<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
      <title>NYS Division of Homeland Security &amp; Emergency Services - Office of Cyber Security</title>
      <link>http://www.dhses.ny.gov/ocs/advisories/</link>
      <description>Cyber Security Advisory RSS Feed</description>
      <language>en-us</language>
      <lastbuilddate>Wed, 16 May 2012 22:00:50 GMT</lastbuilddate>
      
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-036.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime that could allow remote code execution. Apple QuickTime is used to play media files on Microsoft Windows and Apple Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple QuickTime. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            <category>New Advisory</category>
            <guid>2012-036</guid>
            <pubdate>Wed, 16 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-035.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple&apos;s Mac OS X and Mac OS X Server that could allow remote code execution. Mac OS X is a desktop operating system for the Apple Mac. Mac OS X Server is a server operating system for the Apple Mac.
	 These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of OS X.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            <category>New Advisory</category>
            <guid>2012-035</guid>
            <pubdate>Mon, 14 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow For Code Execution (APSB12-13)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-034.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow for remote code execution.&amp;nbsp; Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-034</guid>
            <pubdate>Wed, 09 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (MS12-030)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-033.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office, specifically in Microsoft Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Microsoft Excel 2003
	 Microsoft Excel 2007
	 Microsoft ...]]></description>
            
            <guid>2012-033</guid>
            <pubdate>Wed, 09 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (MS12-031) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-032.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Visio Viewer has been identified that could allow for remote code execution. Microsoft Visio Viewer is a program used for viewing flowcharts and diagrams. &amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Visio Viewer 2010 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities: High 
	 Small government entities: High ...]]></description>
            
            <guid>2012-032</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in .NET Framework Could Allow Remote Code Execution (MS12-035)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-031.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework which could allow for remote code execution. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET application.
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-031</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (MS12-029)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Word.&amp;nbsp; This vulnerability can be exploited by opening a specially crafted Word document received as an e-mail attachment, or by visiting a website that is hosting a specially crafted Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. &amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Microsoft Office 2003 
	 Microsoft Office 2007 
	 Microsoft Office 2008 for Mac ...]]></description>
            
            <guid>2012-030</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (MS12-034)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-029.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&amp;nbsp;Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight.&amp;nbsp;Microsoft Office is Microsoft&apos;s business application suite. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media.
	 The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. Successful exploitation of this vulnerability could result in the attacker gaining the same privileges as ...]]></description>
            
            <guid>2012-029</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Input Vulnerability in PHP Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-028b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in PHP which could allow an attacker to remotely disclose source code and potentially execute arbitrary code. PHP is a programming language originally designed for use in web based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web based software applications.&amp;nbsp; Successful exploitation could result in an attacker viewing the PHP source code of a web based application or website and potentially executing arbitrary code.
	 Public exploit code is available in the form of a Metasploit module that is capable of triggering the vulnerability by delivering ...]]></description>
            
            <guid>2012-028 </guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Input Vulnerability in PHP Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-028.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in PHP which could allow an attacker to remotely disclose source code and potentially execute arbitrary code. PHP is a programming language originally designed for use in web based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web based software applications.&amp;nbsp; Successful exploitation could result in an attacker viewing the PHP source code of a web based application or website and potentially executing arbitrary code.
	 Public exploit code is available in the form of a Metasploit module that is capable of triggering the vulnerability by delivering ...]]></description>
            
            <guid>2012-028</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Adobe Flash Player Object Confusion Remote Code Execution Vulnerability </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-027.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. &amp;nbsp;Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. &amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. &amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-027</guid>
            <pubdate>Fri, 04 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Oracle Database Server 'TNS Listener' </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-026.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Oracle database server&apos;s &apos;TNS Listener&apos; service, which could allow&amp;nbsp;for multiple remote attacks against an Oracle database.&amp;nbsp;This vulnerability may be remotely exploitable without authentication. Oracle database&amp;nbsp;is an enterprise database server available for multiple operating systems.&amp;nbsp;&apos;TNS Listener&apos; is a component that routes connections from the client to the database server based on a naming convention (instance name). 
	 Successful exploitation of this vulnerability could result in an attacker altering the naming convention and routing the database information to the attackers system. 
	 SYSTEMS AFFECTED: 
	 
	 Oracle Database 11g Release 2, versions 11.2.0.2, 11.2.0.3 ...]]></description>
            
            <guid>2012-026</guid>
            <pubdate>Tue, 01 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-025</guid>
            <pubdate>Wed, 25 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2012-024</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Common Controls</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-023.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Common Controls that could allow an attacker to take complete control of a vulnerable system. Windows Common Controls are a set of interfaces that enable a user to interact with an application and are used by all supported versions of the Windows Operating System. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs, ...]]></description>
            
            <guid>2012-023</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-022.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. The vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET application. 
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2012-022</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Could Allow Remote Code Execution (MS12-024)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-021.cfm</link>
            <description><![CDATA[A new vulnerability has been reported in the Microsoft Windows Operating System. Exploitation may occur if a user opens a specially crafted, signed portable executable (PE) file. In order to exploit this vulnerability, an attacker could append specially crafted code to a digitally signed portable executable file without invalidating the signature and then have a user run or install the program. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2012-021</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-023)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-020.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 
	 Internet Explorer 9 
	 
	 RISK: 
 Government: 
	 
	 Large and medium ...]]></description>
            
            <guid>2012-020</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-019b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-019 - UPDATED</guid>
            <pubdate>Thu, 05 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-019.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-019</guid>
            <pubdate>Wed, 28 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Remote Desktop </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-016b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Windows Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems or cause a denial-of-service. RDP provides a graphical interface for users to establish a virtual session to other hosts on the network. Successfully exploiting this vulnerability would allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; This could also result in producing a denial-of-service condition on targeted systems.&amp;nbsp;
 	 Please note that Microsoft is strongly&amp;nbsp;encouraging entities to make a special priority of applying this particular update. Through our Managed Security ...]]></description>
            
            <guid>2012-016 - UPDATED</guid>
            <pubdate>Fri, 16 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Cisco ASA 5500 Series Products and Cisco ASA Modules for Catalyst 6500 Switches</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Cisco Adaptive Security Appliance (ASA) 5500 series appliances and ASA modules for Catalyst 6500 series switches. Cisco ASA products provide firewall, intrusion prevention, remote access, and other services. Successful exploitation could lead to the attacker taking control of a client machine or cause the appliance to reload, creating denial-of-service conditions.
	 SYSTEMS AFFECTED: 
	 
 Cisco ASA 5500 Series Appliances 
 Cisco Catalyst 6500 series ASA Service Modules
 
	 RISK: 
 Government: 
	 
 Large and medium government entities:&amp;nbsp;High 
	 Small government entities:&amp;nbsp;High 
	 
	 Businesses: 
	 
