<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.security-database.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.security-database.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
	<channel>
		<title>Security-Database Alerts Monitor : Last 100 Alerts</title>
		<link>http://www.security-database.com/</link>
		<description>Security-Database.com is a free web service solution that offer real-time vulnerabilities alerts and notifications.</description>
		<language>en-us</language>
		<pubDate>Wed, 23 Jul 08 19:11:47 +0200</pubDate>

		
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.security-database.com/Last100Alerts" type="application/rss+xml" /><item>
			<title>High - RHSA-2008:0607-01 - Problem Description:

Updated kernel packages...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/343714083/detail.php</link>
			<description>Problem Description:

Updated kernel packages that fix a security issue and several bugs are now
available for Red Hat Enterprise Linux 4.

This update has been rated as having important...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/343714083" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 23 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0607-01</feedburner:origLink></item>

		
		<item>
			<title>High - USN-627-1 -  Dnsmasq vulnerability</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843377/detail.php</link>
			<description>A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843377" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=USN-627-1</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0582-01 - Problem Description:

Updated PHP packages...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342544989/detail.php</link>
			<description>Problem Description:

Updated PHP packages that fix several security issues are now available for
Red Hat Application Stack v1.

This update has been rated as having moderate security impact...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342544989" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0582-01</feedburner:origLink></item>

		
		<item>
			<title>Low - MDVSA-2008:152 - Updated wireshark packages fix denial of service vulnerability</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/343075236/detail.php</link>
			<description>Problem Description:
 
 A vulnerability was found in Wireshark, that could cause it to crash
 while processing malicious packets.
 
 This update provides Wireshark 1.0.2, which is not...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/343075236" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=MDVSA-2008:152</feedburner:origLink></item>

		
		<item>
			<title>Medium - DSA-1613 - libgd2 -- multiple vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342422230/detail.php</link>
			<description>Multiple vulnerabilities have been identified in libgd2, a libraryfor programmatic graphics creation and manipulation. The CommonVulnerabilities and Exposures project identifies the following...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342422230" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=DSA-1613</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3263 - Asterisk allows remote attackers to cause a...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/343196836/detail.php</link>
			<description>Asterisk allows remote attackers to cause a denial of service (CPU consumption) by quickly sending a large number of IAX POKE requests.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/343196836" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3263</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3262 - Cross-site request forgery (CSRF) vulnerability...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342975834/detail.php</link>
			<description>Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirement for the previous password.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342975834" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3262</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3261 - Open redirect vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342975835/detail.php</link>
			<description>Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342975835" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3261</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3260 - Multiple cross-site scripting (XSS)...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342975836/detail.php</link>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342975836" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3260</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3259 - OpenSSH before 5.1 sets the SO_REUSEADDR socket...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843379/detail.php</link>
			<description>OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843379" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3259</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3258 - Multiple SQL injection vulnerabilities in Zoph...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843380/detail.php</link>
			<description>Multiple SQL injection vulnerabilities in Zoph before 0.7.0.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843380" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3258</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3257 - Stack-based buffer overflow in the Apache...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843381/detail.php</link>
			<description>Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843381" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3257</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3256 - SQL injection vulnerability in folder.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843382/detail.php</link>
			<description>SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843382" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3256</feedburner:origLink></item>

		
		<item>
			<title>NA - CVE-2008-3255 - Cross-site scripting (XSS) vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843383/detail.php</link>
			<description>Cross-site scripting (XSS) vulnerability in LunarNight Laboratory WebProxy 1.7.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843383" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3255</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3254 - SQL injection vulnerability in index.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843384/detail.php</link>
			<description>SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843384" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3254</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3253 - Cross-site scripting (XSS) vulnerability in the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843385/detail.php</link>
			<description>Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise)...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843385" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3253</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3188 - libxcrypt in SUSE openSUSE 11.0 uses the DES...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342843386/detail.php</link>
			<description>libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342843386" height="1" width="1"/&gt;</description>
			<pubDate>Tue, 22 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3188</feedburner:origLink></item>

