<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
    <channel>
        <title>IBM Internet Security Systems Internet Threat Information</title>
        <link>http://www.iss.net</link>
        <description><![CDATA[The latest Internet Threats, brought to you by XForce - the IBM Internet Security Systems' world-renowned security research and development team.]]></description>
        <language>en</language>
        <copyright>2007 IBM Internet Security Systems. All rights reserved worldwide.</copyright>

<item>
	<title>Oracle WebLogic Server Apache Connector Remote Code Execution</title>
	<link>http://www.iss.net/threats/299.html</link>
	<description>Oracle WebLogic Server (formerly known as BEA WebLogic Server) is vulnerable to a buffer overflow, which would cause a denial of service and potentially&amp;nbsp;remote code execution.</description>
	<pubDate>Fri,  1 Aug 2008 00:00:00 -0400</pubDate>
</item><item>
	<title>Multiple Vendors Vulnerable to DNS Cache Poisoning</title>
	<link>http://www.iss.net/threats/298.html</link>
	<description>Multiple vendor DNS protocol implementations could allow a remote attacker to poison the DNS cache.&amp;nbsp; Patches that resolve the vulnerability on the DNS may be rendered ineffective if the DNS is behind a NAT device that does not randomize ports.
Public exploit code was made available on July 24, 2008.&amp;nbsp; At the time of this update, neither X-Force nor IBM MSS has witness any active exploitation nor the integration of this exploit into any exploit toolkits.</description>
	<pubDate>Thu, 17 Jul 2008 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft ActiveX Snapshot Viewer for Microsoft Access RCE</title>
	<link>http://www.iss.net/threats/297.html</link>
	<description>Microsoft ActiveX Snapshot Viewer for Microsoft Access could allow a remote attacker to execute arbitrary code on the system.&amp;nbsp; Targeted exploitation was reported on July 7, but X-Force has been monitoring toolkit-related mass exploitation since July 10.&amp;nbsp; As of July 24, exploitation has continued to escalate.&amp;nbsp; See technical description for more details.</description>
	<pubDate>Mon,  7 Jul 2008 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Dynamics GP Multiple (4) Buffer&amp;nbsp;Overflows</title>
	<link>http://www.iss.net/threats/296.html</link>
	<description>The Microsoft Dynamics GP is vulnerable to&amp;nbsp;four heap and stack-based buffer overflows. A remote attacker could overflow the buffer and execute arbitrary code or gain control of the affected system by&amp;nbsp;sending malicious queries to the Distributed Process Server or Distributed Process Manager.</description>
	<pubDate>Mon, 30 Jun 2008 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Windows DirectX SAMI Code Execution</title>
	<link>http://www.iss.net/threats/295.html</link>
	<description>Microsoft Windows DirectX could allow a remote attacker to execute arbitrary code on the system.</description>
	<pubDate>Tue, 10 Jun 2008 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Windows MJPEG Codec Multiple Overflows</title>
	<link>http://www.iss.net/threats/294.html</link>
	<description>The Microsoft MJPEG codec is vulnerable to&amp;nbsp;multiple&amp;nbsp;stack-based buffer overflows when parsing specially crafted files. A remote attacker could overflow the buffer and execute arbitary code within the context of the user viewing the malicious file.</description>
	<pubDate>Tue, 10 Jun 2008 00:00:00 -0400</pubDate>
</item>
   </channel>
</rss>