 Large and medium business entities:&amp;nbsp;High ...]]></description>
            
            <guid>2012-018</guid>
            <pubdate>Thu, 15 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-017.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and&amp;nbsp;SeaMonkey&amp;nbsp;applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla&amp;nbsp;SeaMonkey&amp;nbsp;is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or bypass security restrictions. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2012-017</guid>
            <pubdate>Wed, 14 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Remote Desktop </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-016.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Windows Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems or cause a denial-of-service. RDP provides a graphical interface for users to establish a virtual session to other hosts on the network. Successfully exploiting this vulnerability would allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; This could also result in producing a denial-of-service condition on targeted systems.&amp;nbsp;
 	 Please note that Microsoft is strongly&amp;nbsp;encouraging entities to make a special priority of applying this particular update. Through our Managed Security ...]]></description>
            
            <guid>2012-016</guid>
            <pubdate>Tue, 13 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. 
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely result in denial-of-service conditions. ...]]></description>
            
            <guid>2012-015</guid>
            <pubdate>Tue, 06 Mar 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely result in denial-of-service conditions. ...]]></description>
            
            <guid>2012-014</guid>
            <pubdate>Thu, 16 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in C Run-Time Library</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-013.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&#xe2;??s C Run-Time Library which could allow an attacker to take complete control of an affected system. The C Run-Time Library is a collection of support files used to implement basic functions such as input/output and memory management. The vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted media file hosted on a website or sent as an e-mail attachment.
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            
            <guid>2012-013</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in .NET Framework and Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-012.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media. The vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application.
 	 Successful exploitation could result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2012-012</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-011.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Windows that could allow for remote code execution due to improper validation of input by a Windows kernel-mode driver. The vulnerable driver controls window displays, screen output, and input from devices which it passes to applications. Successful exploitation of these vulnerabilities could result in the execution of arbitrary code with full administrative privileges resulting in full control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 	 SYSTEMS AFFECTED: 
 
 Windows XP
 Windows Server 2003
 Windows Vista ...]]></description>
            
            <guid>2012-011</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Viewer 2010</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-010.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Visio Viewer 2010, a program used for viewing flowcharts and diagrams. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
 	 SYSTEMS AFFECTED: 
 
 Microsoft Visio Viewer 2010 
 
 RISK: 
 Government: 
	 
	 Large and medium government entities:&amp;nbsp;High 
	 Small government entities:&amp;nbsp;High 
	 
	 Businesses: 
	 
	 Large and medium business entities:&amp;nbsp;High 
	 Small ...]]></description>
            
            <guid>2012-010</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-009.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Internet Explorer, Microsoft&apos;s web browser, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 	 SYSTEMS AFFECTED: 
 
 Internet Explorer 6
 Internet Explorer 7
 Internet Explorer 8 
 Internet Explorer 9 
 
 RISK: 
 Government: 
	 
	 Large and medium government ...]]></description>
            
            <guid>2012-009</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-008.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-008</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-007.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2012-007</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-006.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple&apos;s OS X and OS X Server that could allow remote code execution. OS X is a desktop operating system for the Apple Mac. OS X Server is a server operating system for the Apple Mac. 
	 These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, while using a vulnerable version of OS X.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2012-006</guid>
            <pubdate>Fri, 03 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-005.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-005</guid>
            <pubdate>Wed, 01 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Symantec pcAnywhere - Updated</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-004b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Symantec pcAnywhere which could allow remote code execution. pcAnywhere is a remote access software solution. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Symantec has released a statement indicating&amp;nbsp;that users should not use pcAnywhere or, at minimum, should block the ports used by pcAnywhere at the perimeter.&amp;nbsp;This is due to a breach in which the source code for ...]]></description>
            
            <guid>2012-004 -UPDATED</guid>
            <pubdate>Mon, 30 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Symantec pcAnywhere</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Symantec pcAnywhere which could allow remote code execution. pcAnywhere is a remote access software solution. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Symantec has released a statement indicating&amp;nbsp;that users should not use pcAnywhere or, at minimum, should block the ports used by pcAnywhere at the perimeter.&amp;nbsp;This is due to a breach in which the source code for ...]]></description>
            
            <guid>2012-004</guid>
            <pubdate>Thu, 26 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-003.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of&amp;nbsp;an affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create and edit&amp;nbsp;PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2012-003</guid>
            <pubdate>Wed, 11 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Could Allow Remote Code Execution (MS12-005)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-002.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in a component of Microsoft Windows.&amp;nbsp;Exploitation may occur if a user opens a specially crafted Microsoft Office file. Successful exploitation&amp;nbsp;will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP
	 Microsoft Vista
	 Microsoft Windows 7
	 Microsoft Windows Server 2003
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government:
	 
	 Large and medium government entities: High
	 	 Small ...]]></description>
            
            <guid>2012-002</guid>
            <pubdate>Tue, 10 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Windows Media Could Allow Remote Code Execution (MS12-004)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-001.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Media.&amp;nbsp; One has been identified in the Microsoft Windows Media Player application and another in DirectShow, both of which could allow remote code execution. Windows Media Player is a media library application that is used for playing audio, video, and viewing images.&amp;nbsp; DirectShow is used for streaming media on Windows operating systems. It is a part of DirectX, which is a set of low level Application Programming Interfaces (APIs) used by Windows programs for multimedia support. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as ...]]></description>
            
            <guid>2012-001</guid>
            <pubdate>Tue, 10 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Reported in the .NET Framework (MS11-100)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-082.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been reported in the Microsoft .NET Framework, specifically in ASP.NET, that could allow remote code execution. ASP.NET allows developers to build dynamic web applications and web services. Successful exploitation of some of the vulnerabilities could result in an attacker gaining the same privileges as the targeted user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; One vulnerability will cause a Denial of Service condition.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft .NET Framework 1.1 
	 Microsoft .NET Framework 2.0 ...]]></description>
            
            <guid>2011-082</guid>
            <pubdate>Thu, 29 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-081.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. 
	 These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2011-081</guid>
            <pubdate>Tue, 20 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-072b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-072 - Updated</guid>
            <pubdate>Mon, 19 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Oracle JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-080.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could impede proper operations. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file.
	 Please note that this update is not part of the Oracle Quarterly Critical Patch Update.&amp;nbsp;&amp;nbsp;The last quarter update was in October 2011.&amp;nbsp;&amp;nbsp;The next update is scheduled for January 10, 2012. ...]]></description>
            
            <guid>2011-080</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-079.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Excel, a spreadsheet application. This vulnerability could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or accessed via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 	 Microsoft Office 2003
	 Microsoft Office 2004 for Mac
	 
