<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CU*Secure</title>
	<atom:link href="http://www.cusecure.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cusecure.org</link>
	<description>Are You Safe?</description>
	<lastBuildDate>Wed, 16 May 2012 17:56:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>14 News, WFIE, Evansville, Henderson, OwensboroHave you gotten a call from an &#8230; &#8211; 14 News WFIE Evansville</title>
		<link>http://news.google.com/news/url?sa=t&#038;fd=R&#038;usg=AFQjCNEhJ3hDeoeb7wtovJ3qX3z3G5g_6g&#038;url=http://www.14news.com/story/18438005/have-you-gotten-a-call-from-your-bank-or-credit-union-saying-theres-a-problem-with-your-account</link>
		<comments>http://news.google.com/news/url?sa=t&#038;fd=R&#038;usg=AFQjCNEhJ3hDeoeb7wtovJ3qX3z3G5g_6g&#038;url=http://www.14news.com/story/18438005/have-you-gotten-a-call-from-your-bank-or-credit-union-saying-theres-a-problem-with-your-account#comments</comments>
		<pubDate>Wed, 16 May 2012 17:56:12 +0000</pubDate>
		<dc:creator>credit union phishing - Google News</dc:creator>
				<category><![CDATA[Google News]]></category>

		<guid isPermaLink="false">http://www.cusecure.org/?guid=faf79639bc85cab3379aa7af63149ec3</guid>
		<description><![CDATA[14 News, WFIE, Evansville, Henderson, OwensboroHave you gotten a call from an ...14 News WFIE Evansville&#34;It&#039;s lead us to believe it&#039;s a phishing scheme where people are randomly calling in our community,&#34; says Steve Bugg, Chief Market...]]></description>
			<content:encoded><![CDATA[<table border="0" cellpadding="2" cellspacing="7" style="vertical-align:top;"><tr><td width="80" align="center" valign="top"><font style="font-size:85%;font-family:arial,sans-serif"></font></td><td valign="top" class="j"><font style="font-size:85%;font-family:arial,sans-serif"><br /><div style="padding-top:0.8em;"><img alt="" height="1" width="1" /></div><div class="lh"><a href="http://news.google.com/news/url?sa=t&amp;fd=R&amp;usg=AFQjCNEhJ3hDeoeb7wtovJ3qX3z3G5g_6g&amp;url=http://www.14news.com/story/18438005/have-you-gotten-a-call-from-your-bank-or-credit-union-saying-theres-a-problem-with-your-account"><b>14 News, WFIE, Evansville, Henderson, OwensboroHave you gotten a call from an <b>...</b></b></a><br /><font size="-1"><b><font color="#6f6f6f">14 News WFIE Evansville</font></b></font><br /><font size="-1">&quot;It&#39;s lead us to believe it&#39;s a <b>phishing</b> scheme where people are randomly calling in our community,&quot; says Steve Bugg, Chief Marketing and Member Service Officer at Heritage Federal <b>Credit Union</b>. Just yesterday Heritage Federal <b>Credit Union</b> received <b>...</b></font><br /><font size="-1" class="p"></font><br /><font class="p" size="-1"><a class="p" href="http://news.google.com/news/more?pz=1&amp;ned=us&amp;ncl=dUoJ5Tclc8c8T3M"><nobr><b></b></nobr></a></font></div></font></td></tr></table>]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/16/14-news-wfie-evansville-henderson-owensborohave-you-gotten-a-call-from-an-14-news-wfie-evansville/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Consumer credit-score knowledge improves, says CFA</title>
		<link>http://www.cuna.org/newsnow/12/system051512-9.html</link>
		<comments>http://www.cuna.org/newsnow/12/system051512-9.html#comments</comments>
		<pubDate>Tue, 15 May 2012 23:40:46 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CU/System]]></category>
		<category><![CDATA[CUNA News]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/system051512-9.html</guid>
		<description><![CDATA[During the past year, consumers' knowledge about credit scores improved significantly, with more awareness about who collects information on which most scores are based, the importance of checking this information, what good scores are, how to raise th...]]></description>
			<content:encoded><![CDATA[During the past year, consumers' knowledge about credit scores improved significantly, with more awareness about who collects information on which most scores are based, the importance of checking this information, what good scores are, how to raise them and what service providers use these scores, according to a new study.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/consumer-credit-score-knowledge-improves-says-cfa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WOCCU at IRS hearing: Adjust FATCA definitions</title>
		<link>http://www.cuna.org/newsnow/12/system051512-8.html</link>
		<comments>http://www.cuna.org/newsnow/12/system051512-8.html#comments</comments>
		<pubDate>Tue, 15 May 2012 22:51:39 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CU/System]]></category>
		<category><![CDATA[CUNA News]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/system051512-8.html</guid>
		<description><![CDATA[During a hearing convened by the Internal Revenue Service Tuesday, the World Council of Credit Unions urged the agency to consider changes to its proposed Foreign Account Tax Compliance Act regulations that would reduce undue regulatory burdens on cred...]]></description>
			<content:encoded><![CDATA[During a hearing convened by the Internal Revenue Service Tuesday, the World Council of Credit Unions urged the agency to consider changes to its proposed Foreign Account Tax Compliance Act regulations that would reduce undue regulatory burdens on credit unions in other countries.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/woccu-at-irs-hearing-adjust-fatca-definitions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wall Street Journal spotlights CU&#8217;s video-teller kiosks</title>
		<link>http://www.cuna.org/newsnow/12/system051512-7.html</link>
		<comments>http://www.cuna.org/newsnow/12/system051512-7.html#comments</comments>
