Gain Elevated Privileges</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-293.shtml</link>
  <pubDate>25 Jan 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-292: Internet Explorer CVE-2010-0249 Remote Code Execution Vulnerability</title>
  <description>T-292: Internet Explorer CVE-2010-0249 Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-292.shtml</link>
  <pubDate>19 Jan 17:45 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-291: Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability</title>
  <description>T-291: Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-291.shtml</link>
  <pubDate>15 Jan 15:20 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-290: Net-SNMP 'snmpUDPDomain.c' Remote Information Disclosure Vulnerability</title>
  <description>T-290: Net-SNMP 'snmpUDPDomain.c' Remote Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-290.shtml</link>
  <pubDate>14 Jan 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-289: HP StorageWorks Products Remote Management Interface Privilege Escalation Vulnerability</title>
  <description>T-289: HP StorageWorks Products Remote Management Interface Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-289.shtml</link>
  <pubDate>12 Jan 15:30 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-288: New phpldapadmin packages fix remote file inclusion</title>
  <description>T-288: New phpldapadmin packages fix remote file inclusion</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-288.shtml</link>
  <pubDate>07 Jan 15:40 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-287: NetworkManager Security Bypass and Information Disclosure Vulnerabilities</title>
  <description>T-287: NetworkManager Security Bypass and Information Disclosure Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-287.shtml</link>
  <pubDate>05 Jan 2010 14:38 GMT </pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-286: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability</title>
  <description>T-286: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-286.shtml</link>
  <pubDate>28 Dec 2009 20:35 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-285: Linux Kernel KVM Large SMP Instruction Local Denial of Service Vulnerability</title>
  <description>T-285: Linux Kernel KVM Large SMP Instruction Local Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-285.shtml</link>
  <pubDate>23 Dec 2009 17:08 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-284: Allied Telesyn AT-TFTP Server Filename Remote Buffer Overflow Vulnerability</title>
  <description>T-284: Allied Telesyn AT-TFTP Server Filename Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-284.shtml</link>
  <pubDate>22 Dec 2009 21:49 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-283: Ruby on Rails 'strip_tags()' Non-Printable Character Cross Site Scripting Vulnerability</title>
  <description>T-283: Ruby on Rails 'strip_tags()' Non-Printable Character Cross Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-283.shtml</link>
  <pubDate>18 Dec 2009 15:14 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-282: Cisco ASA 8.x VPN SSL module Clientless
URL-list control bypass vulnerability.</title>
  <description>T-282: Cisco ASA 8.x VPN SSL module Clientless
URL-list control bypass vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-282.shtml</link>
  <pubDate>17 Dec 2009 16:49 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-281: Mozilla Firefox and SeaMonkey MFSA 2009-65 through -71 Multiple Vulnerabilities</title>
  <description>T-281: Mozilla Firefox and SeaMonkey MFSA 2009-65 through -71 Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-281.shtml</link>
  <pubDate>16 Dec 2009 15:26 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item><title>T-280: New Adobe Reader,Acrobat Vulnerability Under Attack</title>
<description>New Adobe Reader,Acrobat Vulnerability Under Attack</description>
<link>http://circ.jc3.doe.gov/bulletins/t-280.shtml</link>
<pubDate>15 Dec 2009 19:41 GMT</pubDate><category>New Bulletin </category></item>
<item><title>T-279: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</title>
<description>Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</description>
<link>http://circ.jc3.doe.gov/bulletins/t-279.shtml</link>
<pubDate>11 Dec 2009 15:50 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-278: ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability</title>
  <description>ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/T-278.shtml</link>
  <pubDate>11 Dec 2009 20:00 GMT</pubDate>
  <category>New Bulletin</category></item>
<item>
  <title>T-277:Microsoft Security Bulletin Summary for December 2009</title>
  <description>Microsoft Security Bulletin Summary for December 2009</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-277.shtml</link>
  <pubDate>10 Dec 2009 17:30 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-276:HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability</title>
  <description>HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-276.shtml</link>
  <pubDate>19 Nov 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-275: Sun Java Runtime Environment Font Processing Buffer Overflow Vulnerability</title>
  <description>Sun Java Runtime Environment Font Processing Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-275.shtml</link>
  <pubDate>19 Nov 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-274: HP OpenView Network Node Manager Remote Denial of Service Vulnerability</title>
  <description>HP OpenView Network Node Manager Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-274.shtml</link>
  <pubDate>18 Nov 2009 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-273: Sun xVM VirtualBox Guest Additions Kernel Memory Consumption Flaw Lets Local Users Deny Service </title>
  <description>Sun xVM VirtualBox Guest Additions Kernel Memory Consumption Flaw Lets Local Users Deny Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-273.shtml</link>
  <pubDate>17 Nov 2009 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-272: Google Chrome prior to 3.0.195.32 Multiple Security Vulnerabilities</title>
  <description>Google Chrome prior to 3.0.195.32 Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-272.shtml</link>
  <pubDate>16 Nov 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-271: McAfee IntruShield Network Security Manager Permits Session Hijacking Attacks </title>
  <description>McAfee IntruShield Network Security Manager Permits Session Hijacking Attacks </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-271.shtml</link>
  <pubDate>13 Nov 2009 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-270: Citrix Online Plug-ins Lets Remote Users Spoof SSL Endpoints</title>
  <description>Citrix Online Plug-ins Lets Remote Users Spoof SSL Endpoints</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-270.shtml</link>
  <pubDate>12 Nov 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-269: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</title>
  <description>Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-269.shtml</link>
  <pubDate>10 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-268: HP Power Manager Management Web Server Login Remote Code Execution Vulnerability</title>
  <description>HP Power Manager Management Web Server Login Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-268.shtml</link>
  <pubDate>9 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-267: Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment</title>
  <description>Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-267.shtml</link>
  <pubDate>6 Nov 2009 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-266: Sun Solaris SCTP 'sctp(7P)' and SDP 'sdp(7D)' Sockets Local Denial Of Service Vulnerability</title>
  <description>Sun Solaris SCTP 'sctp(7P)' and SDP 'sdp(7D)' Sockets Local Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-266.shtml</link>
  <pubDate>5 Nov 2009 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-265: BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability</title>
  <description>BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-265.shtml</link>
  <pubDate>4 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-264: VMware Products Directory Traversal Vulnerability</title>
  <description>VMware Products Directory Traversal Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-264.shtml</link>
  <pubDate>3 Nov 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-263: KDE Multiple Input Validation Vulnerabilities</title>
  <description>KDE Multiple Input Validation Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-263.shtml</link>
  <pubDate>2 Nov 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-262: Drupal Workflow Module Multiple HTML Injection Vulnerabilities</title>
  <description>Drupal Workflow Module Multiple HTML Injection Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-262.shtml</link>
  <pubDate>30 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-261: Solaris Trusted Extensions Weakness May Let Users Gain Elevated Privileges </title>
  <description>Solaris Trusted Extensions Weakness May Let Users Gain Elevated Privileges </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-261.shtml</link>
  <pubDate>29 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-260: Mozilla Firefox and SeaMonkey MFSA 2009-52 through -64 Multiple Vulnerabilities</title>
  <description>Mozilla Firefox and SeaMonkey MFSA 2009-52 through -64 Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-260.shtml</link>
  <pubDate>28 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-259: Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability</title>
  <description>Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-259.shtml</link>
  <pubDate>27 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-258: Multiple Security Vulnerabilities in Adobe Reader and Acrobat</title>
  <description>Multiple Security Vulnerabilities in Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-258.shtml</link>
  <pubDate>26 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-257: MapServer Multiple Security Vulnerabilities</title>
  <description>MapServer Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-257.shtml</link>
  <pubDate>23 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-256: Pidgin OSCAR Plugin Invalid Memory Access Denial Of Service Vulnerability</title>
  <description>Pidgin OSCAR Plugin Invalid Memory Access Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-256.shtml</link>
  <pubDate>22 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-255: Oracle Critical Patch Update Advisory</title>
  <description>Oracle Critical Patch Update Advisory</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-255.shtml</link>
  <pubDate>21 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-254: Cisco IOS Software Authentication Proxy Vulnerability</title>
  <description>Cisco IOS Software Authentication Proxy Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-254.shtml</link>
  <pubDate>20 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-253: Cisco Unified Presence Denial of Service Vulnerabilities</title>
  <description>Cisco Unified Presence Denial of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-253.shtml</link>
  <pubDate>19 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-252: Xpdf Multiple Integer Overflow Vulnerabilities</title>
  <description>Xpdf Multiple Integer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-252.shtml</link>
  <pubDate>16 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-251: Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability</title>
  <description>Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-251.shtml</link>
  <pubDate>15 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-250: Microsoft Patch Tuesday Reminder</title>
  <description>Microsoft Patch Tuesday Reminder</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-250.shtml</link>
  <pubDate>14 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-249: Sun VirtualBox VBoxNetAdpCtl Configuration Tool Local Privilege Escalation Vulnerability</title>
  <description>Sun VirtualBox VBoxNetAdpCtl Configuration Tool Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-249.shtml</link>
  <pubDate>13 Oct 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-248: Adobe Acrobat Reader Remote Code Execution Vulnerability</title>
  <description>Adobe Acrobat Reader Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-248.shtml</link>
  <pubDate>9 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-247: Multiple HP JetDirect Printers Multiple Cross Site Scripting Vulnerabilities</title>
  <description>Multiple HP JetDirect Printers Multiple Cross Site Scripting Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-247.shtml</link>
  <pubDate>8 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-246: IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability</title>
  <description>IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-246.shtml</link>
  <pubDate>6 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-245: VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host </title>
  <description>VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-245.shtml</link>
  <pubDate>5 Oct 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-244: Solaris IP(7P) Module and STREAMS Framework Denial of Service Vulnerabilities</title>
  <description>Solaris IP(7P) Module and STREAMS Framework Denial of Service Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-244.shtml</link>
  <pubDate>2 Oct 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-243: Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability</title>
  <description>Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-243.shtml</link>
  <pubDate>1 Oct 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-242: Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability</title>
  <description>Adobe Photoshop Elements Active File Monitor Service Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-242.shtml</link>
  <pubDate>30 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-241: Blackberry OS NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certficates </title>
  <description>Blackberry OS NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certficiates</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-241.shtml</link>
  <pubDate>29 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-240: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-240.shtml</link>
  <pubDate>28 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-239: Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vulnerability</title>
  <description>Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-239.shtml</link>
  <pubDate>25 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-238: Cisco Unified Communications Manager SIP Message Denial of Service Vulnerability</title>
  <description>Cisco Unified Communications Manager SIP Message Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-238.shtml</link>
  <pubDate>24 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-237: Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability</title>
  <description>Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-237.shtml</link>
  <pubDate>23 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-236: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-236.shtml</link>
  <pubDate>22 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-235: IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability</title>
  <description>IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-235.shtml</link>
  <pubDate>21 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-234: Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-234.shtml</link>
  <pubDate>18 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-233: Wireshark 1.2.1 Multiple Vulnerabilities</title>
