<?xml version="1.0" encoding="Windows-1251"?><?xml-stylesheet href="/style/rss.css" type="text/css"?><rss version="2.0">	<channel>		<title>Securityvulns news channel</title>		<link>http://securityvulns.com/</link>		<language>en</language>		<description>securityvulns.com vulnerabilities newsline</description>		<category>security, computers, news</category>		<generator>3APA3A RSS generator v1.4.2</generator>		<webMaster>3APA3A@security.nnov.ru</webMaster>		<managingEditor>3APA3A@security.nnov.ru</managingEditor>		<lastBuildDate>Sun, 21 Mar 2010 00:14:00 GMT</lastBuildDate>		<copyright>2003-2007 Securityvulns, All rights reserved</copyright>		<image>			<url>http://securityvulns.com/images/banners/b88x31e.jpg</url>			<title>Securityvulns news channel</title>			<link>http://securityvulns.com/</link>		</image>			<item>				<title>libpng DoS</title>				<category>library</category>				<link>http://securityvulns.com/news/libpng/1003.html</link>				<description>Resources exhaustion on data decompression in png_decompress_chunk&#40;&#41;. Applications: libpng 1.2, libpng 1.0, libpng 1.4 (18.03.2010)</description>				<guid  isPermaLink="false">10699.libpng/1003.18.03.2010.</guid>				</item>			<item>				<title>QuickZip buffer overflow</title>				<category>local</category>				<link>http://securityvulns.com/news/QuickZip/BO.html</link>				<description>Buffer overflow on .zip files parsing. (18.03.2010)</description>				<guid  isPermaLink="false">10700.QuickZip/BO.18.03.2010.</guid>				</item>			<item>				<title>SAP MaxDB code execution</title>				<category>remote</category>				<link>http://securityvulns.com/news/SAP/MaxDB/1003.html</link>				<description>Buffer overflow on TCP/7210 request parsing. (18.03.2010)</description>				<guid  isPermaLink="false">10698.SAP/MaxDB/1003.18.03.2010.</guid>				</item>			<item>				<title>MediaCoder buffer overflow</title>				<category>local</category>				<link>http://securityvulns.com/news/MediaCoder/lst.html</link>				<description>Buffer overflow on .lst files parsing. Applications: MediaCoder 0.7 (18.03.2010)</description>				<guid  isPermaLink="false">10702.MediaCoder/lst.18.03.2010.</guid>				</item>			<item>				<title>httpdx DoS</title>				<category>remote</category>				<link>http://securityvulns.com/news/httpdx/DoS.html</link>				<description>Crash on malformed HTTP request. Applications: httpdx 1.5 (18.03.2010)</description>				<guid  isPermaLink="false">10701.httpdx/DoS.18.03.2010.</guid>				</item>			<item>				<title>Microsoft Virtual PC protection bypass</title>				<category>local</category>				<link>http://securityvulns.com/news/Microsoft/VirtualPC/MP.html</link>				<description>Invalid memory regions protection for memory &gt;2GB allows to bypass Windows memory protection techniques for guest system. Applications: Virtual Server 2005, Virtual PC 2007, Windows 7 (18.03.2010)</description>				<guid  isPermaLink="false">10697.Microsoft/VirtualPC/MP.18.03.2010.</guid>				</item>			<item>				<title>Windisc buffer overflow</title>				<category>local</category>				<link>http://securityvulns.com/news/Windisc/BO.html</link>				<description>Buffer overflow on Banzhaf &#40;.bnz&#41; files parsing. Applications: Windisc 1.3 (18.03.2010)</description>				<guid  isPermaLink="false">10696.Windisc/BO.18.03.2010.</guid>				</item>			<item>				<title>Miranda IM TLS encryption vulnerability</title>				<category>m-i-t-m</category>				<link>http://securityvulns.com/news/Miranda/IM/TLS.html</link>				<description>Under some conditions TLS is not used for Jabber server connection regradless of settings. Applications: Miranda IM 0.8 (18.03.2010)</description>				<guid  isPermaLink="false">10695.Miranda/IM/TLS.18.03.2010.</guid>				</item>			<item>				<title>Web applications security vulnerabilities summary &#40;PHP, ASP, JSP, CGI, Perl&#41;</title>				<category>remote</category>				<link>http://securityvulns.com/news/CGI/2010.03.18.html</link>				<description>PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. Applications: eFront 3.5, Nensor CMS 2.01, Quicksilver Forums 1.4, PowerDNS Administrator 1.1, QSF Portal 1.4, Sahana 0.6, SOFTSAURUS 2.01, Dojo Toolkit SDK 1.4 (18.03.2010)</description>				<guid  isPermaLink="false">10694.CGI/2010.03.18.18.03.2010.</guid>				</item>			<item>				<title>WebKit / Apple Safari / Google Chrome multiple security vulnerabilities, updated since 15.03.2010</title>				<category>library</category>				<link>http://securityvulns.com/news/WebKit/1003.html</link>				<description>Use-after-free, integer overflow, clickjacking. Applications: Safari 4.0, Chrome 3.0 (17.03.2010)</description>				<guid  isPermaLink="false">10692.WebKit/1003.17.03.2010.15.03.2010</guid>				</item>			<item>				<title>bind DNS server cache poisoning, updated since 01.12.2009</title>				<category>remote</category>				<link>http://securityvulns.com/news/bind/0912.html</link>				<description>It&#39;s possible to inject cache record during DNSSEC request processing. Applications: bind 9.4, bind 9.5, bind 9.6, bind 9.7 (17.03.2010)</description>				<guid  isPermaLink="false">10431.bind/0912.17.03.2010.01.12.2009</guid>				</item>		</channel>	</rss>
<!-- Cache Version: 1, Object ID: rss.EN.0.4.full(1), Request number: 2923, Cached -->