		<pubDate>Tue, 15 May 2012 22:26:53 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CU/System]]></category>
		<category><![CDATA[CUNA News]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/system051512-7.html</guid>
		<description><![CDATA[Raleigh, N.C.-based Coastal FCU's newest technology--remote video teller kiosks--was in the national spotlight Tuesday in an article in The Wall Street Journal about the latest "gizmos" that enable financial institutions to let their members and custom...]]></description>
			<content:encoded><![CDATA[Raleigh, N.C.-based Coastal FCU's newest technology--remote video teller kiosks--was in the national spotlight Tuesday in an article in <I>The Wall Street Journal</I> about the latest "gizmos" that enable financial institutions to let their members and customers do-it-themselves.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/wall-street-journal-spotlights-cus-video-teller-kiosks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CUNA joint testimony seeks patent rule tweaks</title>
		<link>http://www.cuna.org/newsnow/12/wash051512-3.html</link>
		<comments>http://www.cuna.org/newsnow/12/wash051512-3.html#comments</comments>
		<pubDate>Tue, 15 May 2012 21:58:43 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CUNA News]]></category>
		<category><![CDATA[Washington]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/wash051512-3.html</guid>
		<description><![CDATA[CUNA and and other financial services groups are largely supportive of the U.S. Patent Office's proposed patent law changes, but the patent proposal could also use some additional tweaks, Eliot D. Williams of Baker Botts L.L.P., testifying on behalf of...]]></description>
			<content:encoded><![CDATA[CUNA and and other financial services groups are largely supportive of the U.S. Patent Office's proposed patent law changes, but the patent proposal could also use some additional tweaks, Eliot D. Williams of Baker Botts L.L.P., testifying on behalf of the Financial Services Roundtable, will tell members of the U.S. Congress today.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/cuna-joint-testimony-seeks-patent-rule-tweaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ohio CUs have 24% hike in MBL originations</title>
		<link>http://www.cuna.org/newsnow/12/system051512-6.html</link>
		<comments>http://www.cuna.org/newsnow/12/system051512-6.html#comments</comments>
		<pubDate>Tue, 15 May 2012 21:54:33 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CU/System]]></category>
		<category><![CDATA[CUNA News]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/system051512-6.html</guid>
		<description><![CDATA[Ohio credit unions loaned out $133.2 million in member business lending originations during 2011, an increase of 27.3% from 2010's originations totaling $107.7 million, according to the Ohio Credit Union League.]]></description>
			<content:encoded><![CDATA[Ohio credit unions loaned out $133.2 million in member business lending originations during 2011, an increase of 27.3% from 2010's originations totaling $107.7 million, according to the Ohio Credit Union League.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/ohio-cus-have-24-hike-in-mbl-originations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bill would extend NFIP to June 30</title>
		<link>http://www.cuna.org/newsnow/12/wash051512-2.html</link>
		<comments>http://www.cuna.org/newsnow/12/wash051512-2.html#comments</comments>
		<pubDate>Tue, 15 May 2012 21:50:03 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CUNA News]]></category>
		<category><![CDATA[Washington]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/wash051512-2.html</guid>
		<description><![CDATA[The National Flood Insurance Program would be extended until June 30 under legislation that is expected to be offered by Rep. Judy Biggert (R-Ill.) today.]]></description>
			<content:encoded><![CDATA[The National Flood Insurance Program would be extended until June 30 under legislation that is expected to be offered by Rep. Judy Biggert (R-Ill.) today.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/bill-would-extend-nfip-to-june-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCUA:  Study on trust in local FIs an opportunity</title>
		<link>http://www.cuna.org/newsnow/12/system051512-4.html</link>
		<comments>http://www.cuna.org/newsnow/12/system051512-4.html#comments</comments>
		<pubDate>Tue, 15 May 2012 21:16:49 +0000</pubDate>
		<dc:creator>CUNA News Now Headlines</dc:creator>
				<category><![CDATA[CU/System]]></category>
		<category><![CDATA[CUNA News]]></category>

		<guid isPermaLink="false">http://www.cuna.org/newsnow/12/system051512-4.html</guid>
		<description><![CDATA[A Penn State University study that indicates consumers have more trust in local financial institutions may present an opportunity for credit unions.]]></description>
			<content:encoded><![CDATA[A Penn State University study that indicates consumers have more trust in local financial institutions may present an opportunity for credit unions.]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/pcua-study-on-trust-in-local-fis-an-opportunity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-135: Vulnerability Summary for the Week of May 7, 2012</title>
		<link>http://www.us-cert.gov/cas/bulletins/SB12-135.html</link>
		<comments>http://www.us-cert.gov/cas/bulletins/SB12-135.html#comments</comments>
		<pubDate>Tue, 15 May 2012 18:00:00 +0000</pubDate>
		<dc:creator>US-CERT</dc:creator>
				<category><![CDATA[US-CERT Security Tips]]></category>

		<guid isPermaLink="false">http://www.us-cert.gov/cas/bulletins/SB12-135.html</guid>
		<description><![CDATA[
      