  <description>Wireshark 1.2.1 Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-233.shtml</link>
  <pubDate>17 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-232: VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities</title>
  <description>VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-232.shtml</link>
  <pubDate>16 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-231: HP StorageWorks Remote Management Interface Vulnerability</title>
  <description>HP StorageWorks Remote Management Interface Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-231.shtml</link>
  <pubDate>15 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-230: Solaris Heap Overflow Vulnerability in w(1) Utility</title>
  <description>Solaris Heap Overflow Vulnerability in w(1) Utility</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-230.shtml</link>
  <pubDate>14 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-229: Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities</title>
  <description>Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-229.shtml</link>
  <pubDate>11 Sep 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-228: Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability</title>
  <description>Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-228.shtml</link>
  <pubDate>10 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-227: Microsoft Patch Tuesday Reminder</title>
  <description>Microsoft Patch Tuesday Reminder</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-227.shtml</link>
  <pubDate>9 Sep 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-226: Debian devscripts 'uscan' Input Validation Vulnerability</title>
  <description>Debian devscripts 'uscan' Input Validation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-226.shtml</link>
  <pubDate>8 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-225: Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability</title>
  <description>Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-225.shtml</link>
  <pubDate>4 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-224: OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities</title>
  <description>OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-224.shtml</link>
  <pubDate>3 Sep 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-223: Autonomy KeyView Module Excel Document Processing Buffer Overflow Vulnerability</title>
  <description>Autonomy KeyView Module Excel Document Processing Buffer Overflow</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-223.shtml</link>
  <pubDate>2 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-222: Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability</title>
  <description>Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-222.shtml</link>
  <pubDate>1 Sep 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-221: Multiple Browser HTTP Resource in HTTPS Context Security Bypass Vulnerability</title>
  <description>Multiple Browser HTTP Resource in HTTPS Context Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-221.shtml</link>
  <pubDate>31 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-220: Sun Java System Access Manager Debug Files Local Information Disclosure Vulnerability</title>
  <description>Sun Java System Access Manager Debug Files Local Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-220.shtml</link>
  <pubDate>28 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-219: Sun Virtual Desktop Infrastructure (VDI) Secure LDAP Vulnerability</title>
  <description>Sun Virtual Desktop Infrastructure (VDI) Secure LDAP Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-219.shtml</link>
  <pubDate>27 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-218: Cisco Lightweight Access Point Over-the-Air Provisioning Manipulation Vulnerability</title>
  <description>Cisco Lightweight Access Point Over-the-Air Provisioning Manipulation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-218.shtml</link>
  <pubDate>26 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-217: Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability</title>
  <description>Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-217.shtml</link>
  <pubDate>25 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-216: Multiple Vulnerabilities With Adobe Flash Player, Adobe Reader and Acrobat</title>
  <description>Multiple Vulnerabilities With Adobe Flash Player, Adobe Reader and Acrobat</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-216.shtml</link>
  <pubDate>24 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-215: Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability</title>
  <description>Libpurple msn_slplink_process_msg() Arbitrary Write Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-215.shtml</link>
  <pubDate>21 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-214: Solaris Kernel Filesystem and Virtual Memory Subsystems Vulnerability</title>
  <description>Solaris Kernel Filesystem and Virtual Memory Subsystems Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-214.shtml</link>
  <pubDate>20 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-213: Cisco IOS XR Software Border Gateway Protocol Vulnerability</title>
  <description>Cisco IOS XR Software Border Gateway Protocol Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-213.shtml</link>
  <pubDate>19 Aug 2009 14:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-212: Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability</title>
  <description>Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-212.shtml</link>
  <pubDate>18 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-211: Memcached Multiple Heap Based Buffer Overflow Vulnerability</title>
  <description>Memcached Multiple Heap Based Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-211.shtml</link>
  <pubDate>17 Aug 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-210: Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities</title>
  <description>Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-210.shtml</link>
  <pubDate>14 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-209: NTP 'ntpq' Stack Buffer Overflow Vulnerability</title>
  <description>NTP 'ntpq' Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-209.shtml</link>
  <pubDate>13 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-208: Apple Safari Code Execution and Security Bypass Vulnerabilities</title>
  <description>Apple has released Safari 4.0.3 for Windows and Mac OS X to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or spoof a website.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-208.shtml</link>
  <pubDate>12 Aug 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-207: Microsoft Patch Tuesday Reminder</title>
<description></description>
<link>http://circ.jc3.doe.gov/bulletins/t-207.shtml</link>
<pubDate>12 Aug 2009 00:00 GMT</pubDate>
<category>New Bulletin </category>
</item>
<item>
  <title>T-206: Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability</title>
  <description>Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-206.shtml</link>
  <pubDate>10 Aug 2009 15:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-205: Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-205.shtml</link>
  <pubDate>7 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-204: Apple Mac OS X 2009-003 Multiple Security Vulnerabilities</title>
  <description>Apple Mac OS X 2009-003 Multiple Security Vulnerabilities.  Apple Mac OS X Code Execution and Security Bypass Vulnerabilities.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-204.shtml</link>
  <pubDate>06 August 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-203: Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability</title>
  <description>Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability.  Sun Java Runtime Environment (JRE) is prone to a privilege-escalation vulnerability.  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-203.shtml</link>
  <pubDate>05 August 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-202: Mozilla Firefox Error Page Address Bar URL Spoofing Vulnerability</title>
  <description>Mozilla Firefox Error Page Address Bar URL Spoofing Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-202.shtml</link>
  <pubDate>4 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-201: Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability</title>
  <description>Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-201.shtml</link>
  <pubDate>3 Aug 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-200: Absolute Software Computrace LoJack for Laptops Security Bypass Vulnerability</title>
  <description>Absolute Software Computrace LoJack for Laptops Security Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-200.shtml</link>
  <pubDate>31 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-199: Mozilla Firefox NULL Character CA SSL Certificate Validation Security Bypass Vulnerability</title>
  <description>Mozilla Firefox NULL Character CA SSL Certificate Validation Security Bypass Vulnerability.  Mozilla Firefox before 3.5 and NSS before 3.12.3 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-199.shtml</link>
  <pubDate>31 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-198: Squid Multiple Remote Denial of Service Vulnerabilities</title>
  <description>Squid Multiple Remote Denial of Service Vulnerabilities.  Squid proxy server contains multiple remote denial of service vulnerabilities.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-198.shtml</link>
  <pubDate>30 July 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-197: ISC BIND Denial of Service Vulnerability</title>
  <description>ISC BIND Denial of Service Vulnerability.  ISC BIND has a vulnerability that could allow remote unauthenticated users to cause a denial of service.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-197.shtml</link>
  <pubDate>29 July 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-196: Critical Cumulative Security Update for Internet Explorer</title>
  <description>Critical Cumulative Security Update for Internet Explorer</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-196.shtml</link>
  <pubDate>29 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-195: Remote Jail Breakout Vulnerability via Symlink Traversal in NcFTPd</title>
  <description>Remote Jail Breakout Vulnerability via Symlink Traversal in NcFTPd</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-195.shtml</link>
  <pubDate>28 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-194: Multiple Vulnerabilities in Cisco Wireless LAN Controllers</title>
  <description>Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

For Public Release 2009 July 27 1600 UTC (GMT)

- ---------------------------------------------------------------------

Summary

Multiple vulnerabilities exist in the Cisco Wireless LAN Controller
(WLC) platforms. This security advisory outlines the details of the following vulnerabilities:

  * Malformed HTTP or HTTPS authentication response denial of service
    vulnerability
  * SSH connections denial of service vulnerability
  * Crafted HTTP or HTTPS request denial of service vulnerability
  * Crafted HTTP or HTTPS request unauthorized configuration
    modification vulnerability

Cisco has released free software updates that address these vulnerabilities.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-194.shtml</link>
  <pubDate>27 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-193: Sun Solaris Auditing Extended File Attributes (fsattr(5)) Local Denial Of Service Vulnerability</title>
  <description>Sun Solaris Auditing Extended File Attributes (fsattr(5)) Local Denial Of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-193.shtml</link>
  <pubDate>24 Jul 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-192: Microsoft Office Web Components ActiveX Control 'msDataSourceObject' is vulnerable to Code Execution</title>
  <description>Microsoft Office Web Components ActiveX Control 'msDataSourceObject' is vulnerable to Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-192.shtml</link>
  <pubDate>24 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-191: Vulnerability in Adobe Acrobat, Reader, and Flash Player</title>
  <description>Vulnerability in Adobe Acrobat, Reader, and Flash Player</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-191.shtml</link>
  <pubDate>23 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-190: Buffer Overflow in NASA Common Data Format (CDF) Library</title>
  <description>Buffer Overflow in NASA Common Data Format (CDF) Library</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-190.shtml</link>
  <pubDate>22 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-189: Directory Traversal Vulnerability in the Administration Interface in Cisco Customer Response Solutions</title>
  <description>Directory Traversal Vulnerability in the Administration Interface in Cisco Customer Response Solutions</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-189.shtml</link>
  <pubDate>21 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-188: Linked XSS Vulnerability found in Oracle BEA Weblogic Server</title>
  <description>Linked XSS Vulnerability found in Oracle BEA Weblogic Server</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-188.shtml</link>
  <pubDate>20 Jul 2009 20:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-187: Security Vulnerability in Solaris NFSv4 Kernel Module May Panic an NFSv4 Client System </title>
  <description>Security Vulnerability in Solaris NFSv4 Kernel Module May Panic an NFSv4 Client System</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-187.shtml</link>
  <pubDate>17 Jul 2009 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-186: Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-186.shtml</link>
  <pubDate>17 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-185: Two Remote Code Execution Vulnerabilities in Firefox</title>
  <description>Two Remote Code Execution Vulnerabilities in Firefox.  Firefox has vulnerabilities in the Unicode Data and Tracemonkey components. Successful exploit of either could result in the attacker running code in the context of the logged in user.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-185.shtml</link>
  <pubDate>16 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-184: Microsoft Monthly Updates</title>
  <description>Microsoft Monthly Updates.  Microsoft has released updates that address vulnerabilities in, Microsoft Windows, Windows Server, DirectShow, Virtual PC and Server, Office Publisher, and ISA Server.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-184.shtml</link>
  <pubDate>15 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-183: Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution </title>
  <description>Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-183.shtml</link>
  <pubDate>14 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-182: Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability</title>
  <description>Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulnerability.  Nagios is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-182.shtml</link>
  <pubDate>13 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-181: Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Vulnerability</title>
  <description>Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-181.shtml</link>
  <pubDate>10 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-180: Citrix XenCenterWeb Multiple Input Validation Vulnerabilities</title>
  <description>Citrix XenCenterWeb Multiple Input Validation Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-180.shtml</link>
  <pubDate>09 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-179: Ubuntu Linux TIFF Image Library Vulnerability</title>
  <description>Ubuntu Linux TIFF Image Library Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-179.shtml</link>