	 RISK: ...]]></description>
            
            <guid>2011-079</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows OLE</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-078.cfm</link>
            <description><![CDATA[A remote code execution vulnerability has been discovered in Microsoft Windows Object Linking and Embedding (OLE) technology that could allow attackers to take complete control of affected systems. OLE technology is a Windows protocol that provides a platform for applications to access and manipulate functionalities that are made available by other applications. This vulnerability can be exploited by opening a rich document file format containing a specially crafted OLE object. Successful exploitation could result in an attacker gaining the same privileges as the logged on user.&amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-078</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-077.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-077</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-076.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, by visiting a website that is hosting a specially crafted PowerPoint file, or by opening a legitimate PowerPoint file that is located in the same network directory as a specially crafted library file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2011-076</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-075.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office, which is Microsoft&apos;s business application suite, that could allow attackers to take complete control of affected systems. This vulnerability can be exploited by opening a specially crafted Word file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office for Mac 2011 
	 Microsoft ...]]></description>
            
            <guid>2011-075</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX Kill Bits</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-074.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. Exploiting these vulnerabilities could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted e-mail which is specifically crafted to take advantage of one or more of these vulnerabilities. Successful exploitation of any of these vulnerabilities could allow an attacker to gain the same privileges as the ...]]></description>
            
            <guid>2011-074</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-073.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Windows Media Center and Media Player applications that could allow remote code execution. Windows Media Center is a digital video recorder and media player. Windows Media Player is a media library application that is used for playing audio, video, and viewing images. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-073</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-067b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of this vulnerability could result in the escalation of privileges, the creation of denial-of-service conditions, or the execution of arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
	 December 13 - UPDATED OVERVIEW:
 Microsoft has released a patch for this vulnerability in bulletin MS11-087
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP 
	 Microsoft Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2003 
	 Microsoft Windows ...]]></description>
            
            <guid>2011-067 - Updated</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-072.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-072</guid>
            <pubdate>Tue, 06 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-071.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-071</guid>
            <pubdate>Mon, 14 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-070.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox and Thunderbird applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2011-070</guid>
            <pubdate>Wed, 09 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-069.cfm</link>
            <description><![CDATA[Multiple memory corruption vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-069</guid>
            <pubdate>Wed, 09 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in TCP/IP </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-068.cfm</link>
            <description><![CDATA[A vulnerability has been identified in the Microsoft Windows TCP/IP stack that could allow for remote code execution.&amp;nbsp;The Microsoft Windows TCP/IP stack is an implementation of the TCP/IP protocol, which is used by computer systems worldwide to communicate and exchange data.&amp;nbsp;Successful exploitation could allow attackers to run arbitrary code with kernel mode privileges. This could allow attackers to install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Windows Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government: 
	 
	 Large and ...]]></description>
            
            <guid>2011-068</guid>
            <pubdate>Tue, 08 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-067.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of this vulnerability could result in the escalation of privileges, the creation of denial-of-service conditions, or the execution of arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
	 It should be noted that there is currently no patch available for this vulnerability and the vulnerability is being actively exploited on the Internet with malware known as Duqu.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP 
	 Microsoft ...]]></description>
            
            <guid>2011-067</guid>
            <pubdate>Fri, 04 Nov 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-066.cfm</link>
            <description><![CDATA[A security bypass vulnerability has been discovered in Microsoft Outlook Web Access (OWA).&amp;nbsp;Microsoft OWA is a browser-based application that is used to access e-mail, calendars, contacts, tasks, documents, and other Outlook mailbox content remotely.&amp;nbsp;This vulnerability will allow an attacker to login to Outlook user accounts without supplying the user&apos;s authentication credentials. Successful exploitation will result in an attacker gaining unrestricted access to the user&apos;s OWA account. The attacker could then send, view, change, or delete user data such as e-mail, calendar appointments, or tasks, or create auto-forward rules that may allow an attacker to obtain copies of the e-mails. ...]]></description>
            
            <guid>2011-066</guid>
            <pubdate>Wed, 26 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X and Apple Safari</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-065.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple Mac OS X and Apple Safari that could allow remote code execution. Apple Mac OS X is a desktop operating system for the Apple Mac. Apple Safari is a web browser available for Mac OS X and Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple Mac OS X or Apple Safari.&amp;nbsp;Successful exploitation will result in an attacker gaining the same privileges as the logged on ...]]></description>
            
            <guid>2011-065</guid>
            <pubdate>Thu, 13 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS11-081) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-064.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
	 Internet Explorer 9
	 
	 RISK: 
 Government:
	 
	 Large and medium government entities: High
	 Small government ...]]></description>
            
            <guid>2011-064</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-063.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of any of these vulnerabilities could result in the escalation of privileges, create Denial of Service conditions, or execute arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Windows XP 
	 Microsoft Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2003 
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities: ...]]></description>
            
            <guid>2011-063</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the Microsoft .NET Framework and Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-062.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and used for streaming media. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application. 
	 Successful exploitation could result in an attacker gaining the same privileges as ...]]></description>
            
            <guid>2011-062</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-061.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on ...]]></description>
            
            <guid>2011-061</guid>
            <pubdate>Thu, 29 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-060.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product that includes e-mail, calendars, instant messaging, and document management. Successful exploitation of four of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. Failed exploit attempts of these four vulnerabilities may result in a denial of service condition. The remaining vulnerabilities could allow for information disclosure.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-060</guid>
            <pubdate>Tue, 27 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-059.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 There are ...]]></description>
            
            <guid>2011-059</guid>
            <pubdate>Wed, 21 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-058.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow attackers to take complete control of affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-058</guid>
            <pubdate>Tue, 13 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-056.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office SharePoint Server 2007 
	 Microsoft Office SharePoint ...]]></description>
            
            <guid>2011-056</guid>
            <pubdate>Tue, 13 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-047b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2011-047 - Updated</guid>
            <pubdate>Thu, 01 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Remote Desktop Protocol Worm "Morto"</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-055.cfm</link>
            <description><![CDATA[There are reports of a new worm circulating that takes advantage of open port 3389/TCP to compromise systems. No user interaction is required for the host to become compromised. &amp;nbsp;The worm has the capability to infect and subsequently control the impacted hosts.&amp;nbsp;Anti-virus vendors are developing signatures to detect the worm. 
	 SYSTEMS AFFECTED: 
	 
	 All supported versions of Windows Operating Systems 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities:&amp;nbsp;High
	 Small government entities:&amp;nbsp;High
	 
	 Businesses: 
	 
	 Large and medium business entities:&amp;nbsp;High
	 Small business entities:&amp;nbsp;High 
	 
	 Home users: High 
	 DESCRIPTION:
	 Over the past ...]]></description>
            
            <guid>2011-055</guid>
            <pubdate>Mon, 29 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-054.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools including a web browser and an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page.&amp;nbsp;Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges ...]]></description>
            