		
		<item>
			<title>NA - SUN-239907 - Sun Alert 239907 SUN ALERT WEEKLY SUMMARY REPORT - Week of 13-Jul-2008 to 19-Jul-2008</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342422231/detail.php</link>
			<description>&amp;lt;div class=&amp;quot;product&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Product:&amp;lt;/b&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;state&amp;quot;&amp;gt;&amp;lt;b&amp;gt;State:&amp;lt;/b&amp;gt; Workaround&amp;lt;/div&amp;gt;&amp;lt;div...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342422231" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=SUN-239907</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0641-02 - Problem Description:

Updated acroread...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341676199/detail.php</link>
			<description>Problem Description:

Updated acroread packages that fix various security issues are now
available for Red Hat Enterprise Linux 3 Extras, 4 Extras, and 5 Supplementary.

This update has been...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341676199" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0641-02</feedburner:origLink></item>

		
		<item>
			<title>High - MDVSA-2008:151 - Updated libxslt packages fix buffer overflow vulnerability</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/342200069/detail.php</link>
			<description>Problem Description:
 
 A buffer overflow vulnerability in libxslt could be exploited via an
 XSL style sheet file with a long XLST transformation match condition,
 which could possibly lead to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/342200069" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=MDVSA-2008:151</feedburner:origLink></item>

		
		<item>
			<title>High - GLSA-200807-12 -  BitchX: Multiple vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961015/detail.php</link>
			<description>Synopsis
========

Multiple vulnerabilities in BitchX may allow for the remote execution
of arbitrary code or symlink attacks.

Background
==========

BitchX is an IRC client.

Affected...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961015" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=GLSA-200807-12</feedburner:origLink></item>

		
		<item>
			<title>High - GLSA-200807-11 -  PeerCast: Buffer overflow</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961016/detail.php</link>
			<description>Synopsis
========

A buffer overflow vulnerability in PeerCast may allow for the remote
execution of arbitrary code.

Background
==========

PeerCast is a client and server for P2P-radio...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961016" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=GLSA-200807-11</feedburner:origLink></item>

		
		<item>
			<title>Low - GLSA-200807-10 -  Bacula: Information disclosure</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818742/detail.php</link>
			<description>Synopsis
========

A vulnerability in Bacula may allow local attackers to obtain sensitive
information.

Background
==========

Bacula is a network based backup suite.

Affected packages...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818742" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=GLSA-200807-10</feedburner:origLink></item>

