<?xml version="1.0"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>oCERT Advisories</title>
    <link>http://www.ocert.org</link>
    <description>oCERT Advisories</description>
    <copyright>oCERT.org - Some rights reserved</copyright>
    <language>en</language>
    <webMaster>team@ocert.org (oCERT Team)</webMaster>
    <managingEditor>team@ocert.org (oCERT Team)</managingEditor>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <ttl>120</ttl>
    <image>
      <url>http://www.ocert.org/images/logo_bottom.png</url>
      <title>oCERT Logo</title>
      <link>http://www.ocert.org</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="http://www.ocert.org/rss/advisories.xml"/>

    <item>
      <title>#2012-001 multiple implementations denial-of-service via MurmurHash algorithm collision</title>
      <link>http://www.ocert.org/advisories/ocert-2012-001.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2012-001.html</guid>
      <pubDate>Fri, 23 Nov 2012 17:30:00 GMT</pubDate>
    </item>
    <item>
      <title>#2011-003 multiple implementations denial-of-service via hash algorithm collision</title>
      <link>http://www.ocert.org/advisories/ocert-2011-003.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2011-003.html</guid>
      <pubDate>Wed, 28 Dec 2011 18:10:00 GMT</pubDate>
    </item>
    <item>
      <title>#2011-002 libavcodec insufficient boundary check</title>
      <link>http://www.ocert.org/advisories/ocert-2011-002.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2011-002.html</guid>
      <pubDate>Wed, 10 Aug 2011 13:15:00 GMT</pubDate>
    </item>
    <item>
      <title>#2011-001 Chyrp input sanitization errors</title>
      <link>http://www.ocert.org/advisories/ocert-2011-001.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2011-001.html</guid>
      <pubDate>Wed, 13 Jul 2011 20:15:00 GMT</pubDate>
    </item>
    <item>
      <title>#2010-004 FFmpeg/libavcodec arbitrary offset dereference</title>
      <link>http://www.ocert.org/advisories/ocert-2010-004.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2010-004.html</guid>
      <pubDate>Fri, 28 Sep 2010 13:45:00 GMT</pubDate>
    </item>
    <item>
      <title>#2010-003 Free Simple CMS path sanitization errors</title>
      <link>http://www.ocert.org/advisories/ocert-2010-003.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2010-003.html</guid>
      <pubDate>Fri, 17 Sep 2010 10:20:00 GMT</pubDate>
    </item>
    <item>
      <title>#2010-002 Joomla input sanitization errors (XSS)</title>
      <link>http://www.ocert.org/advisories/ocert-2010-002.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2010-002.html</guid>
      <pubDate>Tue, 20 Jul 2010 21:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2010-001 multiple http client unexpected download filename vulnerability</title>
      <link>http://www.ocert.org/advisories/ocert-2010-001.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2010-001.html</guid>
      <pubDate>Mon, 17 May 2010 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-019 - Ganeti path sanitization errors</title>
      <link>http://www.ocert.org/advisories/ocert-2009-019.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-019.html</guid>
      <pubDate>Thu, 17 Dec 2009 16:23:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-017 - PHP multiple issues</title>
      <link>http://www.ocert.org/advisories/ocert-2009-017.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-017.html</guid>
      <pubDate>Mon, 30 Nov 2009 22:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-015 - KDE multiple issues</title>
      <link>http://www.ocert.org/advisories/ocert-2009-015.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-015.html</guid>
      <pubDate>Tue, 27 Oct 2009 21:10:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-016 - Poppler, xpdf integer overflow during heap allocation</title>
      <link>http://www.ocert.org/advisories/ocert-2009-016.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-016.html</guid>
      <pubDate>Tue, 21 Oct 2009 23:15:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-014 - Android denial-of-service issues</title>
      <link>http://www.ocert.org/advisories/ocert-2009-014.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-014.html</guid>
      <pubDate>Mon, 05 Oct 2009 13:45:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-013 - yTNEF/Evolution TNEF attachment decoder input sanitization errors</title>
      <link>http://www.ocert.org/advisories/ocert-2009-013.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-013.html</guid>
      <pubDate>Thu, 05 Sep 2009 12:45:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-011 - Android improper camera and audio permission verification</title>
      <link>http://www.ocert.org/advisories/ocert-2009-011.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-011.html</guid>
      <pubDate>Thu, 16 Jul 2009 15:25:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-010 - mimTeX and mathTeX buffer overflows and command injection</title>
      <link>http://www.ocert.org/advisories/ocert-2009-010.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-010.html</guid>
      <pubDate>Thu, 13 Jul 2009 23:45:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-012 - libtiff tools integer overflows</title>
      <link>http://www.ocert.org/advisories/ocert-2009-012.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-012.html</guid>
      <pubDate>Thu, 13 Jul 2009 19:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-008 - Dillo integer overflow</title>
      <link>http://www.ocert.org/advisories/ocert-2009-008.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-008.html</guid>