            <guid>2011-054</guid>
            <pubdate>Wed, 17 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in BlackBerry Enterprise </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-053.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the BlackBerry Mobile Data System (MDS) Connection Service and BlackBerry Messaging Agent that could allow remote code execution on the affected BlackBerry Enterprise Server. The MDS Connection Service is used to provide wireless application management across mobile devices. The BlackBerry Messaging Agent is used to provide wireless messaging services to mobile devices. Exploitation of these vulnerabilities could result in the attacker gaining the same privileges as the BlackBerry Enterprise Server service account. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2011-053</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-052.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-052</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-051.cfm</link>
            <description><![CDATA[Multiple memory corruption vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-051</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (MS11-060)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-050.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams.&amp;nbsp;These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an e-mail attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Visio 2003 
	 Microsoft Visio 2007 ...]]></description>
            
            <guid>2011-050</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in DNS Server Could Allow Remote Code Execution (MS11-058)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-049.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Windows DNS Server. The Domain Name System (DNS) is used to translate IP addresses into human-readable domain names. Microsoft includes their implementation of DNS with their Windows Server operating systems. Both vulnerabilities can be exploited by sending a specially crafted DNS query to the affected system. Successful exploitation of the first vulnerability could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Successful exploitation of the second vulnerability could result in ...]]></description>
            
            <guid>2011-049</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS11-057)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-048.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 
	 Internet Explorer 9 
	 
	 RISK: 
 Government: 
	 
	 Large and ...]]></description>
            
            <guid>2011-048</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-047.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2011-047</guid>
            <pubdate>Thu, 04 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-046.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a specially crafted file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the ...]]></description>
            
            <guid>2011-046</guid>
            <pubdate>Wed, 22 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-045.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page or if a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker ...]]></description>
            
            <guid>2011-045</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-044.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player, which could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or if a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-044</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-043.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow attackers to take complete control of affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-043</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-042.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows that could allow for remote code execution when handling specially crafted OpenType fonts (a cross-platform font file format developed jointly by Adobe and Microsoft). OpenType fonts are fonts that are embedded in documents, such as Microsoft Word, or used in web pages. The vulnerability can be exploited if a user visits a network share containing a specially crafted OpenType font. This vulnerability can also be exploited if a user views a web site that contains a link to a network share containing a specially crafted OpenType font. Successful exploitation of this ...]]></description>
            
            <guid>2011-042</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-041.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Excel, a spreadsheet application. These vulnerabilities could allow for remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 Microsoft ...]]></description>
            
            <guid>2011-041</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the Microsoft .NET Common Language Runtime (CLR) and in Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-040.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application. 
	 Successful exploitation could result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-040</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-039.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page.
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-039</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Vector Markup Language (VML)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-038.cfm</link>
            <description><![CDATA[A vulnerability has been discovered within Microsoft&apos;s web browser, Internet Explorer, that could allow for remote code execution.&amp;nbsp; Specifically, the vulnerability is in the way Vector Markup Language (VML) is processed by Internet Explorer. VML is an XML-based language used to produce and render vector graphics.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as the logged on user.&amp;nbsp; Depending on the privileges associated with the affected user, an attacker could then install programs, view, change, or delete data; or create accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet ...]]></description>
            
            <guid>2011-038</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-037.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Several of the vulnerabilities can also lead to information disclosure if successfully exploited. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 ...]]></description>
            
            <guid>2011-037</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in OLE Automation</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-036.cfm</link>
            <description><![CDATA[A remote code execution vulnerability has been discovered in Microsoft Windows Object Linking and Embedding (OLE) Automation. OLE Automation is a Windows protocol that provides a platform for applications to access and manipulate functionalities that are made available by other applications. This vulnerability can be exploited if a user views a specially crafted Windows Metafile (WMF) image on a web page or by opening a specially crafted WMF file as an e-mail attachment. 
	 Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the ...]]></description>
            
            <guid>2011-036</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft PowerPoint Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-033b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a website that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 June 14 - UPDATED OVERVIEW: 
 Microsoft has announced that the ...]]></description>
            
            <guid>2011-033 - Updated</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-035b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 One of ...]]></description>
            
            <guid>2011-035 - Updated</guid>
            <pubdate>Wed, 25 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-035.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 One of ...]]></description>
            
            <guid>2011-035</guid>
            <pubdate>Fri, 13 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in WINS Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-034.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Windows Internet Name Service (WINS) that could allow remote code execution. WINS is a service that translates computer names to numeric addresses which are needed for computers to communicate with each other. Successful exploitation of this vulnerability could allow an attacker to take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. Failed exploitation attempts may result in a denial-of-service condition. 
	 SYSTEMS AFFECTED: 
	 
	 Windows Server 2003
	 Windows Server 2008
	 
	 RISK:
	 Government:
	 
	 Large and medium government ...]]></description>
            
            <guid>2011-034</guid>
            <pubdate>Tue, 10 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft PowerPoint Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-033.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a website that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft ...]]></description>
            
            <guid>2011-033</guid>
            <pubdate>Tue, 10 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-032.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same ...]]></description>
            
            <guid>2011-032</guid>
            <pubdate>Mon, 02 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-031.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2011-031</guid>
            <pubdate>Fri, 22 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017c.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017 Updated</guid>
            <pubdate>Fri, 22 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017b.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017 Updated</guid>
            <pubdate>Mon, 18 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft HTML Help</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft HTML Help which could allow remote code execution. Microsoft HTML Help allows users to view HTML help files for Windows operating systems.&amp;nbsp;The vulnerability can be exploited if a user opens a specially crafted Microsoft HTML Help file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-030</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Fax Cover Page Editor</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-029.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Fax Cover Page Editor. Windows Fax Cover Page Editor enables users to create, modify, or view computer generated fax cover pages. Windows Fax Cover Page Editor is installed by default on Windows Vista Business Edition, Windows Vista Ultimate Edition, and in all supported editions of Windows 7. &amp;nbsp;This vulnerability can be exploited if a user views a malicious web page, views a specially crafted Windows Fax Cover Page, or opens an e-mail attachment containing a specially crafted image file designed to exploit the vulnerabilities. 
	 Successful exploitation will result in ...]]></description>
            
            <guid>2011-029</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in GDI+ </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-028.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Graphics Device Interface (GDI+). Microsoft GDI+ enables various applications to display images. Microsoft GDI+ is installed by default on all Microsoft Windows operating systems. This vulnerability can be exploited if a user views a malicious web page, views or previews a malicious e-mail message, or opens an e-mail attachment containing a specially crafted image file designed to exploit the vulnerability. 
	 Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the attacker could then install programs; ...]]></description>
            
            <guid>2011-028</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in JScript and VBScript Scripting Engines</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-027.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft JScript and VBScritping scripting engines. Jscript and VBScript are scripting languages used to enhance the user experience when visiting web pages such as those that display animated content. This vulnerability can be exploited if a user visits a web page with specially crafted content designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-027</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the OpenType Compact Font Format (CFF) Driver </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-026.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows OpenType Compact Font Format driver that could allow for remote code execution. OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or Web pages. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2011-026</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file or a legitimate Microsoft Office file that&amp;nbsp;is located in the same network directory as&amp;nbsp;a malicious library file. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office ...]]></description>
            