The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored b...]]></description>
			<content:encoded><![CDATA[
      <div><a name="top" id="top"></a>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" >NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" >CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" >Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0</p>
</li>
<li>
<p><strong>Medium</strong> - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9</p>
</li>
<li>
<p><strong>Low</strong> - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p></td>
</tr>
</table><br>
<a name="high" id="high"></a>
<div id="high_v">
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5" id="high_v_title" style="background-color:#D8000C;color:white;">High Vulnerabilities</th>
</tr>
<tr>
<th style="width:24%;">Primary<br>
Vendor -- Product</th>
<th style="width:44%;">Description</th>
<th style="width:8%;">Published</th>
<th style="width:4%;">CVSS Score</th>
<th style="width:10%;">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align:left;">adobe -- flash_cs3<br></td>
<td style="text-align:left;">Buffer overflow in Adobe Flash Professional before CS6 allows attackers to execute arbitrary code via unspecified vectors.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0778&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0778" >CVE-2012-0778</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- illustrator<br></td>
<td style="text-align:left;">Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0780&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0780" >CVE-2012-0780</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- illustrator<br></td>
<td style="text-align:left;">Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2023&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2023" >CVE-2012-2023</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- illustrator<br></td>
<td style="text-align:left;">Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2024&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2024" >CVE-2012-2024</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- illustrator<br></td>
<td style="text-align:left;">Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2025&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2025" >CVE-2012-2025</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- illustrator<br></td>
<td style="text-align:left;">Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2026&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2026" >CVE-2012-2026</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- photoshop<br></td>
<td style="text-align:left;">Use-after-free vulnerability in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2027&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2027" >CVE-2012-2027</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- photoshop<br></td>
<td style="text-align:left;">Buffer overflow in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2028&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2028" >CVE-2012-2028</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- shockwave_player<br></td>
<td style="text-align:left;">Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2029&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2029" >CVE-2012-2029</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- shockwave_player<br></td>
<td style="text-align:left;">Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2030&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2030" >CVE-2012-2030</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- shockwave_player<br></td>
<td style="text-align:left;">Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2031&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2031" >CVE-2012-2031</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- shockwave_player<br></td>
<td style="text-align:left;">Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2033.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2032&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2032" >CVE-2012-2032</a><br></td>
</tr>
<tr>
<td style="text-align:left;">adobe -- shockwave_player<br></td>
<td style="text-align:left;">Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2033&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2033" >CVE-2012-2033</a><br></td>
</tr>
<tr>
<td style="text-align:left;">apple -- mac_os_x<br></td>
<td style="text-align:left;">Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0662&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0662" >CVE-2012-0662</a><br></td>
</tr>
<tr>
<td style="text-align:left;">ffmpeg -- ffmpeg<br></td>
<td style="text-align:left;">Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4031&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4031" >CVE-2011-4031</a><br></td>
</tr>
<tr>
<td style="text-align:left;">hp -- performance_insight<br></td>
<td style="text-align:left;">SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2007&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2007" >CVE-2012-2007</a><br></td>
</tr>
<tr>
<td style="text-align:left;">hp -- performance_insight<br></td>
<td style="text-align:left;">Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privileges via unknown vectors.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2009&amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)" >9.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2009" >CVE-2012-2009</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- visio_viewer<br></td>
