<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:admin="http://webns.net/mvcb/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/"><channel rdf:about="http://nvd.nist.gov/download/nvd-rss-analyzed.xml"><title>National Vulnerability Database</title><link>http://web.nvd.nist.gov/view/vuln/search</link><description>This feed contains the most recent fully analyzed CVE cyber vulnerabilities published within the National Vulnerability Database.</description><dc:language xmlns:dc="http://purl.org/dc/elements/1.1/">en-us</dc:language><dc:rights xmlns:dc="http://purl.org/dc/elements/1.1/">This material is not copywritten and may be freely used, however, attribution is requested.</dc:rights><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16T03:33:58-05:00</dc:date><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nvd@nist.gov</dc:creator><items><rdf:Seq xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/></rdf:Seq></items></channel><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085"><title>CVE-2011-3085</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085</link><description>The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084"><title>CVE-2011-3084</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084</link><description>Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083"><title>CVE-2011-3083</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083</link><description>browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248"><title>CVE-2012-1248 (basercms)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248</link><description>app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247"><title>CVE-2012-1247 (web_mart)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247</link><description>Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246"><title>CVE-2012-1246 (web_mart)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246</link><description>Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612"><title>CVE-2012-2612 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612</link><description>The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611"><title>CVE-2012-2611 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611</link><description>The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514"><title>CVE-2012-2514 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514</link><description>The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513"><title>CVE-2012-2513 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513</link><description>The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512"><title>CVE-2012-2512 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512</link><description>The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511"><title>CVE-2012-2511 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511</link><description>The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333"><title>CVE-2012-2333 (openssl)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333</link><description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277"><title>CVE-2012-2277 (documentum_information_rights_management)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277</link><description>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many &quot;batch begin untethered&quot; commands.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276"><title>CVE-2012-2276 (documentum_information_rights_management)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276</link><description>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390"><title>CVE-2011-1390 (rational_clearquest)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390</link><description>SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804"><title>CVE-2012-1804 (movicon)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804</link><description>The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item></rdf:RDF>

