<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IDF Task Force &#187; Latest vulnerabilities</title>
	<atom:link href="http://www.idftaskforce.com/blog/tag/latest-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.idftaskforce.com/blog</link>
	<description>Cell Phone Spy and Computer Forensics</description>
	<lastBuildDate>Tue, 05 Jan 2010 18:18:32 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Latest high risk vulnerabilities for the last week of November, 2009</title>
		<link>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities-for-the-last-week-of-november-2009/</link>
		<comments>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities-for-the-last-week-of-november-2009/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 14:48:21 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[2009 vulnerabilities]]></category>
		<category><![CDATA[high risk vulnerabilities]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>
		<category><![CDATA[november]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=118</guid>
		<description><![CDATA[


Primary
Vendor &#8212; Product
Description
Published
CVSS Score





2wire &#8212; 1700hg
2wire &#8212; 1701hg
2wire &#8212; 1800hw
2wire &#8212; 2071
2wire &#8212; 2700hg
2wire &#8212; 2701hg-t
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities-for-the-last-week-of-november-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest Vulnerabilities for 1st week of November</title>
		<link>http://www.idftaskforce.com/blog/latest-vulnerabilities-ro-1st-week-of-november/</link>
		<comments>http://www.idftaskforce.com/blog/latest-vulnerabilities-ro-1st-week-of-november/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 17:21:23 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=106</guid>
		<description><![CDATA[


Primary
Vendor &#8212; Product
Description
Published
CVSS Score





adobe &#8212; shockwave_player
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.
2009-11-04
9.3



dobe &#8212; shockwave_player
Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/latest-vulnerabilities-ro-1st-week-of-november/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest High Risk Vulnerabilities</title>
		<link>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities/</link>
		<comments>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 18:16:17 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=91</guid>
		<description><![CDATA[


Vendor &#8212; Product
Description
Published




acoustica &#8212; mp3_audio_mixer
Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.
2009-10-27


adam_gerson &#8212; moodle_courselist
SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/latest-high-risk-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High Risk Vulnerability Summary for third week of October</title>
		<link>http://www.idftaskforce.com/blog/high-risk-vulnerability-summary-for-third-week-of-october/</link>
		<comments>http://www.idftaskforce.com/blog/high-risk-vulnerability-summary-for-third-week-of-october/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 16:55:35 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=74</guid>
		<description><![CDATA[


Vendor &#8212; Product
Description
Published
CVSS Score





adobe &#8212; acrobat
adobe &#8212; acrobat_reader
Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.
2009-10-19
9.3



adobe &#8212; acrobat
adobe &#8212; acrobat_reader
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/high-risk-vulnerability-summary-for-third-week-of-october/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft patches 34 vulnerabilities</title>
		<link>http://www.idftaskforce.com/blog/microsoft-patches-34-vulnerabilities/</link>
		<comments>http://www.idftaskforce.com/blog/microsoft-patches-34-vulnerabilities/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 15:36:28 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft updates]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=64</guid>
		<description><![CDATA[In this week&#8217;s huge  patch, Microsoft delivers 13 bulletins that fix 34 vulnerabilities targeting Windows, Internet Explorer,  .NET framework, Forefront, MS Office, SQL server, Developer Tools and Silverlight.
Vulnerabilities in SMB v2 Could Allow Remote Code Execution
This security update resolves one publicly disclosed and two privately reported vulnerabilities in Server Message Block Version 2 (SMBv2). The [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/microsoft-patches-34-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest vulnerabilities</title>
		<link>http://www.idftaskforce.com/blog/latest-vulnerabilities/</link>
		<comments>http://www.idftaskforce.com/blog/latest-vulnerabilities/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 16:06:17 +0000</pubDate>
		<dc:creator>IDF Agent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Latest vulnerabilities]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.idftaskforce.com/blog/?p=58</guid>
		<description><![CDATA[apple &#8212; safari:
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a &#8216;\0&#8242; character in a domain name in the subject&#8217;s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority
avast &#8212; avast_antivirus_home
avast &#8212; [...]]]></description>
		<wfw:commentRss>http://www.idftaskforce.com/blog/latest-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