  <pubDate>8 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-178: Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote Memory Corruption Vulnerability</title>
  <description>Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote Memory Corruption Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-178.shtml</link>
  <pubDate>7 Jul 2009 13:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-177: FCKeditor input sanitization errors</title>
  <description>FCKeditor input sanitization errors</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-177.shtml</link>
  <pubDate>6 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-176: Sun Kernel udp(7p) Denial of Service Vulnerability</title>
  <description>Sun Kernel udp(7p) Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-176.shtml</link>
  <pubDate>6 Jul 2009 12:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-175: Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability</title>
  <description>Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-175.shtml</link>
  <pubDate>02 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-174: MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability</title>
  <description>MIT Kerberos fails to handle an error condition which allows for memory corruption.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-174.shtml</link>
  <pubDate>01 July 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-173: phpMyAdmin 'db' Parameter Cross Site Scripting Vulnerability</title>
  <description>phpMyAdmin 'db' Parameter Cross Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-173.shtml</link>
  <pubDate>30 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-172: Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability</title>
  <description>Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerability.  The Linux kernel is vulnerable to a denial of service attack.  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-172.shtml</link>
  <pubDate>29 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-171: Samba Format String And Security Bypass Vulnerabilities</title>
  <description>Samba Format String And Security Bypass Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-171.shtml</link>
  <pubDate>26 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-170: Cisco Physical Access Gateway Malformed Packet Remote Denial of Service Vulnerability</title>
  <description>Cisco Physical Access Gateway Malformed Packet Remote Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-170.shtml</link>
  <pubDate>25 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-169: Adobe Shockwave Player Unspecified Security Vulnerability</title>
  <description>Adobe Shockwave Player Unspecified Security Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-169.shtml</link>
  <pubDate>24 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-168: IrfanView 'TIFF' File Handling Remote Integer Overflow Vulnerability</title>
  <description>IrfanView 'TIFF' File Handling Remote Integer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-168.shtml</link>
  <pubDate>23 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-167: OpenSSL Multiple Vulnerabilities</title>
  <description>OpenSSL Multiple Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-167.shtml</link>
  <pubDate>22 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-166: FreeBSD Direct Pipe Writes Information Disclosure Vulnerability</title>
  <description>FreeBSD Direct Pipe Writes Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-166.shtml</link>
  <pubDate>19 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-165: Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability.  Microsoft Active Directory Encoded LDAP String Memory Corruption Remote Code Execution Vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-165.shtml</link>
  <pubDate>18 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-164: Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability</title>
  <description>Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability.  Apple Java CColourUIResource Pointer Dereference Code Execution Vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-164.shtml</link>
  <pubDate>18 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-163: Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability</title>
  <description>Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability.  Linux Kernel is vulnerable to security bypass via "NFS MAY_EXEC".</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-163.shtml</link>
  <pubDate>17 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-162: Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities</title>
  <description>Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities.  Drupal Views Module lets attackers bypass security and inject HTML and scripts into pages.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-162.shtml</link>
  <pubDate>16 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-161: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabilities.  The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-161.shtml</link>
  <pubDate>15 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-160: Microsoft Windows Print Spooler 'EnumeratePrintShares()' Remote Stack Buffer Overflow Vulnerability</title>
  <description>Microsoft Windows Print Spooler 'EnumeratePrintShares()' Remote Stack Buffer Overflow Vulnerability.  Remote exploitation of a stack buffer overflow vulnerability in Windows 2000 print spooler.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-160.shtml</link>
  <pubDate>12 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-159: Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities</title>
  <description>Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities.  Adobe Reader and Acrobat are prone to multiple remote vulnerabilities.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-159.shtml</link>
  <pubDate>11 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-158: HP OpenView Network Node Manager SNMP and MIB Unspecified Remote Code Execution Vulnerability</title>
  <description>HP OpenView Network Node Manager SNMP and MIB Unspecified Remote Code Execution Vulnerability.  HP OpenView Network Node Manager (NNM) is prone to a remote code-execution vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-158.shtml</link>
  <pubDate>10 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-157: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities</title>
  <description>Apple Safari Prior to 4.0 Multiple Security Vulnerabilities</description>   
  <link>http://circ.jc3.doe.gov/bulletins/t-157.shtml</link>
  <pubDate>09 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-156: GNOME Evolution S/MIME Email Signature Verification Vulnerability</title>
  <description>GNOME Evolution S/MIME Email Signature Verification Vulnerability.  GNOME Evolution contains a vulnerability that allows an attacker to change a signed S/MIME message without detection.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-156.shtml</link>
  <pubDate>08 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-155: OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerability.  OpenSSL is prone to a denial-of-service vulnerability caused by a NULL-pointer dereference condition. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-155.shtml</link>
  <pubDate>05 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-154: Sun Solaris Kerberos Credential Management Security Bypass Vulnerability</title>
  <description>Sun Solaris Kerberos Credential Management Security Bypass Vulnerability.  Solaris Kerberos is prone to a security-bypass vulnerability that affects the Kerberos credential cache management.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-154.shtml</link>
  <pubDate>05 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-153: Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness</title>
  <description>Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-153.shtml</link>
  <pubDate>04 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-152: Apple QuickTime JP2 Image Handling Heap Buffer Overflow Vulnerability</title>
  <description>Apple QuickTime JP2 Image Handling Heap Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-152.shtml</link>
  <pubDate>04 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-151: Microsoft Windows Desktop Wall Paper System Parameter Local Denial Of Service Vulnerability</title>
  <description>Microsoft Windows Desktop Wall Paper System Parameter Local Denial Of Service Vulnerability.  Microsoft Windows Desktop Wall Paper System contains a local denial of service vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-151.shtml</link>
  <pubDate>03 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-150: VMware Hosted products and ESX and ESXi  security issues</title>
  <description>VMware Hosted products and ESX and ESXi  security issues</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-150.shtml</link>
  <pubDate>02 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-149: Apache 'Options' and 'AllowOverride' Security Directives Vulnerability</title>
  <description>Apache 'Options' and 'AllowOverride' Security Directives Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-149.shtml</link>
  <pubDate>01 June 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-148: Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vulnerability</title>
  <description>Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-148.shtml</link>
  <pubDate>29 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-147: OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</title>
  <description>OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-147.shtml</link>
  <pubDate>29 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-146: BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities</title>
  <description>BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities.  BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-146.shtml</link>
  <pubDate>28 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-145: Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability</title>
  <description>Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-145.shtml</link>
  <pubDate>28 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-144: FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability</title>
  <description>FreeBSD 'telnetd' Daemon Remote Code Execution Vulnerability.  FreeBSD 'telnetd' Daemon allows remote code execution.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-144.shtml</link>
  <pubDate>27 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-143: Pidgin Multiple Buffer Overflow Vulnerabilities</title>
  <description>Pidgin Multiple Buffer Overflow Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-143.shtml</link>
  <pubDate>26 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-142: Basic Analysis and Security Engine Cross-Site Scripting Vulnerability</title>
  <description>Basic Analysis and Security Engine Cross-Site Scripting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-142.shtml</link>
  <pubDate>26 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-141: Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities</title>
  <description>Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities Multiple vulnerabilities have been identified in Novell GroupWise, which could be exploited by remote attackers to bypass security restrictions, conduct phishing attacks, cause a denial of service or compromise a vulnerable system. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-141</link>
  <pubDate>22 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-140: CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability</title>
  <description>CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-140.shtml</link>
  <pubDate>21 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-139: Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-139.shtml</link>
  <pubDate>20 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-138: NTP 'ntpd' Autokey and ntpq Stack Buffer Overflow Vulnerability</title>
  <description>NTP 'ntpd' Autokey and ntpq Stack Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-138.shtml</link>
  <pubDate>19 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-137: Microsoft IIS 6.0 WebDAV Remote Authentication Bypass</title>
  <description>Microsoft IIS 6.0 WebDAV Remote Authentication Bypass</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-137.shtml</link>
  <pubDate>18 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-136: Apple Mac OS X PICT Image Handling Integer Overflow Vulnerability</title>
  <description>Apple Mac OS X PICT Image Handling Integer Overflow Vulnerability.  Apple Mac OS X is prone to an integer-overflow vulnerability when handling PICT image files. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-136.shtml</link>
  <pubDate>15 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-135: Apple Mac OS X Help Viewer HTML Document Remote Code Execution Vulnerability</title>
  <description>Apple Mac OS X Help Viewer HTML Document Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-135.shtml</link>
  <pubDate>14 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-134: Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability</title>
  <description>Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-134.shtml</link>
  <pubDate>13 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-133: Little CMS Monochrome Profiles Null Pointer Dereference Denial of Service Vulnerability</title>
  <description>Little CMS Monochrome Profiles Null Pointer Dereference Denial of Service Vulnerability.  Little CMS is prone to a remote denial-of-service vulnerability.  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-133.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-132: Multiple Trend Micro Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple Trend Micro Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple Trend Micro products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-132.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-131: Multiple AVG Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple AVG Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple AVG products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-131.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-130: F-PROT Products CAB File Scan Evasion Vulnerability</title>
  <description>F-PROT Products CAB File Scan Evasion Vulnerability.  Multiple F-Prot products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-130.shtml</link>
  <pubDate>12 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-129: HP OpenView Network Node Manager 'ovalarmsrv.exe' Remote Code Execution Vulnerability</title>
  <description>HP OpenView Network Node Manager 'ovalarmsrv.exe' Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-129.shtml</link>
  <pubDate>8 May 2009</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-128: Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability</title>
  <description>Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-128.shtml</link>
  <pubDate>08 May 2009</pubDate>
  <category>New Bulletin </category>
</item>

<item>
  <title>T-127: Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description>Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerability.  Multiple F-Secure products are prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-127.shtml</link>
  <pubDate>07 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-126: Insight Control Suite For Linux (ICE-LX) Multiple Remote Vulnerabilities In Nagios</title>
  <description>Release Date: 2009-05-05
Last Updated: 2009-05-05

Potential Security Impact: Multiple remote vulnerabilities in Nagios

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with Insight Control suite for Linux (ICE-LX) running Nagios.
