<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:admin="http://webns.net/mvcb/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/"><channel rdf:about="http://nvd.nist.gov/download/nvd-rss.xml"><title>National Vulnerability Database</title><link>http://web.nvd.nist.gov/view/vuln/search</link><description>This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.</description><dc:language xmlns:dc="http://purl.org/dc/elements/1.1/">en-us</dc:language><dc:rights xmlns:dc="http://purl.org/dc/elements/1.1/">This material is not copywritten and may be freely used, however, attribution is requested.</dc:rights><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16T03:33:58-05:00</dc:date><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nvd@nist.gov</dc:creator><items><rdf:Seq xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0671" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0670" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0669" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0668" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0667" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0666" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0665" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0664" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0663" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0265" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3102" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3101" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3100" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3099" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3098" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3097" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3096" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3095" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3094" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3093" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3092" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3091" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3090" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3089" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3088" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3087" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3086" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/></rdf:Seq></items></channel><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0671"><title>CVE-2012-0671</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0671</link><description>Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .pict file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0670"><title>CVE-2012-0670</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0670</link><description>Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted sean atom in a movie file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0669"><title>CVE-2012-0669</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0669</link><description>Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0668"><title>CVE-2012-0668</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0668</link><description>Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0667"><title>CVE-2012-0667</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0667</link><description>Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTVR movie file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0666"><title>CVE-2012-0666</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0666</link><description>Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTMovie object.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0665"><title>CVE-2012-0665</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0665</link><description>Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0664"><title>CVE-2012-0664</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0664</link><description>Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text track in a movie file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0663"><title>CVE-2012-0663</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0663</link><description>Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0265"><title>CVE-2012-0265</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0265</link><description>Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-16</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3102"><title>CVE-2011-3102</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3102</link><description>Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3101"><title>CVE-2011-3101</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3101</link><description>Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3100"><title>CVE-2011-3100</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3100</link><description>Google Chrome before 19.0.1084.46 does not properly draw dash paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3099"><title>CVE-2011-3099</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3099</link><description>Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a malformed name for the font encoding.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3098"><title>CVE-2011-3098</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3098</link><description>Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3097"><title>CVE-2011-3097</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3097</link><description>The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an out-of-bounds write error in the implementation of sampled functions.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3096"><title>CVE-2011-3096</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3096</link><description>Use-after-free vulnerability in Google Chrome before 19.0.1084.46 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an error in the GTK implementation of the omnibox.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3095"><title>CVE-2011-3095</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3095</link><description>The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3094"><title>CVE-2011-3094</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3094</link><description>Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3093"><title>CVE-2011-3093</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3093</link><description>Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3092"><title>CVE-2011-3092</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3092</link><description>The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3091"><title>CVE-2011-3091</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3091</link><description>Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3090"><title>CVE-2011-3090</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3090</link><description>Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker processes.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3089"><title>CVE-2011-3089</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3089</link><description>Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3088"><title>CVE-2011-3088</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3088</link><description>Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3087"><title>CVE-2011-3087</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3087</link><description>Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3086"><title>CVE-2011-3086</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3086</link><description>Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085"><title>CVE-2011-3085</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085</link><description>The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084"><title>CVE-2011-3084</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084</link><description>Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083"><title>CVE-2011-3083</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083</link><description>browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248"><title>CVE-2012-1248 (basercms)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1248</link><description>app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247"><title>CVE-2012-1247 (web_mart)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1247</link><description>Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246"><title>CVE-2012-1246 (web_mart)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1246</link><description>Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612"><title>CVE-2012-2612 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2612</link><description>The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611"><title>CVE-2012-2611 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2611</link><description>The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514"><title>CVE-2012-2514 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2514</link><description>The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513"><title>CVE-2012-2513 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2513</link><description>The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512"><title>CVE-2012-2512 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2512</link><description>The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511"><title>CVE-2012-2511 (netweaver)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2511</link><description>The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-15</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333"><title>CVE-2012-2333 (openssl)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333</link><description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277"><title>CVE-2012-2277 (documentum_information_rights_management)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2277</link><description>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many &quot;batch begin untethered&quot; commands.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276"><title>CVE-2012-2276 (documentum_information_rights_management)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2276</link><description>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390"><title>CVE-2011-1390 (rational_clearquest)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1390</link><description>SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item><item rdf:about="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804"><title>CVE-2012-1804 (movicon)</title><link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1804</link><description>The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2012-05-14</dc:date></item></rdf:RDF>