<td style="text-align:left;">Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka &quot;VSD File Format Memory Corruption Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0018&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0018" >CVE-2012-0018</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel File Format Memory Corruption Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0141&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0141" >CVE-2012-0141</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0142&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0142" >CVE-2012-0142</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel Memory Corruption Using Various Modified Bytes Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0143&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0143" >CVE-2012-0143</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- office<br></td>
<td style="text-align:left;">Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka &quot;TrueType Font Parsing Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0159&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0159" >CVE-2012-0159</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- .net_framework<br></td>
<td style="text-align:left;">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Serialization Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0160&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0160" >CVE-2012-0160</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- .net_framework<br></td>
<td style="text-align:left;">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Serialization Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0161&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0161" >CVE-2012-0161</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- .net_framework<br></td>
<td style="text-align:left;">Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Buffer Allocation Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0162&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0162" >CVE-2012-0162</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- office<br></td>
<td style="text-align:left;">GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka &quot;GDI+ Record Type Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0165&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0165" >CVE-2012-0165</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- office<br></td>
<td style="text-align:left;">Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka &quot;GDI+ Heap Overflow Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0167&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0167" >CVE-2012-0167</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- silverlight<br></td>
<td style="text-align:left;">Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka &quot;Silverlight Double-Free Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0176&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0176" >CVE-2012-0176</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- windows_7<br></td>
<td style="text-align:left;">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka &quot;Windows and Messages Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0180&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" >7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0180" >CVE-2012-0180</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- windows_7<br></td>
<td style="text-align:left;">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka &quot;Keyboard Layout File Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0181&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" >10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0181" >CVE-2012-0181</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- office<br></td>
<td style="text-align:left;">Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka &quot;RTF Mismatch Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0183&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0183" >CVE-2012-0183</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel SXLI Record Memory Corruption Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0184&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0184" >CVE-2012-0184</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka &quot;Excel MergeCells Record Heap Overflow Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0185&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0185" >CVE-2012-0185</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- excel<br></td>
<td style="text-align:left;">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel Series Record Parsing Type Mismatch Could Result in Remote Code Execution Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1847&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1847" >CVE-2012-1847</a><br></td>
</tr>
<tr>
<td style="text-align:left;">microsoft -- windows_7<br></td>
<td style="text-align:left;">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka &quot;Scrollbar Calculation Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1848&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1848" >CVE-2012-1848</a><br></td>
</tr>
<tr>
<td style="text-align:left;">oracle -- database_10g<br></td>
<td style="text-align:left;">The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka &quot;TNS Poison.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1675&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1675" >CVE-2012-1675</a><br></td>
</tr>
<tr>
<td style="text-align:left;">php -- php<br></td>
<td style="text-align:left;">sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;d&#039; case.</td>
<td style="text-align:center;">2012-05-11</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1823&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1823" >CVE-2012-1823</a><br></td>
</tr>
<tr>