The vulnerabilities could be remotely exploited via cross-site request forgery (CSRF) and remote authentication bypass.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-126.shtml</link>
  <pubDate>06 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-125: The Linux kernel is prone to a local privilege-escalation vulnerability via ptrace_attach().</title>
  <description>The Linux kernel is prone to a local privilege-escalation vulnerability via ptrace_attach(). Currently we are not aware of any working exploits. A fix is available in the GIT repository. http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d84f4f992cbd76e8f39c488cf0c5d123843923b1
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-125.shtml</link>
  <pubDate>05 May 2009</pubDate>
  <category></category>
</item>
<item>
  <title>T-124: Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-124.shtml</link>
  <pubDate>04 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-123: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities</title>
  <description>A remote attacker can exploit a buffer overflow to gain apache privileges, or cause a denial of service.
CA ARCserve Backup on Solaris, Tru64, HP-UX, and AIX contains multiple vulnerabilities in the Apache HTTP Server version
as shipped with ARCserve Backup. CA has issued updates that contain version 2.0.63 of the Apache HTTP Server to address
the vulnerabilities. Refer to the References section for a list of resolved issues by CVE identifier.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-123.shtml</link>
  <pubDate>01 May 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-122: McAfee Products RAR/ZIP Files Scan Evasion Vulnerability</title>
  <description></description>
  <link>http://circ.jc3.doe.gov/bulletins/t-122.shtml</link>
  <pubDate>30 Apr 09</pubDate>
  <category></category>
</item>
<item>
  <title>T-121: Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability</title>
  <description>This is a root compromise, privilege escalation exploit. A local attacker can exploit this issue to execute arbitrary code with superuser privileges. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-121.shtml</link>
  <pubDate>29 April 2009</pubDate>
  <category>New Bulletin</category>
</item>
<item>
  <title>T-120: Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability</title>
  <description>Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-120.shtml</link>
  <pubDate>28 APR 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-119: Symantec Brightmail Gateway Appliance Cross-site Scripting and Elevation of Privilege</title>
  <description>Symantec Brightmail Gateway Appliance Cross-site Scripting and Elevation of Privilege.  Symantec Brightmail Gateway is prone to a remote privilege-escalation vulnerability.  Remote authorized attackers who have access to the targeted host's local network can exploit this issue to gain elevated access. Successful exploits may compromise the affected computer and may aid in other attacks.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-119.shtml</link>
  <pubDate>28 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-118: GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities</title>
  <description>GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities.  The GNOME glib library is
prone to multiple integer-overflow vulnerabilities related to encoding and decoding Base64 data.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-118.shtml</link>
  <pubDate>27 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-117: Sun Java System Delegated Administrator HTTP Response Splitting Vulnerability</title>
  <description>Sun Java System Delegated Administrator HTTP Response Splitting Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-117.shtml</link>
  <pubDate>24 APR 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-116: Symantec Ghost EasySetup Wizard Lets Remote Users Deny Service </title>
  <description>Symantec Norton Ghost 'EasySetupInt.dll' ActiveX Multiple Remote Denial of Service Vulnerabilities. This vulnerability can cause Denial of service via network. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-xxx.shtml</link>
  <pubDate>24 Apr 09</pubDate>
  <category></category>
</item>
<item>
  <title>T-115: Multiple Vulnerabilities in Firefox, Thunderbird and Seamonkey</title>
  <description>Multiple vulnerabilities in Firefox, Thunderbird and Seamonkey: Multiple newly disclosed vulnerabilities in Firefox, Thunderbird and Seamonkey could result in disclosure of information, crashing the application or the running of inserted javascript. One vulnerability results in memory corruption and could conceivably be used to run arbitrary code.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-115.shtml</link>
  <pubDate>23 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-114: Xpdf JBIG2 Processing Multiple Security Vulnerabilities</title>
  <description>Xpdf JBIG2 Processing Multiple Security Vulnerabilities. Failed exploit attempts will likely cause denial-of-service conditions. Currently we are not aware of any working exploits. Updates are available. Please see the references for more information.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-114.shtml</link>
  <pubDate>22 April 2009</pubDate>
  <category></category>
</item>
<item>
  <title>T-113: udev Netlink Message Validation Local Privilege Escalation Vulnerability</title>
  <description>udev Netlink Message Validation Local Privilege Escalation Vulnerability.  udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-113.shtml</link>
  <pubDate>21 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-112: CUPS Integer Overflow in Processing TIFF Images Lets Remote Users Execute Arbitrary Code </title>
  <description>CUPS Integer Overflow in Processing TIFF Images Lets Remote Users Execute Arbitrary Code </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-112.shtml</link>   
  <pubDate>17 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-111: Oracle April 2009 Critical Patch Update</title>
  <description>Oracle April 2009 Critical Patch Update Multiple Vulnerabilities. Oracle has released the April 2009 critical patch update that addresses 43 vulnerabilities.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-111.shtml</link>
  <pubDate>16 Apr 2009 16:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-110: OpenBSD PF Remote Denial of Service Vulnerability</title>
  <description>OpenBSD PF Remote Denial Of Service Vulnerability Exploiting this issue allows remote attackers to cause a kernel panic on affected computers, denying further service to legitimate users.
OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
OpenBSD OpenBSD 4.4
   OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
OpenBSD OpenBSD 4.5
    OpenBSD 002_pf.patch
      ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-110.shtml</link>
  <pubDate>16 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-109: Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)</title>
  <description>Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)
This security update resolves a publicly disclosed vulnerability in the Windows SearchPath function that could allow elevation of privilege if a user downloaded a specially crafted file to a specific location, then opened an application that could load the file under certain circumstances.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-109.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-108: Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause De</title>
  <description>Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (961759)
This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE).</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-108.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-107: Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)</title>
  <description>Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)
This security update resolves four publicly disclosed vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker is allowed to log on to the system and then run a specially crafted application.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-107.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-106: Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)</title>
  <description>Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)
This security update resolves a privately reported and a publicly disclosed vulnerability.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-106.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-105: Critical Cumulative Security Update for Internet Explorer (963027)</title>
  <description>Cumulative Security Update for Internet Explorer (963027)
This security update resolves four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-105.shtml</link>
  <pubDate>15 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-104: Vulnerabilities in Windows HTTP services could allow remote code execution</title>
  <description>Vulnerabilities in Windows HTTP services could allow remote code execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-104.shtml</link>
  <pubDate>15 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-103: Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution</title>
  <description>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution. This security update resolves a privately reported vulnerability in Microsoft DirectX. The vulnerability could allow remote code execution if user opened a specially crafted MJPEG file. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-103.shtml</link>
  <pubDate>15 Apr 09</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-102: Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution</title>
  <description>Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-102.shtml</link>
  <pubDate>15 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-101: Vmware Flaw in Multiple Products Allows Compromise of Host System</title>
  <description>Vmware Flaw in Multiple Products Allows Compromise of Host System.  A local user can exploit a flaw in the virtual machine display function to execute arbitrary code on the target host system.  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-101.shtml</link>
  <pubDate>14 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-100: Tor Security Bypass And Privilege Escalation Weaknesses</title>
  <description>Tor Security Bypass And Privilege Escalation Weaknesses.  Tor is prone to multiple weaknesses that may allow attackers to exploit other vulnerabilities that facilitate privilege-escalation and security-bypass attacks.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-100.shtml</link>
  <pubDate>13 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-099: Linux Kernel CIFS Remote Buffer Overflow Vulnerability</title>
  <description>Linux Kernel CIFS Remote Buffer Overflow Vulnerability.  An attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-099.shtml</link>
  <pubDate>10 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-098: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</title>
  <description>Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances.  Cisco has announced multiple vulnerabilities in its ASA Adaptive Security Appliance and PIX Security Appliance. Most result in DoS, to allow an attacker to bypass VPN authentication or bypass ACL rules.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-098.shtml</link>
  <pubDate>09 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-097: Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability
ZDI-09-016</title>
  <description>Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability ZDI-09-016: April 6th, 2009 CVE ID. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. A valid IPC$ connection must be established in order to exploit this vulnerability.
  </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-097.shtml</link>
  <pubDate>06 April 2009</pubDate>
  <category>New Bulletin </category>
</item> 
<item>
  <title>T-096: Clam AV 0.94 and below Rar Evasion Vulnerability</title>
  <description>Clam AV 0.94 and below Rar Evasion Vulnerability.  ClamAV AntiVirus is prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-096.shtml</link>
  <pubDate>07 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-095: Microsoft Office PowerPoint code execution vulnerability</title>
  <description>Microsoft Office PowerPoint code execution vulnerability.  Unspecified vulnerability in MS Powerpoint could allow a remote attacker to execute arbitrary code on the system.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-095.shtml</link>
  <pubDate>06 April 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-094: Wireshark PN-DCP Data Format String Vulnerability</title>
  <description>Wireshark could allow a remote attacker to execute arbitrary code on the system, caused by a format string vulnerability in the PN-DCP dissector.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-094.shtml</link>
  <pubDate>02 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-093: Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</title>
  <description>Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities.  Security Vulnerabilities in the Java Runtime Environment (JRE) LDAP Implementation may Allow a Denial of Service (DoS) and Malicious Code to be Executed Vulnerability affects LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-093.shtml</link>
  <pubDate>01 Apr 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-092: Mozilla Firefox '_moveToEdgeShift' Remote Code Execution Vulnerability</title>
  <description>Mozilla Firefox '_moveToEdgeShift' Remote Code Execution Vulnerability.  This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-092.shtml</link>
  <pubDate>31 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-091: Conficker Worm Targets Microsoft Windows Systems</title>
  <description>Conficker Worm Targets Microsoft Windows Systems.  Public reports indicate a widespread infection of the Conficker worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across a network if the host is not patched with MS08-067.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-091.shtml</link>
  <pubDate>30 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-090: Squid Web Proxy Cache HTTP Version Number Parsing Denial of Service Vulnerability</title>
  <description>Squid Web Proxy Cache HTTP Version Number Parsing Denial of Service Vulnerability.  
Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to handle certain HTTP requests.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-090.shtml</link>
  <pubDate>27 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-089: pam-krb5 Local Privilege Escalation Vulnerability</title>
  <description>pam-krb5 Local Privilege Escalation Vulnerability.  pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-089.shtml</link>
  <pubDate>26 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-088: HP-UX VERITAS File System and VERITAS Oracle Disk Manager Local Privilege Escalation Vulnerability</title>
  <description>HP-UX VERITAS File System and VERITAS Oracle Disk Manager Local Privilege Escalation Vulnerability
HP-UX is prone to a local privilege-escalation vulnerability affecting VERITAS File System (VRTSvxfs) and VERITAS Oracle Disk Manager (VRTSodm).</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-088.shtml</link>
  <pubDate>25 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-087: Sun Solaris NFS Daemon (nfsd(1M)) Security Bypass Vulnerability</title>
  <description></description>
  <link>http://circ.jc3.doe.gov/bulletins/t-087.shtml</link>
  <pubDate>24 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-086: Linux Kernel 'readlink' Local Privilege Escalation Vulnerability</title>
  <description>Linux Kernel 'readlink' Local Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-086.shtml</link>
  <pubDate>23 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-085: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-085.shtml</link>
  <pubDate>20 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-084: Tasklist Drupal Module Unspecified SQL Injection Vulnerability</title>
  <description>Tasklist Drupal Module Unspecified SQL Injection Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-084.shtml</link>
  <pubDate>19 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-083: Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</title>
  <description>Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-083.shtml</link>
  <pubDate>18 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-082: Opera Web Browser HTML Parsing Heap-Based Remote Code Execution Vulnerability</title>
  <description>Opera Web Browser HTML Parsing Heap-Based Remote Code Execution Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-082.shtml</link>
  <pubDate>17 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-081: Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerabilities</title>
  <description>The 'libpng' library is prone to multiple memory-corruption vulnerabilities because it fails to properly initialize data structures.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-081.shtml</link>
  <pubDate>16 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-080: Hewlett-Packard WMI Mapper for HP Systems Insight Manager Unauthorized Access Vulnerabilities</title>
  <description>Hewlett-Packard WMI Mapper for HP Systems Insight Manager Unauthorized Access Vulnerabilities</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-080.shtml</link>
  <pubDate>13 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-079: Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</title>
  <description>Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-079.shtml</link>
  <pubDate>12 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-078: Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vulnerability</title>
  <description>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-078.shtml</link>
  <pubDate>11 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-077: IBM Tivoli Storage Manager HSM Buffer Overflow Vulnerability</title>
  <description>A security vulnerability exists in the IBM Tivoli Storage Manager (TSM) HSM for Windows client.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-077.shtml</link>
  <pubDate>10 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-076: OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability</title>
  <description>OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-076.shtml</link>
  <pubDate>09 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-075: VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities</title>
  <description>VMware Server and Workstation are prone to an unauthorized-access vulnerability and multiple privilege-escalation and denial-of-service vulnerabilitie</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-075.shtml</link>
  <pubDate>06 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-074: XML Data Theft Via RDFXML DataSource and Cross-Domain Redirect</title>
  <description>XML Data Theft Via RDFXML DataSource and Cross-Domain Redirect</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-074.shtml</link>
  <pubDate>05 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-073: New proftpd-dfsg packages fix SQL injection vulnerabilites </title>
  <description>Two SQL injection vulnerabilities have been found in proftpd, a virtual-hosting FTP daemon.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-073.shtml</link>
  <pubDate>04 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-072: Adobe Flash Player Invalid Object Reference Bug Lets Remote Users Execute Arbitrary Code </title>
  <description>Adobe Flash Player Invalid Object Reference Bug Lets Remote Users Execute Arbitrary Code</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-072.shtml</link>
  <pubDate>03 March 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-071: Novell eDirectory Management Console Accept-Language Buffer Overflow</title>
  <description>A remotely exploitable vulnerability has been discovered in the iMonitor component of Novell eDirectory.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-071.shtml</link>
  <pubDate>02 Mar 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-070: Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</title>
  <description>Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-070.shtml</link>
  <pubDate>27 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-069: HP OpenView Network Node Manager Vulnerable to Denial of Service</title>
  <description>Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM).</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-069.shtml</link>
  <pubDate>26 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-068: Microsoft Windows AutoRun and AutoPlay Vulnerability</title>
  <description>Microsoft Windows includes an AutoRun feature, which can automatically run code when removable devices are connected to the computer.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-068.shtml</link>
  <pubDate>25 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-067: Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution</title>
  <description>Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-067.shtml</link>
  <pubDate>24 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-066: Multiple HTTP Proxy HTTP Host Header Incorrect Relay Behavior Vulnerability</title>
  <description>Multiple HTTP Proxy HTTP Host Header Incorrect Relay Behavior Vulnerability</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-066.shtml</link>
  <pubDate>23 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-065: Adobe Acrobat and Reader PDF File Handling Remote Code Execution Vulnerability</title>
  <description>Adobe Acrobat and Reader are prone to a remote code-execution vulnerability.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-065.shtml</link>
  <pubDate>20 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-064: BlackBerry Application Web Loader ActiveX Control Remote Buffer Overflow Vulnerability</title>
  <description>RIM BlackBerry Application Web Loader is prone to multiple stack-based buffer overflows.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-064.shtml</link>
  <pubDate>19 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-063: Apple Mac OS X SMB Component Unspecified Buffer Overflow Vulnerability</title>
  <description>Apple Mac OS X is prone to a buffer-overflow vulnerability that occurs in the SMB component.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-063.shtml</link>
  <pubDate>18 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-062: Unspecified Vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6</title>
  <description>Unspecified vulnerablility in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-062.shtml</link>
  <pubDate>17 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-061: pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Escalation Vulnerability</title>
  <description>pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Escalation Vulnerability. pam-krb5 is prone to a local privilege-escalation vulnerability because of a failure to properly handle setuid processes.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-061.shtml</link>
  <pubDate>13 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-060: Cumulative Security Update for Internet Explorer 7</title>
  <description>Cumulative Security Update for Internet Explorer 7. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-060.shtml</link>
  <pubDate>12 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-059: Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution </title>
  <description>Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution 
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-059.shtml</link>
  <pubDate>11 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-058: RealPlayer IVR File Processing Two Vulnerabilities</title>
  <description>Some vulnerabilities have been reported in RealPlayer, which can be exploited by malicious people to compromise a vulnerable system.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-058.shtml</link>
  <pubDate>10 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-057: Certain HP LaserJet Printers, HP Color LaserJet Printers, and HP Digital Senders, Remote Unauthorized Access to Files</title>
  <description> A potential security vulnerability has been identified with certain HP LaserJet printers, HP Color LaserJet printers and HP Digital Senders. The vulnerability could be exploited remotely to gain unauthorized access to files. </description>
  <link>http://circ.jc3.doe.gov/bulletins/t-057</link>
  <pubDate>09 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-056: RealNetworks RealPlayer IVR File Parsing Multiple Vulnerabilities</title>
  <description>RealNetworks RealPlayer IVR File Parsing Multiple Vulnerabilities.  RealPlayer 11 is affected; other versions may also be vulnerable.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-056</link>
  <pubDate>06 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-055: Cisco IOS HTTP Server Multiple Cross Site Scripting Vulnerabilities</title>
  <description>Cisco IOS HTTP Server is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-055.shtml</link>
  <pubDate>05 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-054: Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities Bypass Same-Origin Restrictions</title>
  <description>Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities bypass same-origin restrictions.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-054.shtml</link>
  <pubDate>04 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-053: Buffer Overflows in RealNetworks Helix Server and Helix Mobile Server Allow Remote Attackers to Cause a Denial of Servic</title>
  <description>Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server allows unauthorized disclosure of information, unauthorized modification, or a disruption of service.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-053.shtml</link>
  <pubDate>03 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-052:  Sun Solaris BIND "EVP_VerifyFinal()" and "DSA_do_verify()" Spoofing Vulnerability</title>
  <description>A vulnerability in Sun Solaris could be exploited by attackers to conduct spoofing attacks.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-052.shtml.shtml</link>
  <pubDate>02 Feb 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-051: Sun Java System Access Manager User Enumeration Weakness</title>  <description>A weakness in Sun Java System Access Manager can be exploited by
remote unprivileged users to identify valid user accounts.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-051.shtml</link>
  <pubDate>30 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-050: Sun Solaris Pseudo-terminal Driver Local Denial of Service Vulnerability</title>
  <description>A vulnerability in Sun Solaris could cause a denial of service.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-050.shtml</link>
  <pubDate>29 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-049: Sun Solaris IPv6 Packet Processing Denial of Service Vulnerability</title>
  <description>A vulnerability in Sun Solaris could be exploited by a remote attacker to cause a denial of service condition.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-049.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-048: Computer Assosciates Anti-Virus Engine 'arclib.dll' Multiple Scan Evasion Vulnerabilities</title>
  <description>Vulnerabilities in various CA products could allow a remote attacker to evade detection by the Anti-Virus engine by creating a malformed archive file.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-048.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-047: Sun Solaris "libike" Library Denial of Service</title>
  <description>A vulnerability in Sun Solaris could be exploited by a remote attacker to cause a Denial of Service.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-047.shtml</link>
  <pubDate>28 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-046: Cisco Unified Communications Manager CAPF Denial of Service Vulnerability</title>
  <description>Cisco Unified Communications Manager, formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Certificate Authority Proxy Function (CAPF) service.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-046.shtml</link>
  <pubDate>27 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-045: CYV4: Linux Kernel dell_rbu Denial of Service Security Issues</title>
  <description>Linux Kernel dell_rbu Denial of Service Security Issues

Summary:    Two security issues in the Linux Kernel could be exploited by malicious, local users to
cause a DoS (Denial of Service). Versions 2.6.27.13 and 2.6.28.2 are available to address these issues.