      <pubDate>Thu, 03 Jul 2009 21:05:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-007 - FCKeditor input sanitization errors</title>
      <link>http://www.ocert.org/advisories/ocert-2009-007.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-007.html</guid>
      <pubDate>Thu, 03 Jul 2009 16:45:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-009 - CamlImages integer overflows</title>
      <link>http://www.ocert.org/advisories/ocert-2009-009.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-009.html</guid>
      <pubDate>Thu, 02 Jul 2009 15:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-006 - Android improper package verification when using shared uids</title>
      <link>http://www.ocert.org/advisories/ocert-2009-006.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-006.html</guid>
      <pubDate>Fri, 22 May 2009 22:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-004 - AjaxTerm session id collision</title>
      <link>http://www.ocert.org/advisories/ocert-2009-004.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-004.html</guid>
      <pubDate>Mon, 11 May 2009 18:30:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-001 - Pango integer overflow in heap allocation size calculations</title>
      <link>http://www.ocert.org/advisories/ocert-2009-001.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-001.html</guid>
      <pubDate>Thu, 07 May 2009 18:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-003 - LittleCMS integer errors</title>
      <link>http://www.ocert.org/advisories/ocert-2009-003.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-003.html</guid>
      <pubDate>Fri, 20 Mar 2009 18:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-015 - glib and glib-predecessor heap overflows</title>
      <link>http://www.ocert.org/advisories/ocert-2008-015.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-015.html</guid>
      <pubDate>Wed, 12 Mar 2009 16:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2009-002 - OpenCORE insufficient bounds checking during MP3 decoding</title>
      <link>http://www.ocert.org/advisories/ocert-2009-002.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2009-002.html</guid>
      <pubDate>Wed, 07 Feb 2009 16:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-016 - multiple OpenSSL signature verification API misuse</title>
      <link>http://www.ocert.org/advisories/ocert-2008-016.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-016.html</guid>
      <pubDate>Wed, 07 Jan 2009 14:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-013 - MPlayer Real demuxer heap overflow</title>
      <link>http://www.ocert.org/advisories/ocert-2008-013.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-013.html</guid>
      <pubDate>Mon, 29 Sep 2008 16:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-012 - Horde, Popoon frameworks common input sanitization errors (XSS)</title>
      <link>http://www.ocert.org/advisories/ocert-2008-012.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-012.html</guid>
      <pubDate>Wed, 10 Sep 2008 17:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-014 - WordNet stack and heap overflows</title>
      <link>http://www.ocert.org/advisories/ocert-2008-014.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-014.html</guid>
      <pubDate>Mon, 01 Sep 2008 14:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-008 - multiple heap overflows in xine-lib</title>
      <link>http://www.ocert.org/advisories/ocert-2008-008.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-008.html</guid>
      <pubDate>Fri, 22 Aug 2008 18:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-009 - libxslt heap overflow</title>
      <link>http://www.ocert.org/advisories/ocert-2008-009.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-009.html</guid>
      <pubDate>Thu, 31 Jul 2008 15:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-007 - libpoppler uninitialized pointer</title>
      <link>http://www.ocert.org/advisories/ocert-2008-007.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-007.html</guid>
      <pubDate>Mon, 07 Jul 2008 15:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-006 - multiple SNMP implementations HMAC authentication spoofing</title>
      <link>http://www.ocert.org/advisories/ocert-2008-006.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-006.html</guid>
      <pubDate>Mon, 10 Jun 2008 01:10:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-004 - multiple speex implementations insufficient boundary checks</title>
      <link>http://www.ocert.org/advisories/ocert-2008-004.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-004.html</guid>
      <pubDate>Sat, 17 Apr 2008 08:33:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-003 - libpng zero-length chunks incorrect handling</title>
      <link>http://www.ocert.org/advisories/ocert-2008-003.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-003.html</guid>
      <pubDate>Sat, 12 Apr 2008 20:00:00 GMT</pubDate>
    </item>
    <item>
      <title>#2008-002 - libfishsound insufficient boundary checks</title>
      <link>http://www.ocert.org/advisories/ocert-2008-2.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-2.html</guid>
      <pubDate>Fri, 11 Apr 2008 13:17:43 GMT</pubDate>
    </item>
    <item>
      <title>#2008-001 - GnuPG memory corruption</title>
      <link>http://www.ocert.org/advisories/ocert-2008-1.html</link>
      <guid>http://www.ocert.org/advisories/ocert-2008-1.html</guid>
      <pubDate>Fri, 11 Apr 2008 13:17:43 GMT</pubDate>
    </item>
  </channel>
</rss>