<td style="text-align:left;">php -- php<br></td>
<td style="text-align:left;">sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;d&#039; case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</td>
<td style="text-align:center;">2012-05-11</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2311&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2311" >CVE-2012-2311</a><br></td>
</tr>
<tr>
<td style="text-align:left;">php -- php<br></td>
<td style="text-align:left;">php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.</td>
<td style="text-align:center;">2012-05-11</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2335&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" >7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2335" >CVE-2012-2335</a><br></td>
</tr>
<tr>
<td style="text-align:left;">wellintech -- kingview<br></td>
<td style="text-align:left;">WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1977&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)" >7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1977" >CVE-2012-1977</a><br></td>
</tr>
<tr>
<td style="text-align:left;">xnview -- xnview<br></td>
<td style="text-align:left;">Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0684&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0684" >CVE-2012-0684</a><br></td>
</tr>
<tr>
<td style="text-align:left;">xnview -- xnview<br></td>
<td style="text-align:left;">Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0685&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" >9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0685" >CVE-2012-0685</a><br></td>
</tr>
</tbody>
</table><br>
</div>
<a name="medium" id="medium"></a>
<div id="medium_v">
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5" id="medium_v_title" style="background-color:#FF6524;color:white;">Medium Vulnerabilities</th>
</tr>
<tr>
<th style="width:24%;">Primary<br>
Vendor -- Product</th>
<th style="width:44%;">Description</th>
<th style="width:8%;">Published</th>
<th style="width:4%;">CVSS Score</th>
<th style="width:10%;">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%" style="text-align: left;">N/A -- N/A<br></td>
<td style="text-align: left;">Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka &quot;Plug and Play (PnP) Configuration Manager Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0178&amp;vector=(AV:L/AC:L/Au:S/C:C/I:C/A:C)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0178" >CVE-2012-0178</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0649&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)" >6.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0649" >CVE-2012-0649</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0651&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" >5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0651" >CVE-2012-0651</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0652&amp;vector=(AV:L/AC:L/Au:N/C:C/I:N/A:N)" >4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0652" >CVE-2012-0652</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0654&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0654" >CVE-2012-0654</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0655&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" >6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0655" >CVE-2012-0655</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0656&amp;vector=(AV:L/AC:H/Au:N/C:C/I:C/A:C)" >6.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0656" >CVE-2012-0656</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0658&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0658" >CVE-2012-0658</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0659&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0659" >CVE-2012-0659</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0660&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0660" >CVE-2012-0660</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0661&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0661" >CVE-2012-0661</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- iphone_os<br></td>
<td style="text-align: left;">WebKit in Apple iOS before 5.1.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0672&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0672" >CVE-2012-0672</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- iphone_os<br></td>
<td style="text-align: left;">Safari in Apple iOS before 5.1.1 allows remote attackers to spoof the location bar&#039;s URL via a crafted web site.</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0674&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" >4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0674" >CVE-2012-0674</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0675&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" >4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0675" >CVE-2012-0675</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">apple -- safari<br></td>
<td style="text-align: left;">WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0676&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" >5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0676" >CVE-2012-0676</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">hp -- performance_insight<br></td>
<td style="text-align: left;">Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td style="text-align:center;">2012-05-09</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2008&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" >4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2008" >CVE-2012-2008</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">microsoft -- .net_framework<br></td>
