<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
    <channel>
        <title>IBM Internet Security Systems Internet Threat Information</title>
        <link>http://www.iss.net</link>
        <description><![CDATA[The latest Internet Threats, brought to you by XForce - the IBM Internet Security Systems' world-renowned security research and development team.]]></description>
        <language>en</language>
        <copyright>2007 IBM Internet Security Systems. All rights reserved worldwide.</copyright>

<item>
	<title>Microsoft Windows Media Could Allow Remote Code Execution</title>
	<link>http://www.iss.net/threats/442.html</link>
	<description>A remote code execution vulnerability exists in the Windows multimedia library (winmm.dll) in the code responsible for handling of MIDI files.</description>
	<pubDate>Tue, 10 Jan 2012 00:00:00 -0500</pubDate>
</item><item>
	<title>Microsoft Vulnerability in ASP.NET Could Allow Denial of Service</title>
	<link>http://www.iss.net/threats/440.html</link>
	<description>Microsoft's ASP.NET is vulnerable to a denial of service, caused by insufficient randomization of hash data structures by the CaseInsensitiveHashProvider.getHashCode() function. </description>
	<pubDate>Wed, 04 Jan 2012 00:00:00 -0500</pubDate>
</item><item>
	<title>Multiple products telnetd buffer overflow</title>
	<link>http://www.iss.net/threats/441.html</link>
	<description>Multiple products are vulnerable to a buffer overflow, caused by improper bounds checking by the encrypt_keyid() function of telnetd.</description>
	<pubDate>Wed, 04 Jan 2012 00:00:00 -0500</pubDate>
</item><item>
	<title>Adobe Acrobat and Reader U3D code execution</title>
	<link>http://www.iss.net/threats/439.html</link>
	<description>Adobe Acrobat and Reader could allow a remote attacker to execute arbitrary code on the system, caused by a vulnerability when handling U3D data. </description>
	<pubDate>Thu, 08 Dec 2011 00:00:00 -0500</pubDate>
</item><item>
	<title>Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege</title>
	<link>http://www.iss.net/threats/438.html</link>
	<description>&amp;nbsp;There is a vulnerability in a Microsoft Windows component, the Win32k TrueType font parsing engine that could allow elevation of privilege.&amp;nbsp; This vulnerability is related to the Duqu malware.</description>
	<pubDate>Wed, 09 Nov 2011 00:00:00 -0500</pubDate>
</item><item>
	<title>Transport Layer Security (TLS) protocol SSL negotiation handshake denial of service</title>
	<link>http://www.iss.net/threats/437.html</link>
	<description>A recently released tool by THC exploits the fact that establishing SSL/TLS connections can require substantially more resources on the server than on the client.</description>
	<pubDate>Wed, 09 Nov 2011 00:00:00 -0500</pubDate>
</item>
   </channel>
</rss>
