<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.91">
        <channel>
          <title>Check Point SmartDefense Service Advisories</title>
          <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          <description>The SmartDefense Service provides real-time updates and new attack protection capabilities for Application Intelligence, Web Intelligence, and Network defenses for various products.</description>
          <language>en-us</language>
          <copyright>http://www.checkpoint.com/copyright.html</copyright>
          <pubDate>Tue, 09 Feb 2010 11:17:35 PST</pubDate>
          <lastBuildDate>August 13, 2008 07:07:59 PDT</lastBuildDate>
          <webMaster>webmaster@checkpoint.com</webMaster>
		  
          <image>
            <title>Check Point Software Technologies Ltd.</title>
            <url>https://sc1.checkpoint.com/www/images/layout/duke/logo-checkpoint.gif</url>
            <link>http://www.checkpoint.com/defense/advisories/public/index.html</link>
          </image>

		  
          <item>
            <title>Update Protection against Microsoft Office Drawing Shape Group Properties Buffer Overflow Vulnerability (MS10-003)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-07-Febc.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in the way Microsoft Office handles specially crafted Excel files. Microsoft Excel is a popular spreadsheet application. A remote attacker could exploit this issue via a malformed Excel file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system.]]></description>
            <pubDate>Tue, 09 Feb 2010 02:30:41 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft PowerPoint File Path Handling Buffer Overflow Vulnerability (MS10-004)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-07-Febb.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote code execution vulnerability has been identified in Microsoft PowerPoint. Microsoft PowerPoint is a popular graphics software for preparing slides and presentations. A remote attacker could exploit this issue via a malformed PowerPoint file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system.]]></description>
            <pubDate>Sun, 07 Feb 2010 04:10:28 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Internet Explorer Response Redirect Information Disclosure Vulnerability</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-07-Feba.html</link>
            <severity>3</severity>
            <description><![CDATA[An information disclosure vulnerability has been reported in Microsoft Internet Explorer. A remote attacker could exploit this issue by convincing a user to open a maliciously crafted HTML file with Internet Explorer, which may allow the attacker to view data from a Web page in another Internet Explorer domain.]]></description>
            <pubDate>Mon, 08 Feb 2010 04:33:23 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft DirectShow AVI Parser Heap Overflow Vulnerability (MS10-013)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-07-Feb.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been discovered in the way that Microsoft DirectShow parses AVI media files. Microsoft DirectShow is used for streaming media on Microsoft Windows operating systems. It is used for high-quality capture and playback of multimedia streams. Audio Video Interleave (AVI) is a file type that is used with applications that capture, edit, and play back audio-video sequences. A remote attacker could exploit this issue via a malformed AVI file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system.]]></description>
            <pubDate>Mon, 08 Feb 2010 05:48:47 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Windows Shell Handler URL Validation Code Execution Vulnerability (MS10-007)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-03-Febc.html</link>
            <severity>4</severity>
            <description><![CDATA[A remote code execution vulnerability has been reported in the Microsoft Windows ShellExecute API function. The Windows user interface provides users with access to a wide variety of objects necessary for running applications and managing the operating system. ShellExecute is part of the Windows Shell application programming interface (API) functions. It performs an operation on a specified file. A remote attacker can exploit this vulnerability by convincing a user to visit a specially crafted Web page. Successful exploitation could result in execution of arbitrary code on the affected system.]]></description>
            <pubDate>Sat, 06 Feb 2010 23:48:58 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Active Directory and MIT Kerberos Null Pointer Dereference Vulnerability (MS10-014)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-03-Febb.html</link>
            <severity>3</severity>
            <description><![CDATA[In a Windows Active Directory environment in which an MIT Kerberos realm is trusted by an Active Directory domain, a user who is a member of the MIT Kerberos realm can be authenticated by Windows using the cross-realm trust established between the Active Directory and the MIT Kerberos realm.<br />A denial of service vulnerability exists in implementations of MIT Kerberos. The Kerberos protocol is used to mutually authenticate users and services on an open and unsecured network. It allows services to correctly identify the user of a Kerberos ticket without having to authenticate the user at the service. It does this by using shared secret keys. A remote attacker may exploit this vulnerability to create a denial of service condition, causing the affected system to stop responding.]]></description>
            <pubDate>Sun, 07 Feb 2010 00:00:35 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft SMB NTLM Authentication Lack of Entropy Vulnerability (MS10-012)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-03-Feba.html</link>
            <severity>3</severity>
            <description><![CDATA[An elevation of privilege vulnerability has been reported in the way that Microsoft Server Message Block (SMB) Protocol software handles authentication attempts. The SMB Protocol is a network file sharing protocol that is implemented in Microsoft Windows. A remote attacker may exploit this issue to gain access to the SMB service under the privileges of a specific authorized user.]]></description>
            <pubDate>Sun, 07 Feb 2010 01:37:42 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft SMB Server Null Pointer Denial of Service Vulnerability (MS10-012)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-03-Feb.html</link>
            <severity>3</severity>
            <description><![CDATA[A denial of service vulnerability has been reported in the Microsoft Windows Server Message Block (SMB) implementation. The SMB Protocol is a network file sharing protocol that is implemented in Microsoft Windows. A remote attacker may exploit this vulnerability to create a denial of service condition.]]></description>
            <pubDate>Tue, 09 Feb 2010 02:05:55 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Office PowerPoint OEPlaceholderAtom Arbitrary Array Indexing Vulnerabilities (MS10-004)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-02-Febc.html</link>
            <severity>3</severity>
            <description><![CDATA[Multiple&nbsp;remote code execution vulnerabilities have been identified in Microsoft PowerPoint. Microsoft PowerPoint is a popular graphics software for preparing slides and presentations. A remote attacker could exploit these issues via a malformed PowerPoint file. Successful exploitation of these vulnerabilities may allow execution of arbitrary code on a target system.]]></description>
            <pubDate>Wed, 03 Feb 2010 00:25:54 PST</pubDate>
          </item>

		  
          <item>
            <title>Update Protection against Microsoft Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability (MS10-004)</title>
            <link>http://www.checkpoint.com/defense/advisories/public/2010/cpai-02-Febb.html</link>
            <severity>3</severity>
            <description><![CDATA[A remote code execution vulnerability has been identified in Microsoft PowerPoint. Microsoft PowerPoint is a popular graphics software for preparing slides and presentations. A remote attacker could exploit this issue via a malformed PowerPoint file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system.]]></description>
            <pubDate>Wed, 03 Feb 2010 00:27:44 PST</pubDate>
          </item>


        </channel>
      </rss>