		
		<item>
			<title>High - DSA-1612 - ruby1.8 -- several vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961017/detail.php</link>
			<description>Several vulnerabilities have been discovered in the interpreter forthe Ruby language, which may lead to denial of service or theexecution of arbitrary code. The Common Vulnerabilities and...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961017" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=DSA-1612</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3252 - Stack-based buffer overflow in the read_article...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961018/detail.php</link>
			<description>Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large number of lines...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961018" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3252</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3251 - Multiple SQL injection vulnerabilities in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961019/detail.php</link>
			<description>Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tampereunited/opponent.php; or the id parameter to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961019" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3251</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3250 - SQL injection vulnerability in index.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961021/detail.php</link>
			<description>SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961021" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3250</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3249 - The client in Lenovo System Update before 3.14...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341961024/detail.php</link>
			<description>The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341961024" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3249</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3246 - Unspecified vulnerability in the PDF distiller...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818743/detail.php</link>
			<description>Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3)...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818743" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3246</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3245 - SQL injection vulnerability in phpHoo3.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818745/detail.php</link>
			<description>SQL injection vulnerability in phpHoo3.php in phpHoo3 4.3.9, 4.3.10, 4.4.8, and 5.2.6 allows remote attackers to execute arbitrary SQL commands via the viewCat parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818745" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3245</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3244 - The scanning engine before 4.4.4 in F-Prot...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818746/detail.php</link>
			<description>The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818746" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3244</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3243 - Multiple unspecified vulnerabilities in the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818748/detail.php</link>
			<description>Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818748" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3243</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3242 - Heap-based buffer overflow in the PPMedia Class...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818749/detail.php</link>
			<description>Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code via a long argument to the StartUrl method....&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818749" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3242</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3241 - SQL injection vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818750/detail.php</link>
			<description>SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818750" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3241</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3240 - SQL injection vulnerability in index.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818751/detail.php</link>
			<description>SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm parameter in a directory action.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818751" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3240</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3239 - Unrestricted file upload vulnerability in the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818752/detail.php</link>
			<description>Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818752" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3239</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3238 - Multiple SQL injection vulnerabilities in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818756/detail.php</link>
			<description>Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id parameter in sellers_othersitem.php, (2) the productid...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818756" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3238</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3237 - Cross-site scripting (XSS) vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818758/detail.php</link>
			<description>Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web script or HTML via the productid parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818758" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3237</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3236 - Unspecified vulnerability in Wsadmin in the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818760/detail.php</link>
			<description>Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818760" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3236</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3235 - Unspecified vulnerability in the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818761/detail.php</link>
			<description>Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818761" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3235</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3187 - zypp-refresh-patches in zypper in SUSE openSUSE...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/341818762/detail.php</link>
			<description>zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/341818762" height="1" width="1"/&gt;</description>
			<pubDate>Mon, 21 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3187</feedburner:origLink></item>

		
		<item>
			<title>High - MDVSA-2008:150 - Updated mysql packages fix vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/340288484/detail.php</link>
			<description>Problem Description:
 
 Multiple buffer overflows in yaSSL, which is used in MySQL, allowed
 remote attackers to execute arbitrary code (CVE-2008-0226) or cause
 a denial of service via a...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/340288484" height="1" width="1"/&gt;</description>
			<pubDate>Sat, 19 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=MDVSA-2008:150</feedburner:origLink></item>

		
		<item>
			<title>Medium - MDVSA-2008:149 - Updated mysql packages fix vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/340187137/detail.php</link>
			<description>Problem Description:
 
 Sergei Golubchik found that MySQL did not properly validate optional
 data or index directory paths given in a CREATE TABLE statement; as
 well it would not, under...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/340187137" height="1" width="1"/&gt;</description>
			<pubDate>Sat, 19 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=MDVSA-2008:149</feedburner:origLink></item>

		
		<item>
			<title>High - VU#289235 -  BlackBerry Attachment Service PDF distiller vulnerable to arbitrary code execution</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139362/detail.php</link>
			<description>&amp;lt;div id=&amp;quot;vu&amp;quot; class=&amp;quot;vu&amp;quot; style=&amp;quot;clear:both;&amp;quot;&amp;gt;&amp;lt;H1&amp;gt;Vulnerability Note VU#289235&amp;lt;/H1&amp;gt;&amp;lt;H2&amp;gt;BlackBerry Attachment Service PDF distiller vulnerable to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139362" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=VU#289235</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3234 - sshd in OpenSSH 4 on Debian GNU/Linux, and the...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281341/detail.php</link>
			<description>sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence,...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281341" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3234</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3233 - Cross-site scripting (XSS) vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281342/detail.php</link>
			<description>Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281342" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3233</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3232 - Unspecified vulnerability in dotclear before...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281343/detail.php</link>
			<description>Unspecified vulnerability in dotclear before 1.2.8 has unknown impact and attack vectors related to a missing &amp;quot;Images upload vulnerability fix.&amp;quot;&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281343" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3232</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3231 - xine allows user-assisted attackers to cause a...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281344/detail.php</link>
			<description>xine allows user-assisted attackers to cause a denial of service (application crash) via a crafted OGG file, as demonstrated by lol-ffplay.ogg.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281344" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3231</feedburner:origLink></item>

