<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>eEye Digital Security - Zero-Day Tracker</title><link>http://research.eeye.com/html/alerts/zeroday/index.html</link><description>Publicly disclosed software, hardware and Internet security vulnerabilities that do not have a manufacturer fix or patch.</description><language>en-us</language><copyright>Copyright 2006 eEye Digital Security</copyright><docs>http://blogs.law.harvard.edu/tech/rss</docs><pubDate>Tue, 9 Feb 2010 07:40:00 PST</pubDate><lastBuildDate>Tue, 9 Feb 2010 07:40:00 PST</lastBuildDate> <ttl>360</ttl><item><title>Excel Invalid Object</title><description>A remote code execution vulnerability exists within Microsoft Excel which may allow for a remote attacker to execute arbitrary code under the context of the logged in user.</description><link>http://research.eeye.com/html/alerts/zeroday/20090224.html</link><guid>http://research.eeye.com/html/alerts/zeroday/20090224.html</guid> <pubDate>Tue, 24 Feb 2009 12:00:00 PST</pubDate></item><item><title>Adobe PDF Buffer Overflow</title><description>A vulnerability exists within Adobe Acrobat that allows an attacker to execute arbitrary code on a victims machine if they view a malicious PDF document.</description><link>http://research.eeye.com/html/alerts/zeroday/20090212.html</link><guid>http://research.eeye.com/html/alerts/zeroday/20090212.html</guid> <pubDate>Thu, 19 Feb 2009 12:00:00 PST</pubDate></item><item><title>Creative Software AutoUpdate Engine ActiveX stack buffer overflow</title><description>The Creative Software AutoUpdate Engine ActiveX control is a component that provides automatic update capabilities to Creative Labs software. This ActiveX control is provided by the file CTSUEng.ocx. The Create Software AutoUpdate Engine ActiveX control is marked Safe For Scripting and Safe For Initialization, which means that a web page in Internet Explorer has the ability to interact with the control. This ActiveX control contains a stack buffer overflow in the CacheFolder property.  Exploit code for this vulnerability is publicly available.</description><link>http://research.eeye.com/html/alerts/zeroday/20080526.html</link><guid>http://research.eeye.com/html/alerts/zeroday/20080526.html</guid> <pubDate>Mon, 26 May 2008 12:00:00 PST</pubDate></item><item><title>Internet Connection Sharing DoS</title><description>A denial of service vulnerability exists within the Internet Connection Sharing service in Microsoft Windows XP.</description><link>http://research.eeye.com/html/alerts/zeroday/20061028.html</link><guid>http://research.eeye.com/html/alerts/zeroday/20061028.html</guid> <pubDate>Sat, 28 Oct 2006 12:00:00 PST</pubDate></item><item><title>RPC Memory Exhaustion</title><description>The three referenced exploits take advantage of an inherent problem in RPC, in which an attacker gets to supply the size of an output buffer, and RPC allocates the buffer and (more importantly) initializes it to zeroes, which causes the entire memory range to become committed.</description><link>http://research.eeye.com/html/alerts/zeroday/20051116.html</link><guid>http://research.eeye.com/html/alerts/zeroday/20051116.html</guid> <pubDate>Wed, 16 Nov 2005 12:00:00 PST</pubDate></item></channel></rss>