</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-045</link>
  <pubDate>26 Jan 2009 4:45 PM
</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-044: Apple QuickTime MPEG-2 Playback Component For Windows Input Validation Vulnerability</title>
  <description>Apple has published an advisory for an input validation error in the Quicktime MPEG-2 Playback Component for Windows.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-044.shtml</link>
  <pubDate>23 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-043: Apple QuickTime Memory Corruption and Buffer Overflow Vulnerabilities</title>
  <description>Multiple vulnerabilities in Apple QuickTime 7.5 and prior could allow remote attackers to cause a Denial of Service</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-043.shtml</link>
  <pubDate>22 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
	<title>T-042: Linux Kernel "keyctl_join_session_keyring()" Denial of Service</title>
	<description>A local denial of service vulnerability has been discovered in the Linux kernel</description>
  	<link>http://circ.jc3.doe.gov/bulletins/t-042.shtml</link>
  	<pubDate>21 Jan 2009</pubDate>
  	<category>New Bulletin </category>	
</item>
<item>
  <title>T-041: Symantec AppStream Client LaunchObj ActiveX Control Insecure Methods</title>
  <description>A vulnerability in Symantec AppStream Client could allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-041.shtml</link>
  <pubDate>20 Jan 2009</pubDate>
  <category>New Bulletin </category>

</item>
<item>
  <title>T-040: Sun SPARC Enterprise Server Authentication Bypass Vulnerability</title>
  <description>A vulnerability in certain Sun SPARC Enterprise servers could allow a remote attacker to gain root access on the target system.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-040.shtml</link>
  <pubDate>20 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-039: Sun Java System Access Manager Privilege Vulnerability And Password Security Issue</title>
  <description>A vulnerability and security issue in Sun Java System Access Manager could be exploited by an attacker to gain escalated privileges, or disclose sensitive information.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-039.shtml</link>
  <pubDate>16 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-038: Cisco ONS Platform Crafted Packet Vulnerability</title>
  <description>Certain Cisco Platforms contain a vulnerability when processing TCP traffic streams that may result in a reload of the device control card.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-038.shtml</link>
  <pubDate>15 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-037: Oracle Has Released The January 2009 Critical Patch Update.</title>
  <description>Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-037.shtml</link>
  <pubDate>14 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-036: Vulnerabilities in SMB Could Allow Remote Code Execution (MS09-001) - Critical</title>
  <description>This security update resolves two privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-036.shtml</link>
  <pubDate>13 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-035: Microsoft RPC Worm Spreads in Corporate Networks</title>
  <description>A Microsoft RPC vulnerability was patched in an out-of-band release in October, but organizations slow to deploy the update are learning the hard way how fast various RPC worm variants can spread through corporate networks.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-035.shtml</link>
  <pubDate>13 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
<title>T-034: Vulnerability Discovered In XOOPS</title>
  <description>Athos has discovered a vulnerability in XOOPS, which can be exploited by malicious people to compromise a vulnerable system.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-034.shtml</link>
  <pubDate>09 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-033: OpenSSL Security Advisory</title>
  <description>A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to conduct spoofing attacks.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-033.shtml</link>
  <pubDate>08 Jan 2009</pubDate>
  <category>New Bulletin</category>
</item>
<item>
  <title>T-032: New Xterm Packages Fix Regression</title>
  <description>New xterm packages fix regression, there was a design flaw</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-032.shtml</link>
  <pubDate>07 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-031: SolucionWeb "id_area" SQL Injection Vulnerability</title>
  <description>Ehsan_Hp200 has reported a vulnerablility in SolucionWeb, which can be exploited by malicious people to conduct SQL injection attacks.</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-031.shtml</link>
  <pubDate>06 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>T-030:  New Ruby packages fix denial of service</title>
  <description>The regular expression engine of Ruby, a scripting language, contains a memory leak which can be triggered remotely under certain circumstances, leading to a denial of service condition (CVE-2008-3443).</description>
  <link>http://circ.jc3.doe.gov/bulletins/t-030.shtml</link>
  <pubDate>05 Jan 2009</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-346: MySQL-dfsg-5.0 Vulnerabilities</title>
  <description>It was discovered that MySQL, a widely-deployed database server, did not properly validate optional data or index 
  directory paths given in a CREATE TABLE statement, no would it (under proper conditions) prevent two databases from using the same 
  paths for data or index files.  The risk is LOW.  This permits an authenticated user with authoriziation to create tables in one 
  database to read, write or delete data from tables subsequently created in other databases, regardless of other GRANT 
  authorizations.</description>
  <link>http://www.ciac.org/bulletins/s-346.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-345: Security Vulnerability in the Java Runtime Environment Virtual Machine</title>
  <description>A vulnerability in the Java Runtime Environment Virtual Machine may allow an untrusted application or applet that is 
  downloaded from a website to elevate its privileges.  The risk is MEDIUM.  The application or applet may grant itself permissions to 
  read and write local files or execute local applications that are accessible to the user running the untrusted application or 
  applet.</description>
  <link>http://www.ciac.org/bulletins/s-345.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-344: Ruby Security Update</title>
  <description>Multiple interger overflows to a heap overflow were discovered in the array- and string-handling code used by Ruby.  The 
  risk is MEDIUM.  An attacker could use these flaws to crash a Ruby application or, possibly, execute arbitrary code with the privileges 
  of the Ruby application using untrusted inputs in array or string operations.</description>
  <link>http://www.ciac.org/bulletins/s-344.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-343: Apple Safari 3.1.2 for Windows</title>
  <description>Apple Safari automatically executes downloaded files based on Internet Explorer zone settings, which can allow a remote attacker to execute arbitary code on a vulnerable system.  The risk is MEDIUM.  By convincing a user to visit a specially crafted web page with Apple Safari on Windows, an attacker mey be able to execute arbitrary code on a vulnerable system.</description>
  <link>http://www.ciac.org/bulletins/s-343.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-342: Popper Vulnerability</title>
  <description>It was discovered that poppler, a PDF rendering library, did not properly handle embedded fonts in PDF files, allowing 
  attackers to execute arbitrary code via a crafted font object.  The risk is MEDIUM.  </description>
  <link>http://www.ciac.org/bulletins/s-342.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-341: Multiple Cisco Products Vulnernable to DNS Cache Poisoning Attacks</title>
  <description>Multiple Cisco products are vulnerable to DNS cache poisoning attacks due to their use of insufficiently randomized DNS transaction IDs and UDP source ports in the DNS queries that they produce, which may allow an attacker to more easily forge DNS answers that can poison DNS caches.  The risk is HIGH.  Successful exploitation of the vulnerability described in this document may result in invalid hostname-to-IP address mappings in the cache of an affected DNS server. This may lead of this DNS server to contact with wrong provider of network services. </description>
  <link>http://www.ciac.org/bulletins/s-341.shtml</link>
  <pubDate>28 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-340: HP OpenView Network Node Manager (OV NNM)</title>
  <description>A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be 
  exploited remotely to gain unauthorized access to data.  The risk is LOW.   The vulnerability could be exploited remotely to gain 
  unauthorized access to data.</description>
  <link>http://www.ciac.org/bulletins/s-340.shtml</link>
  <pubDate>8 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-339: Vulnerabilities in Outlook Web Access for Exchange Server</title>
  <description>There is a cross-site scripting vulnerability in the affected versions of Outlook Web Access (OWA) for Exchange Server. 
  Exploitation of the vulnerability could lead to elevation of privilege on individual OWA clients connecting to Outlook Web Access for 
  Exchange Server.  The risk is LOW.  To exploit the vulnerability, an attacker would have to convince a user to open a specially 
  crafted e-mail that would run malicious script from within an individual OWA client. If the malicious script is executed, the script 
  would run inthe security context of the user's OWA session and could perform any action that user could perform such as reading, 
  sending, and deleting e-mail as the logged-on user.</description>
  <link>http://www.ciac.org/bulletins/s-339.shtml</link>
  <pubDate>8 Jul 2008 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-338: Apple Security Update 2008-004 / Mac OS X 10.5.4</title>
  <description>The Apple Webkit contains a memory corruption vulnerability. This vulnerability may allow a remote, unauthenticated 
  attacker to execute arbitrary code.  The risk is MEDIUM.  A remote, unauthenticated attacker may be able to execute arbitrary 
  code.</description>
  <link>http://www.ciac.org/bulletins/s-338.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-337: Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access</title>
  <description>Microsoft is investigating active, targeted attacks leveraging a potential vulnerability in the ActiveX control for the 
  Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page.  The 
  risk is MEDIUM.  An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web 
  page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the 
  same user rights as the logged-on user.</description>
  <link>http://www.ciac.org/bulletins/s-337.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-336: PCRE3 Vulnerability</title>
  <description>It was discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when 
  compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution.  The 
  risk is MEDIUM.  May encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and 
  branches, potentially leading the arbitrary code execution.</description>
  <link>http://www.ciac.org/bulletins/s-336.shtml</link>
  <pubDate>8 Jul 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-003: Understanding Cross-Site Scripting (XSS)</title>
  <description>Cross-Site Scripting has become an increasingly prevalent attack vector that can be leveraged to perform a wide range of compromises. These compromises can range from simple popup displays within a user's browser to session and cookie capture that are used for information and identity theft. As these attacks become more mature, as well as obscure, it is imperative that we understand how they happen, how they propagate, and the ways to prevent them. By understanding the different vectors of attack and realizing and implementing simple security measures against them, we can better protect ourselves and our users now, and in the future.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-003.shtml</link>
  <pubDate>3 Jun 2008 17:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-002: Understanding Windows Hash Dumpers and Crackers</title>
  <description>Windows hash dumping tools are often spotlighted as hacker tools that can somehow magically extract windows hashes and allow an intruder access to a system. In actuality, the hashes are there, in memory, where any admin or system level user can get at them. The tools just grab them and print them out. This paper will describe how Windows hashes are created, how the hash dumpers get at them, and what can be done with the hashes.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-002.shtml</link>
  <pubDate>21 May 2008 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech08-001: Understanding PHP Exploits</title>
  <description>Many websites use the PHP programming language to build web pages on the fly from individual files and from values obtained from a database. PHP based websites are widely used to create Wikis such as  MediaWiki used for Wikipedia. If the PHP programs that generate the web pages are not carefully crafted to check user input before it is used, an intruder could inject code into a page and get it executed.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech08-001.shtml</link>
  <pubDate>29 Jan 2008 18:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech07-001: MOICE - Microsoft Office Isolated Conversion Environment</title>
  <description>A common cyber attack is to send a user an Office document 
(Word, Excel, PowerPoint) containing malicious code that 
infects the user's computer and proceeds to do the miscreant's 
bidding. Targeting of users has gotten so sophisticated that 
advice such as "don't open files from people you don't know" is 
no longer effective. 