		
		<item>
			<title>Low - CVE-2008-3230 - The ffmpeg lavf demuxer allows user-assisted...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281345/detail.php</link>
			<description>The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281345" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3230</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3229 - Stack-based buffer overflow in op before...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281346/detail.php</link>
			<description>Stack-based buffer overflow in op before Changeset 563, when xauth support is enabled, allows local users to gain privileges via a long XAUTHORITY environment variable.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281346" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3229</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3228 - Joomla! before 1.5.4 does not configure...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281359/detail.php</link>
			<description>Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that &amp;quot;block common exploits&amp;quot; to SEF URLs, which has unknown impact and remote attack vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281359" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3228</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3227 - Unspecified vulnerability in Joomla! before...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281360/detail.php</link>
			<description>Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a &amp;quot;User Redirect Spam fix,&amp;quot; possibly an open redirect vulnerability.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281360" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3227</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3226 - The file caching implementation in Joomla!...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281361/detail.php</link>
			<description>The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281361" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3226</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3225 - Joomla! before 1.5.4 allows attackers to access...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281362/detail.php</link>
			<description>Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing &amp;quot;LDAP security fix.&amp;quot;&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281362" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3225</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3224 - Unspecified vulnerability in phpBB before 3.0.1...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281363/detail.php</link>
			<description>Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to &amp;quot;urls gone through redirect() being used within login_box().&amp;quot;&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281363" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3224</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3223 - SQL injection vulnerability in the Schema API...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281364/detail.php</link>
			<description>SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to &amp;quot;an inappropriate placeholder for...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281364" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3223</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3222 - Session fixation vulnerability in Drupal 5.x...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281365/detail.php</link>
			<description>Session fixation vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3, when contributed modules &amp;quot;terminate the current request during a login event,&amp;quot; allows remote attackers to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281365" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3222</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3221 - Cross-site request forgery (CSRF) vulnerability...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281366/detail.php</link>
			<description>Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281366" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3221</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3220 - Cross-site request forgery (CSRF) vulnerability...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281367/detail.php</link>
			<description>Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281367" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3220</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3219 - The Drupal filter_xss_admin function in 5.x...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281368/detail.php</link>
			<description>The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not &amp;quot;prevent use of the object HTML tag in administrator input,&amp;quot; which has unknown impact and attack...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281368" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3219</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3218 - Multiple cross-site scripting (XSS)...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281371/detail.php</link>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms,...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281371" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3218</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3217 - PowerDNS Recursor before 3.1.6 does not always...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281372/detail.php</link>
			<description>PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning....&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281372" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3217</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3216 - The save function in br/prefmanager.d in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281373/detail.php</link>
			<description>The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a symlink attack.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281373" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3216</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3215 - libclamav/petite.c in ClamAV before 0.93.3...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281374/detail.php</link>
			<description>libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access.  NOTE: this issue exists...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281374" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3215</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3214 - dnsmasq 2.25 allows remote attackers to cause a...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281375/detail.php</link>
			<description>dnsmasq 2.25 allows remote attackers to cause a denial of service (1) renewing a non-existent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281375" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3214</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3213 - SQL injection vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139363/detail.php</link>
			<description>SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139363" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3213</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3212 - Multiple SQL injection vulnerabilities in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139364/detail.php</link>
			<description>Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139364" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3212</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3211 - Scripteen Free Image Hosting Script 1.2 and...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139365/detail.php</link>
			<description>Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139365" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3211</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3210 - rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139366/detail.php</link>
			<description>rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139366" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3210</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3209 - Heap-based buffer overflow in the OpenGifFile...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139367/detail.php</link>
			<description>Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139367" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3209</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3208 - Simple DNS Plus 4.1, 5.0, and possibly other...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139368/detail.php</link>
			<description>Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139368" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3208</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3207 - PHP remote file inclusion vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139369/detail.php</link>
			<description>PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139369" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3207</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3206 - SQL injection vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339139370/detail.php</link>
			<description>SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQL commands via the category parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339139370" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3206</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-2934 - Mozilla Firefox 3 before 3.0.1 on Mac OS X...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/339281376/detail.php</link>
			<description>Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/339281376" height="1" width="1"/&gt;</description>
			<pubDate>Fri, 18 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-2934</feedburner:origLink></item>