            <guid>2011-025</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office ...]]></description>
            
            <guid>2011-024</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-023.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office 2007
	 Microsoft Office ...]]></description>
            
            <guid>2011-023</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-022.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a malicious web page while using a Web browser that supports XAML Browser Applications (XBAPs). XAML Browser Applications are applications designed to run in a web browser, utilizing portions of Web Services as well as rich-client (Windows Forms) technologies. 
	 The vulnerability could also allow an attacker to execute ...]]></description>
            
            <guid>2011-022</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX Kill Bits </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-021.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft products that utilize ActiveX controls. Exploiting these vulnerabilities could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted e-mail which is specifically crafted to take advantage of one or more of these vulnerabilities. Successful exploitation of any of these vulnerabilities could allow an attacker to gain the same privileges as the logged on ...]]></description>
            
            <guid>2011-021</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-020.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution. SMB is used to provide shared access to files, printers, serial ports, and for other miscellaneous communications between network devices. Successful exploitation of this vulnerability could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 
	 RISK:
 Government:
	 
	 Large and medium government entities: ...]]></description>
            
            <guid>2011-020</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Client</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-019.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Server Message Block (SMB) Client that could allow for remote code execution. SMB is used to provide shared access to files, printers, serial ports, and for other miscellaneous communication between network devices. These vulnerabilities could be exploited if an attacker hosts a website with a specially crafted Uniform Resource Identifier (URI) or by sending a specially crafted browser message to the victim machine. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user or cause a denial-of-service condition. Depending on the privileges ...]]></description>
            
            <guid>2011-019</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Several of the vulnerabilities can also lead to information disclosure if successfully exploited.
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
	 
	 RISK:
 Government: ...]]></description>
            
            <guid>2011-018</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft PowerPoint </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-006b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft PowerPoint, a program used for creating presentations. This vulnerability can be exploited by opening a specially crafted PowerPoint file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note that there is currently no patch available for this vulnerability.
	 UPDATED OVERVIEW:
 Microsoft has ...]]></description>
            
            <guid>2011-006 Updated</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office Excel </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-005b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
	 Please note that there are ...]]></description>
            
            <guid>2011-005 Updated </guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player - UPDATED</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-016b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player which could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment.Successful exploitation may cause the Adobe Flash Player application to crash and could also result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-016 - Updated</guid>
            <pubdate>Tue, 22 Mar 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-016.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player which could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment.Successful exploitation may cause the Adobe Flash Player application to crash and could also result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-016</guid>
            <pubdate>Tue, 15 Mar 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Media</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Windows Media technologies, specifically Windows Media Player, Windows Media Center, and DirectShow.&amp;nbsp; Windows Media Player and Windows Media Center are digital media applications used for playing audio, video, and viewing images. DirectShow is a component of Windows for streaming media and to perform various operations with media files. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-015</guid>
            <pubdate>Wed, 09 Mar 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits or is redirected to a web page, or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker ...]]></description>
            
            <guid>2011-014</guid>
            <pubdate>Thu, 03 Mar 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-013.cfm</link>
            <description><![CDATA[Thirteen security vulnerabilities have been identified in Adobe Flash Player. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the users experience when visiting web pages or reading e-mail messages. These vulnerabilities can be exploited if a user visits a malicious website or opens an e-mail containing Flash media designed to exploit these vulnerabilities. Successful exploitation of one of these vulnerabilities may result in an attacker gaining the same privileges as the logged on user. If the user is logged in with administrator privileges, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-013</guid>
            <pubdate>Wed, 09 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-012.cfm</link>
            <description><![CDATA[Twenty-one vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2011-012</guid>
            <pubdate>Wed, 09 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-011.cfm</link>
            <description><![CDATA[Twenty-nine vulnerabilities have been discovered in the Adobe Reader and Adobe Acrobat applications, which could allow an attacker to take complete control of an affected system. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            
            <guid>2011-011</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-010.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams. These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an e-mail attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Visio 2002
	 Microsoft Visio 2003
	 Microsoft ...]]></description>
            
            <guid>2011-010</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the OpenType Compact Font Format (CFF) Driver</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-009.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows OpenType Compact Font Format driver that could allow for remote code execution. OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or web pages. These vulnerabilities can be exploited if a user visits a specially crafted web page or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2011-009</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Information Services (IIS) FTP Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-008.cfm</link>
            <description><![CDATA[A buffer overrun vulnerability has been discovered in Microsoft Internet Information Services (IIS) when using the File Transfer Protocol (FTP) server component. IIS is a set of Internet-based services running on Microsoft Windows servers. FTP is a simple way to exchange files over the file transfer protocol.&amp;nbsp;An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Unsuccessful exploitation attempts may result in a denial of service.
	 SYSTEMS AFFECTED:
	 
	 Windows Vista - Microsoft FTP Service ...]]></description>
            
            <guid>2011-008</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-007.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
 
	 RISK:
 Government: 
	 
 Large and medium government entities: High
	 Small government entities: High ...]]></description>
            
            <guid>2011-007</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft PowerPoint </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-006.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft PowerPoint, a program used for creating presentations. This vulnerability can be exploited by opening a specially crafted PowerPoint file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note that there is currently no patch available for this vulnerability. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-006</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-005.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
	 Please note that there are ...]]></description>
            
            <guid>2011-005</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Novell GroupWise Internet Agent</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Novell GroupWise Internet Agent. Novell GroupWise is a collaborative software product, which includes e-mail, calendars, instant messaging and document management. The GroupWise Internet Agent (GWIA) is a server component that provides communication to other e-mail systems and conversion of e-mail messages to GroupWise format. Successful exploitation could allow an attacker to gain SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Unsuccessful exploitation attempts may result in a denial of service.
	 SYSTEMS AFFECTED: 
	 
 Novell GroupWise Internet Agent 
	 Novell ...]]></description>
            
            <guid>2011-004</guid>
            <pubdate>Wed, 26 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-003.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the BlackBerry Enterprise Server; not the BlackBerry mobile device. Exploitation of this vulnerability may occur when a BlackBerry smartphone user opens a specially crafted PDF file. This could occur by opening an e-mail attachment or clicking on a link in an e-mail or while browsing the Internet. Successful exploitation could result in an attacker gaining the same privileges as the Blackberry Attachment Service. Depending ...]]></description>
            
            <guid>2011-003</guid>
            <pubdate>Wed, 12 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Data Access Components</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-002.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Data Access Components which could allow an attacker to take complete control of an affected system. Microsoft Data Access Components (MDAC) is a collection of applications that make it easy for programs to access databases. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-002</guid>
            <pubdate>Wed, 12 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2010-108b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp;Failed exploit attempts may result in ...]]></description>
            
