<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
    <channel>
        <title>IBM Internet Security Systems Internet Threat Information</title>
        <link>http://www.iss.net</link>
        <description><![CDATA[The latest Internet Threats, brought to you by XForce - the IBM Internet Security Systems' world-renowned security research and development team.]]></description>
        <language>en</language>
        <copyright>2007 IBM Internet Security Systems. All rights reserved worldwide.</copyright>

<item>
	<title>Microsoft Windows TrueType code execution</title>
	<link>http://www.iss.net/threats/449.html</link>
	<description>A vulnerability exists in code responsible for parsing TrueType fonts in Microsoft Windows' win32k.sys kernel module.</description>
	<pubDate>Tue, 08 May 2012 00:00:00 -0400</pubDate>
</item><item>
	<title>SAMBA RPC Memory Corruption and Code Execution</title>
	<link>http://www.iss.net/threats/448.html</link>
	<description>Samba could allow a remote attacker to execute arbitrary code on the system, caused by an error within the Network Data Representation (NDR) marshalling functionality. An attacker could exploit this vulnerability using a specially-crafted RPC call to execute arbitrary code on the system with root privileges.</description>
	<pubDate>Fri, 20 Apr 2012 00:00:00 -0400</pubDate>
</item><item>
	<title>Java AtomicReferenceArray Sandbox Evasion and Code Execution</title>
	<link>http://www.iss.net/threats/447.html</link>
	<description>The Java Runtime Environment (JRE) versions 7 update 2 and previous as well as version 6 update 30 and previous contain a vulnerability that can be exploited for sandbox evasion and remote code execution in the context of the current user.&amp;nbsp; The vulnerability is in the implementation of the AtomicReferenceArray class that allows type safety checks to be circumvented to bypass the Java sandbox.&amp;nbsp; Publicly exploits for this vulnerability are available and it is being actively exploited in the wild.&amp;nbsp; This vulnerability was fixed in the February 2012 update to the JRE and a April 6th update for Mac OS.&amp;nbsp; All Java installations should immediately apply this update if they have not done so already.
Note:In order for this signature to be detected the tuning parameter &quot;pam.content.jar.decompress&quot; must be enabled in order to analyze code inside JAR files.</description>
	<pubDate>Fri, 20 Apr 2012 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Windows ActiveX Control Code Execution</title>
	<link>http://www.iss.net/threats/445.html</link>
	<description>A privately disclosed vulnerability in the widely deployed Microsoft Common Controls ActiveX control (MSCOMCTL.OCX) can be exploited for remote code execution.</description>
	<pubDate>Tue, 10 Apr 2012 00:00:00 -0400</pubDate>
</item><item>
	<title>Adobe Flash Player for Chrome Sandbox Bypass Vulnerabilities</title>
	<link>http://www.iss.net/threats/446.html</link>
	<description>The sandbox feature of Adobe Flash Player for Chrome has two vulnerabilities which could result in privilege escalation.</description>
	<pubDate>Tue, 10 Apr 2012 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Windows Remote Desktop Protocol Code Execution</title>
	<link>http://www.iss.net/threats/444.html</link>
	<description>A vulnerability exists in the Microsoft Remote Desktop protocol (RDP) that allows for exploitation of the RDP/Terminal&amp;nbsp; Server service to achieve remote code execution.</description>
	<pubDate>Thu, 15 Mar 2012 00:00:00 -0400</pubDate>
</item>
   </channel>
</rss>