		
		<item>
			<title>High - USN-623-1 -  Firefox vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186444/detail.php</link>
			<description>A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu....&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186444" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=USN-623-1</feedburner:origLink></item>

		
		<item>
			<title>NA - SUN-239785 - Sun Alert 239785 Security Vulnerability in the System Management Agent (SMA) SNMP daemon (snmpd(1M))</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338772440/detail.php</link>
			<description>&amp;lt;div class=&amp;quot;product&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Product:&amp;lt;/b&amp;gt; Solaris 10 Operating System OpenSolaris&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;state&amp;quot;&amp;gt;&amp;lt;b&amp;gt;State:&amp;lt;/b&amp;gt;...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338772440" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=SUN-239785</feedburner:origLink></item>

		
		<item>
			<title>High - MDVSA-2008:148 - Updated Firefox packages fix vulnerabilities</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338555424/detail.php</link>
			<description>Problem Description:
 
 Security vulnerabilities have been discovered and corrected in the
 latest Mozilla Firefox program, version 2.0.0.16 (CVE-2008-2785,
 CVE-2008-2933).
 
 This update...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338555424" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=MDVSA-2008:148</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3205 - Directory traversal vulnerability in index.php...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186445/detail.php</link>
			<description>Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186445" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3205</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3204 - SQL injection vulnerability in tops_top.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186447/detail.php</link>
			<description>SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186447" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3204</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3203 - js/pages/pages_data.php in AuraCMS 2.2 through...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186449/detail.php</link>
			<description>js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186449" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3203</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3202 - Cross-site scripting (XSS) vulnerability in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186451/detail.php</link>
			<description>Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action.  NOTE:...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186451" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3202</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3201 - Multiple cross-site scripting (XSS)...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186454/detail.php</link>
			<description>Multiple cross-site scripting (XSS) vulnerabilities in index.php in Pagefusion 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) acct_fname and (2) acct_lname parameters...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186454" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3201</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3200 - SQL injection vulnerability in vlc_forum.php in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186456/detail.php</link>
			<description>SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186456" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3200</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3199 - Multiple unspecified vulnerabilities in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186458/detail.php</link>
			<description>Multiple unspecified vulnerabilities in ReSIProcate before 1.3.4 allow remote attackers to cause a denial of service (stack consumption) via unknown network traffic with a large...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186458" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3199</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3198 - Mozilla Firefox 3.x before 3.0.1 allows remote...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186459/detail.php</link>
			<description>Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page.  NOTE:...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186459" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3198</feedburner:origLink></item>

		
		<item>
			<title>Low - CVE-2008-2933 - Mozilla Firefox before 2.0.0.16, and 3.x before...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186465/detail.php</link>
			<description>Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets &amp;#039;|&amp;#039; (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186465" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-2933</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-2232 - The expand_template function in afuse.c in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186467/detail.php</link>
			<description>The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname.&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186467" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-2232</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-1666 - Unspecified vulnerability in HP Oracle for...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186468/detail.php</link>
			<description>Unspecified vulnerability in HP Oracle for OpenView (OfO) 8.1.7, 9.1.01, 9.2, 9.2.0, 10g, and 10gR2 has unknown impact and attack vectors, possibly related to the July 2008 Oracle Critical Patch...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186468" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-1666</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-1665 - Multiple unspecified vulnerabilities in HP...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/338186469/detail.php</link>
			<description>Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/338186469" height="1" width="1"/&gt;</description>
			<pubDate>Thu, 17 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-1665</feedburner:origLink></item>

