<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.91">
        <channel>
          <title>Check Point Update Services Advisories</title>
          <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          <description>You are viewing a feed that contains frequently updated content. When you subscribe to a feed, it is added to the Common Feed List. Updated information from the feed is automatically downloaded to your computer and can be viewed in Internet Explorer and other programs.</description>
          <language>en-us</language>
          <copyright>http://www.checkpoint.com/copyright.html</copyright>
          <pubDate>Thu, 08 Sep 2011 05:02:34 PDT</pubDate>
          <lastBuildDate>February 27, 2013 11:43:51 PST</lastBuildDate>
          <webMaster>webmaster@checkpoint.com</webMaster>
		  
          <image>
            <title>Check Point Software Technologies Ltd.</title>
            <url>https://sc1.checkpoint.com/www/images/layout/duke/logo-checkpoint.gif</url>
            <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          </image>

		  
          <item>
            <title>Adobe ColdFusion Directory Traversal Information Disclosure (APSA13-03; CVE-2013-3336)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-16-may4.html</link>
            <severity>3</severity>
            <description><![CDATA[A directory traversal vulnerability has been reported in Adobe ColdFusion. The vulnerability is due to a design weakness in the ColdFusion application. A remote attacker may exploit this issue to retrieve arbitrary files from the target system via directory traversal. ]]></description>
            <pubDate>Sun, 19 May 2013 05:13:52 PDT</pubDate>
          </item>

		  
          <item>
            <title>HP Data Protector Create New Folder Buffer Overflow (CVE-2012-0124)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-07-may2.html</link>
            <severity>3</severity>
            <description><![CDATA[A stack buffer overflow vulnerability has been reported in HP Data Protector 5. The vulnerability is due to insecure handling of file names when creating new folders. An unauthenticated remote attacker can exploit this vulnerability by sending a malicious request to the vulnerable server. A successful attack may result in code execution. ]]></description>
            <pubDate>Sun, 19 May 2013 05:14:00 PDT</pubDate>
          </item>

		  
          <item>
            <title>ActiveFax (ActFax) 4.3 Client Importer Buffer Overflow</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-17-mar.html</link>
            <severity>3</severity>
            <description><![CDATA[The vulnerability is a stack based buffer overflow in the "Import Users from File" function, due to the insecure usage of strcpy while parsing the csv formatted file. The module creates a .exp file that must be imported with ActiveFax server. Successful exploitation would result in privilege escalation. ]]></description>
            <pubDate>Sun, 19 May 2013 05:14:07 PDT</pubDate>
          </item>

		  
          <item>
            <title>ACDSee FotoSlate PLP File id Parameter Overflow (CVE-2011-2595)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-28-feb3.html</link>
            <severity>4</severity>
            <description><![CDATA[A parameter overflow vulnerability exists in ACDSee FotoSlate. The vulnerability is due to boundary errors in FSEngine4.dll when processing the "id" attribute certain tags. A remote attacker could trigger this flaw by tricking a victim into opening a specially crafted malicious .plp file. ]]></description>
            <pubDate>Sun, 19 May 2013 05:14:13 PDT</pubDate>
          </item>

		  
          <item>
            <title>Preemptive Protection against Microsoft Lync Remote Code Execution (MS13-035; CVE-2013-1302)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may8.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in Microsoft Lync. The vulnerability is due the way Lync control attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing the user to accept an invitation to launch specially crafted content within a Lync or Communicator session. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.]]></description>
            <pubDate>Tue, 21 May 2013 04:25:51 PDT</pubDate>
          </item>

		  
          <item>
            <title>Microsoft .NET XML Digital Signature Spoofing (MS13-040; CVE-2013-1336)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may6.html</link>
            <severity>3</severity>
            <description><![CDATA[A spoofing vulnerability has been reported when the Microsoft .NET Framework fails to properly validate the signature of specially crafted XML files. Successful exploitation would allow an attacker to modify the contents of an XML file without invalidating the signature associated with the file.]]></description>
            <pubDate>Tue, 14 May 2013 03:56:45 PDT</pubDate>
          </item>

		  
          <item>
            <title>Internet Explorer Deleted Object Code Execution (MS13-037; CVE-2013-1312)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may5.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in Microsoft Internet Explorer. The vulnerability is due to an error in the way Internet Explorer accesses an object in memory that has been deleted. A remote attacker can exploit this issue by enticing a target victim to open a specially crafted web page. Successful exploitation could cause memory corruption in a way that would allow attackers to execute code on the target.]]></description>
            <pubDate>Tue, 14 May 2013 03:56:39 PDT</pubDate>
          </item>

		  
          <item>
            <title>Internet Explorer Layout Use-after-free Code Execution (MS13-037; CVE-2013-1310)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may4.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in Microsoft Internet Explorer. The vulnerability is due to an error in the way Internet Explorer accesses an object in memory that has been deleted. A remote attacker can exploit this issue by enticing a target victim to open a specially crafted web page. Successful exploitation could cause memory corruption in a way that would allow attackers to execute code on the target.]]></description>
            <pubDate>Tue, 14 May 2013 04:53:25 PDT</pubDate>
          </item>

		  
          <item>
            <title>Internet Explorer Initialization Error Use-after-free (MS13-037; CVE-2013-1307)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may3.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in Microsoft Internet Explorer. The vulnerability is due to an error in the way Internet Explorer accesses an object in memory that has been deleted. A remote attacker can exploit this issue by enticing a target victim to open a specially crafted web page. Successful exploitation could cause memory corruption in a way that would allow attackers to execute code on the target.]]></description>
            <pubDate>Tue, 14 May 2013 05:00:00 PDT</pubDate>
          </item>

		  
          <item>
            <title>Internet Explorer Deleted Object Use-after-free (MS13-037; CVE-2013-1311)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2013/cpai-14-may2.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in Microsoft Internet Explorer. The vulnerability is due to an error in the way Internet Explorer accesses an object in memory that has been deleted. A remote attacker can exploit this issue by enticing a target victim to open a specially crafted web page. Successful exploitation could cause memory corruption in a way that would allow attackers to execute code on the target.]]></description>
            <pubDate>Tue, 14 May 2013 03:56:22 PDT</pubDate>
          </item>


        </channel>
      </rss>