MOICE, the Microsoft Office 
Isolated Conversion Environment opens Office documents 
before the Office application, converts it to a format that 
does not "support" malcode and then invokes the application 
with the newly cleaned document. Properly implemented, this 
could mitigate attacks using email-borne Office malcode. </description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech07-001.shtml</link>
  <pubDate>22 May 2007 23:00 GMT</pubDate>
  <category>New Revised Bulletin </category>
</item>
<item>
  <title>CIACTech06-001: Protecting Against SQL Injection Attacks</title>
  <description>SQL injection is a real threat that is being used to exploit company systems and data. 
  This threat can be reduced by a combination of good programming practice, application firewalls, 
  and scanning.</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech06-001.shtml</link>
  <pubDate>6 Sep 2006 21:00 GMT</pubDate>
  <revDate>28 Apr 2008 21:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>CIACTech05-001: Operation of the Sinit/Calypso Worm</title>
  <description>Many sites have detected large numbers of udp packets 
directed at the DNS port (53). These packets contain a lot of structure 
and there is concern that they are exploit or remote control packets. 
It turns out that they are discovery packets being sent to random 
IP addresses by the Sinit Calypso worm. They are invalid DNS packets 
and should be ignored by DNS servers. 
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech05-001.shtml</link>
  <pubDate>15 Nov 2004 20:00 GMT</pubDate>
</item>
<item>
  <title>CIACTech04-001: Remote Detection of the MyDoom.A Worm</title>
  <description>Before systems containing the MyDoom.A worm can be cleaned, 
       they must be detected. As running a scanner on each system can be difficult 
       and time consuming, a method of remote scanning for infected machines is needed.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech04-001.shtml</link>
  <pubDate>30 Jan 2004 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech03-001: Spamming using the Windows Messenger Service</title>
  <description>A spam engine has been released that uses the Windows Messenger Service (not the MSN Messenger instant messaging program) to send spam messages to users. The Messenger service is active on most Windows platforms.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech03-001.shtml</link>
  <pubDate>29 Oct 2002 24:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-005: Understanding Capturing Files with Microsoft Word Field Codes</title>
  <description>Several online articles have worried the problem of file capture using Microsoft Word field codes. The articles have gone so far as suggesting that Word be banned from company computers until this is changed. These articles have created undue worry among computer users about what is a relatively low risk vulnerability.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-005.shtml</link>
  <pubDate>27 Sep 2002 24:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-004: Parasite Programs; Adware, Spyware, and Stealth Networks</title>
  <description>Programs are being intentionally packaged with legitimate 
       software to display advertising on your screen, gather information on your 
       browsing habits, and to sell your unused 
       CPU cycles and disk space. Current applications are relatively benign but 
       could easily be used for an invasion of privacy or other malicious 
       purposes.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-004.shtml</link>
  <pubDate>11 Nov 2002 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-003: Office for Mac X Antipiracy Mechanism Opens Server Ports</title>
  <description>Microsoft Office for Macintosh OS X has an antipiracy mechanism that secretly opens network service ports on a Macintosh system and broadcasts version information to other systems on a single subnet. The problem is that 
       open network services provide attack points for intruders and need to be 
       controlled by users.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-003.shtml</link>
  <pubDate>26 Apr 2002 00:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-002: Microsoft Browser Helper Objects (BHO) Could Hide Malicious Code</title>
  <description>Browser Helper Objects (BHO) are Microsoft's way of attaching add-ins to Internet Explorer 4 and later. In addition to legitimate uses, BHOs are used to attach spyware to a user's web browser 
       to secretly send a user's browsing habits to a marketing site and could be used for malicious code. The problems are that there is no simple way to know what BHOs are attached to a system and no simple way to control the attachment of new ones.
</description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-002.shtml</link>
  <pubDate>2 Apr 2002 23:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>CIACTech02-001: Understanding the SSH CRC32 Exploit</title>
  <description>In recent months, many servers running ssh
       have been compromised using the SSH CRC32 Compensation Attack
       Detector. Compromised machines have either not been upgraded to
       SSH protocol 2 or have not disabled drop back to SSH protocol 1. 
       Use of this attack allows a remote user to gain root access on a server.
  </description>
  <link>http://www.ciac.org/ciac/techbull/CIACTech02-001.shtml</link>
  <pubDate>9 May 2002 19:00 GMT</pubDate>
  <category>New Bulletin </category>
</item>
<item>
  <title>S-317: HP OpenView Network Node Manager (OV NNM) Vulnerabilities</title>
  <description>A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could 
  be exploited remotely to execute arbitrary code or to create a Denial of Service (DoS).  The risk is MEDIUM. The vulnerability could 
  be exploited remotely execute arbitrary code or to create a Denial of Service (DoS).</description>
  <link>http://www.ciac.org/bulletins/s-317.shtml</link>
  <pubDate>19 Jun 2008 16:00 GMT</pubDate>
  <revDate>8 Jul 2008 16:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-164: Tk Vulnerability</title>
  <description>A buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service
   and potentially the execution of arbitrary code.  The risk is MEDIUM.  Could lead to denial of service and potentially the execution of 
   arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-164.shtml</link>
  <pubDate>11 Feb 2008 18:00 GMT</pubDate>
  <revDate>27 Jun 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-316: Vulnerability in Microsoft XML Core Services</title>
  <description>A remote code execution vulnerability exists in Microsoft XML Core Services that could allow an attacker who 
  successfully exploited this vulnerability to make changes to the system with the permissions of the logged-onuser.  The risk is MEDIUM.  
  If the user is logged on with administrative user rights, an attacker could take complete control of the affected system.</description>
  <link>http://www.ciac.org/bulletins/r-316.shtml</link>
  <pubDate>14 Aug 2007 18:00 GMT</pubDate>
  <revDate>27 Jun 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-232: HP-UX Running HP CIFS Server (Samba)</title>
  <description>A potential security vulnerability has been identified with HP-UX running HP CIFS Server (Samba).  The risk is MEDIUM. 
  This vulnerability could be exploited remotely to execute arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-232.shtml</link>
  <pubDate>27 Mar 2008 14:00 GMT</pubDate>
  <revDate>27 Jun 2008 14:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-314: Vulnerability in Bluetooth Stack</title>
  <description>A remote code execution vulnerability exists in the Bluetooth stack in Microsoft Windows because the Bluetooth stack does 
  not correctly handle a large nubmer of service description requests.  The risk is MEDIUM.  The vulnerability could allow an attacker to 
  run code with elevated privileges.  An attacker who successfully exploited this vulenrability could take complete contorl of an 
  affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user 
  rights.</description>
  <link>http://www.ciac.org/bulletins/s-314.shtml</link>
  <pubDate>12 Jun 2008 14:00 GMT</pubDate>
  <revDate>27 Jun 2008 14:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-286: PHP Path Translation Vulnerability</title>
  <description>PHP contains a path translation vulnerability that may allow an attacker to execute arbitrary code.  The risk is MEDIUM.  