		
		<item>
			<title>Low - VU#130923 -  Mozilla Firefox command line URI handling vulnerability</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337214953/detail.php</link>
			<description>&amp;lt;div id=&amp;quot;vu&amp;quot; class=&amp;quot;vu&amp;quot; style=&amp;quot;clear:both;&amp;quot;&amp;gt;&amp;lt;H1&amp;gt;Vulnerability Note VU#130923&amp;lt;/H1&amp;gt;&amp;lt;H2&amp;gt;Mozilla Firefox command line URI handling...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337214953" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=VU#130923</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0599-01 - Problem Description:

Updated seamonkey...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337365238/detail.php</link>
			<description>Problem Description:

Updated seamonkey packages that fix a security issue are now available for
Red Hat Enterprise Linux 2.1, 3, and 4.

This update has been rated as having critical security...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337365238" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0599-01</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0598-02 - Critical: firefox security update</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337365240/detail.php</link>
			<description>Problem Description:

An updated firefox package that fixes various security issues is now
available for Red Hat Enterprise Linux 4.

This update has been rated as having critical security...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337365240" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0598-02</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0597-01 - Problem Description:

Updated firefox...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337365243/detail.php</link>
			<description>Problem Description:

Updated firefox packages that fix various security issues are now available
for Red Hat Enterprise Linux 5.

This update has been rated as having critical security impact...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337365243" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0597-01</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0546-01 - Problem Description:

Updated PHP packages...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/336950375/detail.php</link>
			<description>Problem Description:

Updated PHP packages that fix several security issues are now available for
Red Hat Enterprise Linux 2.1.

This update has been rated as having moderate security impact...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/336950375" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0546-01</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0545-01 - Moderate: php security and bug fix update</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/336950376/detail.php</link>
			<description>Problem Description:

Updated php packages that fix several security issues and a bug are now
available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/336950376" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0545-01</feedburner:origLink></item>

		
		<item>
			<title>High - RHSA-2008:0544-01 - Problem Description:

Updated PHP packages...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/336950379/detail.php</link>
			<description>Problem Description:

Updated PHP packages that fix several security issues are now available for
Red Hat Enterprise Linux 3 and 5.

This update has been rated as having moderate security...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/336950379" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=RHSA-2008:0544-01</feedburner:origLink></item>

		
		<item>
			<title>Medium - DSA-1611 - afuse -- privilege escalation</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337600093/detail.php</link>
			<description>Anders Kaseorg discovered that afuse, an automounting file systemin user-space, did not properly escape meta characters in paths.This allowed a local attacker with read access to the filesystem...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337600093" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=DSA-1611</feedburner:origLink></item>

		
		<item>
			<title>Low - CVE-2008-3197 - Cross-site request forgery (CSRF) vulnerability...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337476857/detail.php</link>
			<description>Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the &amp;quot;Creating a...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337476857" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3197</feedburner:origLink></item>

		
		<item>
			<title>High - CVE-2008-3196 - skeleton.c in yacc does not properly handle...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337476858/detail.php</link>
			<description>skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337476858" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3196</feedburner:origLink></item>

		
		<item>
			<title>Medium - CVE-2008-3194 - Multiple directory traversal vulnerabilities in...</title>
			<link>http://feeds.security-database.com/~r/Last100Alerts/~3/337476860/detail.php</link>
			<description>Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the...&lt;img src="http://feeds.security-database.com/~r/Last100Alerts/~4/337476860" height="1" width="1"/&gt;</description>
			<pubDate>Wed, 16 Jul 2008 00:00:00 +0200</pubDate>
		<feedburner:origLink>http://www.security-database.com/detail.php?alert=CVE-2008-3194</feedburner:origLink></item>

				
	</channel>
</rss>