<td style="text-align: left;">Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka &quot;.NET Framework Index Comparison Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0164&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" >5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0164" >CVE-2012-0164</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">microsoft -- windows_7<br></td>
<td style="text-align: left;">Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka &quot;TCP/IP Double Free Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0179&amp;vector=(AV:L/AC:L/Au:S/C:C/I:C/A:C)" >6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0179" >CVE-2012-0179</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">php -- php<br></td>
<td style="text-align: left;">Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.</td>
<td style="text-align:center;">2012-05-11</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2329&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" >5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2329" >CVE-2012-2329</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">php -- php<br></td>
<td style="text-align: left;">sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;T&#039; case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</td>
<td style="text-align:center;">2012-05-11</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2336&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" >5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2336" >CVE-2012-2336</a><br></td>
</tr>
</tbody>
</table><br>
</div>
<a name="low" id="low"></a>
<div id="low_v">
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5" id="low_v_title" style="background-color:#008AB8;color:white;">Low Vulnerabilities</th>
</tr>
<tr>
<th style="width:24%;">Primary<br>
Vendor -- Product</th>
<th style="width:44%;">Description</th>
<th style="width:8%;">Published</th>
<th style="width:4%;">CVSS Score</th>
<th style="width:10%;">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%" style="text-align: left;">apple -- mac_os_x<br></td>
<td style="text-align: left;">Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.</td>
<td style="text-align:center;">2012-05-10</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0657&amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:N)" >2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0657" >CVE-2012-0657</a><br></td>
</tr>
<tr>
<td width="20%" style="text-align: left;">microsoft -- windows_7<br></td>
<td style="text-align: left;">Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka &quot;Windows Firewall Bypass Vulnerability.&quot;</td>
<td style="text-align:center;">2012-05-08</td>
<td style="text-align:center; width: 5%;"><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0174&amp;vector=(AV:L/AC:L/Au:S/C:P/I:N/A:N)" >1.7</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0174" >CVE-2012-0174</a><br></td>
</tr>
</tbody>
</table></div>
</div>
    ]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/15/sb12-135-vulnerability-summary-for-the-week-of-may-7-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smartphone Security &#8211; WNYT</title>
		<link>http://news.google.com/news/url?sa=t&#038;fd=R&#038;usg=AFQjCNHITtrOvB0tqOAOg3qCNVH9QKi2qQ&#038;url=http://wnyt.com/article/stories/S2618053.shtml?cat=300</link>
		<comments>http://news.google.com/news/url?sa=t&#038;fd=R&#038;usg=AFQjCNHITtrOvB0tqOAOg3qCNVH9QKi2qQ&#038;url=http://wnyt.com/article/stories/S2618053.shtml?cat=300#comments</comments>
		<pubDate>Mon, 14 May 2012 22:25:04 +0000</pubDate>
		<dc:creator>credit union phishing - Google News</dc:creator>
				<category><![CDATA[Google News]]></category>

		<guid isPermaLink="false">http://www.cusecure.org/?guid=6103c145551391335f1f7a2d54e7bfe4</guid>
		<description><![CDATA[WNYTSmartphone SecurityWNYT“We&#039;re constantly evaluating what are the risks out there, and how do we mitigate them,” Rob Roemer Vice President of Information Systems with Capital Communications Federal Credit Union says. They have about 15000 mo...]]></description>
			<content:encoded><![CDATA[<table border="0" cellpadding="2" cellspacing="7" style="vertical-align:top;"><tr><td width="80" align="center" valign="top"><font style="font-size:85%;font-family:arial,sans-serif"><a href="http://news.google.com/news/url?sa=t&amp;fd=R&amp;usg=AFQjCNHITtrOvB0tqOAOg3qCNVH9QKi2qQ&amp;url=http://wnyt.com/article/stories/S2618053.shtml?cat=300"><img src="http://nt3.ggpht.com/news/tbn/b-OqwArg_9AwkM/6.jpg" alt="" border="1" width="80" height="80" /><br /><font size="-2">WNYT</font></a></font></td><td valign="top" class="j"><font style="font-size:85%;font-family:arial,sans-serif"><br /><div style="padding-top:0.8em;"><img alt="" height="1" width="1" /></div><div class="lh"><a href="http://news.google.com/news/url?sa=t&amp;fd=R&amp;usg=AFQjCNHITtrOvB0tqOAOg3qCNVH9QKi2qQ&amp;url=http://wnyt.com/article/stories/S2618053.shtml?cat=300"><b>Smartphone Security</b></a><br /><font size="-1"><b><font color="#6f6f6f">WNYT</font></b></font><br /><font size="-1">“We&#39;re constantly evaluating what are the risks out there, and how do we mitigate them,” Rob Roemer Vice President of Information Systems with Capital Communications Federal <b>Credit Union</b> says. They have about 15000 mobile app users and that number is <b>...</b></font><br /><font size="-1" class="p"></font><br /><font class="p" size="-1"><a class="p" href="http://news.google.com/news/more?pz=1&amp;ned=us&amp;ncl=dOZEOqZCxrU8KRM"><nobr><b></b></nobr></a></font></div></font></td></tr></table>]]></content:encoded>
			<wfw:commentRss>http://www.cusecure.org/2012/05/14/smartphone-security-wnyt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