  An attacker may be able to execute arbitrary code in the context of an application that uses the vulnerable function. The scope of the 
  impact depends on how the affected application works. Applications that process filename input from the network, such as public-facing 
  web applications, would be vulnerable to a remote attacker.</description>
  <link>http://www.ciac.org/bulletins/s-286.shtml</link>
  <pubDate>9 May 2008 15:00 GMT</pubDate>
  <revDate>27 Jun 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-301: Samba Security and Bug Fix Update</title>
  <description>A heap-based buffer overflow flaw was found in the way Samba clients handle over-sized packets. If a client connected to a 
  malicious Samba server, it was possible to execute arbitrary code as the Samba client user.  The risk is MEDIUM.  A malicious Samba 
  server could run arbitrary code on a Samba client as the Samba client user. Alternately, a malicious client could run arbitrary code 
  on a Samba server with the permissions of the Samba server.</description>
  <link>http://www.ciac.org/bulletins/s-301.shtml</link>
  <pubDate>30 May 2008 12:00 GMT</pubDate>
  <revDate>27 Jun 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-226: Vulnerability in Microsoft Outlook (MS08-015)</title>
  <description>A remote code execution exists in Outlook.  The risk is MEDIUM.  The vulnerability could allow remote code execution if 
  Outlook is passed a specially crafted malito URI. </description>
  <link>http://www.ciac.org/bulletins/s-226.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>5 Jun 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-289: Vulnerability in Microsoft Publisher</title>
  <description>A remote code execution vulnerability exists in the way Microsoft Publisher validates object header data. An attacker 
  could exploit the vulnerability by sending a specially crafted Publisher file which could be an e-mail attachment, or hosted on a 
  specially crafted or compromised Web site.  The risk is MEDIUM.  If a user were logged on with administrative user rights, an attacker 
  who successfully exploited this vulnerability could take complete control of an affected system.</description>
  <link>http://www.ciac.org/bulletins/s-289.shtml</link>
  <pubDate>13 May 2008 20:00 GMT</pubDate>
  <revDate>5 Jun 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-290: Vulnerability in Microsoft Jet Database Engine (JET)</title>
  <description>A buffer overfun vulnerability exists in the Microsoft Jet Database Engine (JET) that could allow remote code execution on 
  an affected system.  An attacker could exploit the vulnerability by creating a specially crafted database query and sending it through 
  an application that is using Jet on an affected system.  The risk is MEDIUM.  An attacker who successfully exploited this vulnerability 
  could take complete control of an affected system.</description>
  <link>http://www.ciac.org/bulletins/s-290.shtml</link>
  <pubDate>13 May 2008 19:00 GMT</pubDate>
  <revDate>5 Jun 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-294: libvorbis Security Update</title>
  <description>Several flaws werer reported in the way libvorbis processed audio data.  The risk is MEDIUM.  An attacker could create a 
  carefully crafted OGG audio file in such a way that it could cause an application linked with libvorbis to crash, or execute arbitrary 
  code when it was opened.</description>
  <link>http://www.ciac.org/bulletins/s-294.shtml</link>
  <pubDate>15 May 2008 20:00 GMT</pubDate>
  <revDate>5 Jun 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-227: Vulnerabilities in Microsoft Excel (MS08-014)</title>
  <description>Remote code vulnerabilities exist in the way Excel:
1) processes data validation records when loading Excel files into memory;
2) handles data when importing files into Excel;
3) Style record data when opening Excel files;
4) handles malformed formulas;
5) handles rich text values when loading application data into memory;
6) handles conditional formatting values; and
7) handles macros when opening specially crafted Excel files.  The risk is MEDIUM.  An attacker could exploit the vulnerabilities by 
sending malformed files which could be hosted on a specially crafted or compromised Web site, or included as an e-mail attachment.</description>
  <link>http://www.ciac.org/bulletins/s-227.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>5 Jun 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-272: Speex Security Update</title>
  <description>The Speex library was found to not properly validate input values read from the Speex files headers, which could allow 
  arbitrary code execution.  The risk is MEDIUM. An attacker could create a malicious Speex file that would crash an application or, 
  possibly, allow arbitrary code execution with the privileges of the application calling the Speex library.</description>
  <link>http://www.ciac.org/bulletins/s-272.shtml</link>
  <pubDate>25 Apr 2008 12:00 GMT</pubDate>
  <revDate>29 May 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-297: libxslt Security Update</title>
  <description>The libxslt library did not properly process long "transformation match" conditions in the XSL stylesheet files.  The risk
  is MEDIUM.  An attacker could create a malicious XSL file that would cause a crash, or, possibly, execute and arbitrary code with the 
  privileges of the application using libxslt library to perform XSL transformations.</description>
  <link>http://www.ciac.org/bulletins/s-297.shtml</link>
  <pubDate>22 May 2008 13:00 GMT</pubDate>
  <revDate>29 May 2008 13:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-163: Simple DirectMedia Layer 1.2 Vulnerabilities</title>
  <description>Several local/remote vulnerabilities have been discovered in the image loading library for the Simple DirectMedia 
  Layer 1.2.  The risk is MEDIUM.  Could result in denial of service and potentially the execution of arbitary code.</description>
  <link>http://www.ciac.org/bulletins/s-163.shtml</link>
  <pubDate>11 Feb 2008 18:00 GMT</pubDate>
  <revDate>20 May 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-288: Vulnerabilities in Microsoft Word</title>
  <description>A remote code execution vulnerability exists in the way that Microsoft Word  handle specially crafted Word files. The 
  vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed CSS value.  The 
  risk is MEDIUM.  An attacker who successfully exploited this vulnerability could take complete control of an attected 
  system.</description>
  <link>http://www.ciac.org/bulletins/s-288.shtml</link>
  <pubDate>13 May 2008 19:00 GMT</pubDate>
  <revDate>20 May 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-224: Vulnerabilities in Microsoft Office Web Components (MS08-017)</title>
  <description>Remote code execution vulnerabilities exist in the way Microsoft Office Web Components manages memory resources.  The 
  risk is MEDIUM.  An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web 
  page, the vulnerability could allos remote code execution. </description>
  <link>http://www.ciac.org/bulletins/s-224.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>15 May 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-037: Perl-Compatible Regular Expression (PCRE) Vulnerabilities</title>
  <description>There are several security issues in PCRE library which potentially allow attackers to execute arbitrary code by compiling 
  specially crafted regular expressions.  The risk is LOW.  Could potentially allow attackers to execute arbitrary code by compiling 
  specially crafted regular expressions.</description>
  <link>http://www.ciac.org/bulletins/s-037.shtml</link>
  <pubDate>7 Nov 2007 15:00 GMT</pubDate>
  <revDate>8 May 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-295: Vulnerabilities in .NET Framework (931212)</title>
  <description>A remote code execution vulnerability exists in .NET Framework that could allow an attacker who successfully exploited this vulnerability to make changes to the system with the permissions of the logged-on user.  The risk is HIGH.  A remote code execution vulnerability exists in .NET Framework that could allow an attacker who successfully exploited this vulnerability to make changes to the system with the permissions of the logged-on user. </description>
  <link>http://www.ciac.org/bulletins/r-295.shtml</link>
  <pubDate>10 Jul 2007 20:00 GMT</pubDate>
  <revDate>8 May 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-269: kdegraphics Security Update</title>
  <description>There is a flaw in the way kpdf displayed malformed fonts embedded in PDF files which could potentially execute arbitrary 
  code.  The risk is MEDIUM. An attacker could create a malicious PDF file that would cause kpdf to crash, or potentially, execute 
  arbitrary code when opened.</description>
  <link>http://www.ciac.org/bulletins/s-269.shtml</link>
  <pubDate>25 Apr 2008 11:00 GMT</pubDate>
  <revDate>8 May 2008 11:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-282: HP-UX Running WBEM Services</title>
  <description>Potential security vulnerabilities have been identified with HP-UX running WBEM Services that could remotely execute 
  arbitrary code or gain extended privileges.  The risk is MEDIUM.  These vulnerabilities could be exploited remotely to execute 
  arbitrary code or to gain extended privileges.</description>
  <link>http://www.ciac.org/bulletins/s-282.shtml</link>
  <pubDate>1 May 2008 15:00 GMT</pubDate>
  <revDate>7 May 2008 15:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-100: GNU Tar Vulnerabilities</title>
  <description>Several vulnerabilities have been discovered in GNU Tar. The risk is MEDIUM.  May lead to arbitrary code execution when 
  processing maliciously crafted archives.</description>
  <link>http://www.ciac.org/bulletins/s-100.shtml</link>
  <pubDate>3 Jan 2008 22:00 GMT</pubDate>
  <revDate>7 May 2008 22:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-355: PHP Security Update</title>
  <description>There are several vulnerabilities in PHP.  The risk is MEDIUM.  Could possibly execute arbitrary code as the apache 
  user.</description>
  <link>http://www.ciac.org/bulletins/r-355.shtml</link>
  <pubDate>20 Sep 2007 20:00 GMT</pubDate>
 <revDate>07 May 2008 18:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-270: SeaMonkey Security Update</title>
  <description>A flaw was found in the processing of malformed JavaScript content which could lead to the execution of arbitrary code.  
  The risk is MEDIUM.  A web page containing such maliciuos content could cause SeaMonkey to crash or, potentially, execute arbitrary 
  code as the user running SeaMonkey.</description>
  <link>http://www.ciac.org/bulletins/s-270.shtml</link>
  <pubDate>25 Apr 2008 11:00 GMT</pubDate>
  <revDate>2 May 2008 11:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-225: Vulnerabilities in Microsoft Office (MS08-016)</title>
  <description>There are remote code execution vulnerabilities that exist in the way Microsoft Office handles specially crafted Excel 
  files and processes malformed Office files.  The risk is MEDIUM.  An attacker could exploit the vulnerability by creating a malformed 
  file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site. If a user were logged 
  on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an 
  affected system.</description>
  <link>http://www.ciac.org/bulletins/s-225.shtml</link>
  <pubDate>14 Mar 2008 17:00 GMT</pubDate>
  <revDate>1 May 2008 17:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>R-232: Vulnerability in Microsoft Office</title>
  <description>A remote code execution vulnerability exists in the way Microsoft Office handles a specially crafted drawing object.  
  The risk is MEDIUM.  Code runs in the context of the user.</description>
  <link>http://www.ciac.org/bulletins/r-232.shtml</link>
  <pubDate>9 May 2007 12:00 GMT</pubDate>
  <revDate>1 May 2008 12:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-241: Multiple DLSw Denial of Service Vulnerabilities</title>
  <description>Cisco IOS contains multiple vulnerabilities in the Data-link Switching (DLSw) feature that may result in a reload or 
  memory leaks when processing specially crafted UDP or IP Protocol 91 packets.  The risk is LOW.  Successful exploitation of these 
  vulnerabilities may result in the reload of the device or memory leaks, leading to a DoS condition.</description>
  <link>http://www.ciac.org/bulletins/s-241.shtml</link>
  <pubDate>27 Mar 2008 19:00 GMT</pubDate>
  <revDate>28 Apr 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-092: Adobe Flash Player Vulnerability</title>
  <description>Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits 
  these potential vulnerabilities to take control of the affected system.  The risk is MEDIUM.  Could lead to the potential execution of 
  arbitrary code.</description>
  <link>http://www.ciac.org/bulletins/s-092.shtml</link>
  <pubDate>21 Dec 2007 21:00 GMT</pubDate>
  <revDate>28 Apr 2008 21:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-257: Cumulative Security Update for Internet Explorer</title>
  <description>A remote code execution vulnerability exists in Internet Explorer because of the way that it processes data streams.  An 
  attacker could exploit the vulnerability by constructing a specially crafted Web page.  The risk is MEDIUM.  When a user views the Web 
  page, the vulnerability could allow remote code execution.  An attacker who successfully exploited this vulnerability could gain the 
  same user rights as the logged on user.</description>
  <link>http://www.ciac.org/bulletins/s-257.shtml</link>
  <pubDate>9 Apr 2008 20:00 GMT</pubDate>
  <revDate>24 Apr 2008 20:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
<item>
  <title>S-252: Vulnerabilities in Microsoft Visio</title>
  <description>Several remote code execution vulnerabilities exists in the way Microsoft Visio validates:
1) object header data in specially crafted file; and 
2) memory allocations when loading specially-crafted .DXF files from disk into memory.  The risk is MEDIUM.  An attacker could exploit 
the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a specially crafted or 
compromised Web site.</description>
  <link>http://www.ciac.org/bulletins/s-252.shtml</link>
  <pubDate>9 Apr 2008 19:00 GMT</pubDate>
  <revDate>24 Apr 2008 19:00 GMT</revDate>
  <category>Revised Bulletin </category>
</item>
</channel>
</rss>