            <guid>2010-108 Updated</guid>
            <pubdate>Tue, 11 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Graphics Rendering Engine</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-001.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Graphics Rendering Engine, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user views a specially crafted thumbnail image.&amp;nbsp;In an e-mail or web-based attack scenario, exploitation may occur if a user opens or previews a document containing a specially crafted thumbnail image received as an e-mail attachment or hosted on a website. Alternatively, an attacker can place the specially crafted thumbnail image on a network share and if a user navigates to the file location using Windows Explorer exploitation will occur. Successful ...]]></description>
            
            <guid>2011-001</guid>
            <pubdate>Wed, 05 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-108.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp;Failed exploit attempts may result in ...]]></description>
            
            <guid>2010-108</guid>
            <pubdate>Tue, 21 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-107.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of the BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the BlackBerry Enterprise Server; not the BlackBerry mobile device.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges&amp;nbsp;as the Blackberry Attachment Service. Depending on the privileges associated with the service, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
	 SYSTEMS AFFECTED: 
	 
	 BlackBerry ...]]></description>
            
            <guid>2010-107</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple vulnerabilities in Microsoft Office Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-106.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This file may be received as an e-mail attachment, or downloaded via the Web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2010-106</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Graphics Filters</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-105.cfm</link>
            <description><![CDATA[Seven vulnerabilities have been discovered in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities can be exploited by opening a specially crafted Microsoft Office document received as an e-mail attachment, or downloaded via the Web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions.
	 SYSTEMS AFFECTED:&amp;nbsp;
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 Microsoft ...]]></description>
            
            <guid>2010-105</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the OpenType Font (OTF) Driver </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-104.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Microsoft Windows OpenType Font (OTF) driver that could allow for remote code execution. OpenType fonts are fonts that are embedded in documents or used in web pages. The vulnerabilities can be exploited if a user visits a network share that contains a specially crafted OpenType Font. These vulnerabilities are triggered by the Details and Preview panes in Windows Explorer. These vulnerabilities can also be exploited if a user&amp;nbsp;views a specially crafted OpenType font using a third-party web browser. In this scenario, the vulnerability could be triggered if a user views a web ...]]></description>
            
            <guid>2010-104</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-103.cfm</link>
            <description><![CDATA[Seven vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet ...]]></description>
            
            <guid>2010-103</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097 - Updated</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-102.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker ...]]></description>
            
            <guid>2010-102</guid>
            <pubdate>Fri, 10 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-100a.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted file and can be exploited via e-mail or through the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 UPDATED OVERVIEW:
Microsoft has released a patch which addresses the vulnerabilities in Microsoft Office 2008 for Mac.
	 SYSTEMS ...]]></description>
            
            <guid>2010-100 -  Updated</guid>
            <pubdate>Fri, 10 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-101.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2010-101</guid>
            <pubdate>Wed, 08 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095 - Updated</guid>
            <pubdate>Wed, 17 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-100.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted file and can be exploited via e-mail or through the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office 2004 for Mac
	 Microsoft Office 2007 ...]]></description>
            
            <guid>2010-100</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-099.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft ...]]></description>
            
            <guid>2010-099</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-098.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product that includes e-mail, calendars, instant messaging and document management. Successful exploitation of four of these vulnerabilities could result in an attacker gaining system level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. The remaining vulnerabilities could allow for information disclosure. Failed exploit attempts may result in a denial of service condition.
	 SYSTEMS AFFECTED:
	 
 Novell GroupWise ...]]></description>
            
            <guid>2010-098</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095 - Updated</guid>
            <pubdate>Fri, 05 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097 - Updated</guid>
            <pubdate>Thu, 04 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097</guid>
            <pubdate>Wed, 03 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-096.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page. Exploitation may also occur when a user opens a specially crafted Shockwave (SWF) file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2010-096</guid>
            <pubdate>Fri, 29 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-093b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a widely used multimedia application used to display animations and video when visiting websites. This vulnerability can be exploited by visiting a web page that contains a malicious Adobe Shockwave file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user within the scope of the application. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2010-093 - Updated</guid>
            <pubdate>Fri, 29 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095</guid>
            <pubdate>Thu, 28 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-094b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered for Mozilla Firefox that could allow attackers to execute arbitrary code on affected systems. Mozilla Firefox is a web browser used to access the Internet. Exploitation can occur if a user visits a webpage designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition. ...]]></description>
            
            <guid>2010-094 Updated</guid>
            <pubdate>Thu, 28 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-094.cfm</link>
            <description><![CDATA[An vulnerability has been discovered for Mozilla Firefox that could allow attackers to execute arbitrary code on affected systems. Mozilla Firefox is a web browser used to access the Internet. Exploitation can occur if a user visits a webpage designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition. ...]]></description>
            
            <guid>2010-094</guid>
            <pubdate>Wed, 27 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-093.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a widely used multimedia application used to display animations and video when visiting websites. This vulnerability can be exploited by visiting a web page that contains a malicious Adobe Shockwave file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user within the scope of the application. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2010-093</guid>
            <pubdate>Thu, 21 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-092.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 Exploitation may occur if a user visits, or is redirected to, a web page or opens a malicious file that is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the ...]]></description>
            
            <guid>2010-092</guid>
            <pubdate>Wed, 20 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-091.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the Blackberry Enterprise Server; not the Blackberry mobile device. Successful exploitation may result in an attacker gaining complete control of the Blackberry Enterprise Server. Depending on the privileges associated with the service, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
 
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-091</guid>
            <pubdate>Thu, 14 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Windows Kernel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-090.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in the Microsoft Windows Kernel-Mode driver which could allow for privilege escalation. Utilizing these vulnerabilities, an attacker could escalate privileges and execute arbitrary code with kernel-level privileges resulting in full control of the affected machine.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 
 Microsoft has reported that this vulnerability is being actively exploited at this time as part of the Stuxnet worm.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 Windows Server 2008 R2 ...]]></description>
            
            <guid>2010-090</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in COM Validation in Windows Shell and WordPad</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-089.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Windows Shell and WordPad which could allow remote code execution.&amp;nbsp; Windows Shell provides users with access to objects necessary for running applications and managing the Windows Operating System.&amp;nbsp; WordPad is a word processor application that is included in Microsoft Windows. This vulnerability may be exploited by opening a malicious WordPad document received as an e-mail attachment, or by visiting a website that is hosting a malicious WordPad document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an ...]]></description>
            
            <guid>2010-089</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-088.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Windows Media Player. Windows Media Player is a digital media player and media library application that is used for playing audio, video, and viewing images. Exploitation can occur if a user visits a specially crafted website. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista ...]]></description>
            
            <guid>2010-088</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Common Control Library</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-087.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Windows Common Control Library that could allow an attacker to take complete control of a vulnerable system. The Windows Common Control Library is a set of interfaces that enables a user to interact with an application and is used by all supported versions of the Windows Operating System. Many popular third-party programs utilize this interface including web browsers such as Mozilla Firefox and Google Chrome.
&amp;nbsp;
This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same ...]]></description>
            
            <guid>2010-087</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-086.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Windows Office XP 
 Windows Office 2003
 Windows Office 2007 ...]]></description>
            
            <guid>2010-086</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Word</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-085.cfm</link>
            <description><![CDATA[Eleven vulnerabilities have been discovered in Microsoft Office Word. These vulnerabilities can be exploited by opening a malicious Word document received as an email attachment, or by visiting a website that is hosting a malicious Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
	 SYSTEMS AFFECTED:
	 
 Windows Office XP 
 Windows Office 2003
 Windows ...]]></description>
            
            <guid>2010-085</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-084.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a malicious web server running a specially crafted ASP.NET page. 
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2010-084</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows Embedded OpenType Engine</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-083.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Embedded OpenType (EOT) Font Engine that could allow for remote code execution. EOT Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or web pages. This vulnerability can be exploited if a user visits a specially crafted web page or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2010-083</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-082.cfm</link>
            <description><![CDATA[Ten vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Internet Explorer ...]]></description>
            
            <guid>2010-082</guid>
            <pubdate>Tue, 12 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player, Adobe Reader, Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077d.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 - Updated</guid>
            <pubdate>Wed, 06 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-074b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated ...]]></description>
            
            <guid>2010-074 - Updated</guid>
            <pubdate>Wed, 06 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Flash Player - Updated 9/21</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 Updated</guid>
            <pubdate>Tue, 21 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Flash Player - Updated 9/20</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 Updated</guid>
            <pubdate>Mon, 20 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Remote Procedure Call</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-081.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the way Microsoft Windows handles a specially crafted RPC response. Remote Procedure Call (RPC) is a protocol that is used to request a service from a program that is located on another computer that is on the same network.
	 This vulnerability may be exploited by sending a specially crafted RPC response. Successful exploitation will result in an attacker gaining the same privileges as the RPC client application. Depending on the privileges associated with the RPC client application, an attacker could then install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2010-081</guid>
            <pubdate>Wed, 15 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (MS10-063)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-080.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows and Microsoft Office which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; The vulnerability is caused when Windows or Office incorrectly parses specific font types.&amp;nbsp;This may be exploited if a user opens a specially crafted document or web page viewed in an application which supports embedded OpenType fonts. OpenType is a modern font format developed by Adobe and Microsoft to provide users with an accessible and advanced typographic toolset. Successful exploitation of this vulnerability will result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-080</guid>
            <pubdate>Wed, 15 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in MPEG-4 Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-079.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft MPEG-4 Codec that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress digital media content, such as a song or video. This vulnerability may be exploited if a user opens a specially crafted file, visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-079</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Print Spooler</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-078.cfm</link>
            <description><![CDATA[A vulnerability has been identified in the Microsoft Print Spooler service. The Print Spooler service is used for local and remote printing and is enabled on Windows systems by default. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Successful exploitation of this vulnerability could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. 
	 Microsoft has reported that the vulnerability is being actively exploited at this time. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-078</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player, Adobe Reader, and</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Here You Have - Email Worm</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-076.cfm</link>
            <description><![CDATA[A mass mailing worm has recently been propagating aggressively across the Internet with the subject lines &amp;quot;Here you have&amp;quot; or &amp;quot;Just For you&amp;quot;. The email includes a link disguised to look like a .PDF or a .WMV file, but is actually a link to a .SCR file that contains malicious code. Clicking on the malicious hyperlink will result in compromise of the affected machine and spread of the mass mailing worm to other computers.
	 In&amp;nbsp;addition to the media accounts of impacted businesses, we have received reports that several states that have been impacted by this mass mailing email worm. ...]]></description>
            
            <guid>2010-076</guid>
            <pubdate>Fri, 10 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-075.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla&amp;nbsp;SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla&amp;nbsp;SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. 
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-075</guid>
            <pubdate>Fri, 10 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-074.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated ...]]></description>
            
            <guid>2010-074</guid>
            <pubdate>Thu, 09 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-071b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2010-071 Updated</guid>
            <pubdate>Tue, 07 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-073.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. This vulnerability can be exploited&amp;nbsp;if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2010-073</guid>
            <pubdate>Tue, 31 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows Applications</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-072.cfm</link>
            <description><![CDATA[A new exploitation technique has been identified for a previously known vulnerability affecting Microsoft Windows applications which could allow an attacker to take complete control of an affected system. Microsoft Windows applications are any applications that run on the Microsoft Windows operating system. An attacker can exploit this vulnerability when a user runs a Windows application that does not load external libraries securely. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-072</guid>
            <pubdate>Fri, 27 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-071.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2010-071</guid>
            <pubdate>Thu, 26 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-070.cfm</link>
            <description><![CDATA[Adobe has provided an update which&amp;nbsp;addresses multiple vulnerabilities in Adobe Shockwave Player. These vulnerabilities could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page. Exploitation may also occur when a user opens a specially crafted Shockwave (SWF) file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could ...]]></description>
            
            <guid>2010-070</guid>
            <pubdate>Wed, 25 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-067b.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a website hosting malicious content or opens an email attachment containing Flash media designed to exploit these vulnerabilities.
	 Successful exploitation of five of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-067 Updated</guid>
            <pubdate>Fri, 20 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-056b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 There ...]]></description>
            
            <guid>2010-056 Updated</guid>
            <pubdate>Fri, 20 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-069.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2010-069</guid>
            <pubdate>Tue, 17 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Flash Media Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-068.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Media Server that could allow an attacker to take complete control of an application. Adobe Flash Media Server is an application server product which can stream rich content applications. Successful exploitation of one of these vulnerabilities could result in remote code execution. The attacker could then perform actions in the context of the application. The remaining vulnerabilities could allow for a denial-of-service condition.
 SYSTEMS AFFECTED: 
 
 Adobe Flash Media Server (FMS) 3.5.3 and earlier for Windows and UNIX
 Adobe Flash Media Server 3.0.5 and earlier versions for Windows and UNIX ...]]></description>
            
            <guid>2010-068</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-067.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a website hosting malicious content or opens an email attachment containing Flash media designed to exploit these vulnerabilities. 
	 Successful exploitation of five of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-067</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-066.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet ...]]></description>
            
            <guid>2010-066</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-065.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP and Vista systems. This vulnerability could allow remote code execution if a user opens a specially crafted Windows Movie Maker project file (.MSWMM). The file may be received as an email attachment, on removable media, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-065</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft MPEG Layer-3 Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-064.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft MPEG Layer-3 Codec for Microsoft DirectShow that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress digital media content, such as a song or video. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then ...]]></description>
            
            <guid>2010-064</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Cinepak Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-063.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Cinepak Codec, which is used to compress and decompress digital media files. Cinepak is the primary video codec application for Microsoft Video for Windows and is used to compress and decompress digital media files. This vulnerability could allow remote code execution if a user opens a specially crafted media file (e.g. an AVI file). This vulnerability can be exploited via an email attachment or through the web. Successful exploitation of this vulnerability could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2010-063</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-062.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Excel, a spreadsheet application. This vulnerability could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 	SYSTEMS AFFECTED: 
 	
 	 Microsoft Office XP
 	 Microsoft Office 2003 ...]]></description>
            
            <guid>2010-062</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Word</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-061.cfm</link>
            <description><![CDATA[Four vulnerabilities have been discovered in Microsoft Office Word. These vulnerabilities can be exploited by opening a malicious Word document received as an email attachment, or by visiting a website that is hosting a malicious Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
 	SYSTEMS AFFECTED: 
 	
 Microsoft Office XP 
 	 Microsoft ...]]></description>
            
            <guid>2010-061</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-060.cfm</link>
            <description><![CDATA[Three vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution or denial of service. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Successful exploitation of one of these vulnerabilities could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The other vulnerabilities will result in denial of service conditions.
	 SYSTEMS AFFECTED: 
	 
	 Windows XP
 Windows Server 2003 ...]]></description>
            
            <guid>2010-060</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the Microsoft .NET</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-059.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and used for streaming media. These vulnerabilities can be exploited if a user visits or is redirected to a malicious web page, runs a specially crafted Microsoft .NET application or runs a specially crafted Silverlight application. Successful exploitation could result in an attacker gaining the same ...]]></description>
            
            <guid>2010-059</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS10-051)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-058.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft XML Core Services which could allow remote code execution. Microsoft XML Core Services is installed by default on all Windows systems, and is used to enhance the user experience on web pages. This vulnerability may be exploited if a user visits, or is redirected to, a specifically crafted web page or opens a specially crafted HTML formatted email. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. If the user is logged in with administrative privileges, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-058</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SChannel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-057.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft SChannel which could allow an attacker to take complete control of a vulnerable system. Microsoft SChannel, or Secure Channel, implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. SSL and TLS are commonly used to implement secure communications for web browsing and other network services. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. If successfully exploited, the attacker could gain SYSTEM level privileges and install programs, view, change, or delete data, or create new accounts with full ...]]></description>
            
            <guid>2010-057</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-056.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2010-056</guid>
            <pubdate>Thu, 05 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053d.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 Updated</guid>
            <pubdate>Mon, 02 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-055.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Mozilla Firefox which could allow for remote code execution. Mozilla Firefox is a web browser used to access the Internet.
	 This vulnerability requires that a user visit or be redirected to a web page, or open a malicious file crafted to take advantage of this specific vulnerability. This vulnerability, if exploited, could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts ...]]></description>
            
            <guid>2010-055</guid>
            <pubdate>Mon, 26 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-054.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-054</guid>
            <pubdate>Wed, 21 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 - Updated</guid>
            <pubdate>Wed, 21 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 - Updated</guid>
            <pubdate>Tue, 20 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053</guid>
            <pubdate>Sat, 17 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-052.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise applications that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product which includes email, calendars, instant messaging and document management. Successful exploitation of two of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. The remaining vulnerabilities could allow for information disclosure. Failed exploit attempts may result in denial of service condition.
	 SYSTEMS AFFECTED: 
	 
	 Novell Groupwise ...]]></description>
            
            <guid>2010-052</guid>
            <pubdate>Fri, 16 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution (MS10-044)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-051.cfm</link>
            <description><![CDATA[Vulnerabilities have been discovered in Microsoft Office Access ActiveX control that could allow an attacker to take complete control of a vulnerable system. Microsoft Office Access is a database management system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted email, which are specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could allow an attacker to gain the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-051</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution (MS10-045)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-050.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Office Outlook. Microsoft Office Outlook is an email client.&amp;nbsp; Exploitation of this vulnerability requires that a user open an attachment in a specially crafted e-mail message with a vulnerable version of Microsoft Office Outlook. Successful exploitation of the vulnerability could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 2007 ...]]></description>
            
            <guid>2010-050</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046d.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040 - Updated</guid>
            <pubdate>Tue, 29 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-049.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the ...]]></description>
            
            <guid>2010-049</guid>
            <pubdate>Wed, 23 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Novell Netware</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-048.cfm</link>
            <description><![CDATA[This advisory only pertains to organizations that use Novell Netware for local area network services. Novell Netware provides services such as browsing or accessing NetWare directories, transferring or sharing files, and printing services. A vulnerability has been discovered in the Novell Netware Server Message Block (SMB) which could cause a buffer-overflow to occur. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. This vulnerability will allow an attacker to execute arbitrary code on the affected system. If successfully exploited, the attacker could gain kernel level privileges and install programs, ...]]></description>
            
            <guid>2010-048</guid>
            <pubdate>Thu, 17 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046c.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Wed, 16 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-047.cfm</link>
            <description><![CDATA[Thirty vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. It is used to enhance the user experience when visiting web pages or reading email messages. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a malicious website or opens an email attachment containing Flash media designed to exploit these vulnerabilities. 
	 Successful exploitation of twenty seven of these vulnerabilities could result in an attacker gaining ...]]></description>
            
            <guid>2010-047</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046b.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040 - Updated</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046</guid>
            <pubdate>Thu, 10 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in COM Validation in Microsoft Office Could Allow Remote Code Execution (MS10-036)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-045.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Office, Microsoft&apos;s business application suite. This vulnerability could allow remote code execution if a user opens a specially crafted Office document. The document may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 2007 Microsoft ...]]></description>
            
            <guid>2010-045</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-044.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 2007 Microsoft Office System ...]]></description>
            
            <guid>2010-044</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-043.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Many web design and development tools have built ActiveX support into their products, allowing developers to both create and make use of ActiveX controls in their programs. There are more than 1,000 existing ActiveX controls available for use today.
	 When vulnerabilities are discovered in ActiveX controls, attackers may use specially crafted web pages to exploit these vulnerabilities. Successful exploitation will result in ...]]></description>
            
            <guid>2010-043</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Media Decompression</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-042.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Windows that could allow a remote attacker to take complete control of an affected system. The vulnerabilities exist in the way Microsoft Windows handles media files. Exploitation can occur if a user visits a malicious web page or opens a malicious media file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-042</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer Could Allow Remote Code Execution (MS10-035)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-041.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-041</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040</guid>
            <pubdate>Mon, 07 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027c.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027 Updated</guid>
            <pubdate>Wed, 19 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-039.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player which could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted Shockwave (SWF) file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2010-039</guid>
            <pubdate>Wed, 12 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Visual Basic</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-038.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Visual Basic for Applications (VBA). VBA is used for developing client desktop packaged applications and integrating them with existing data and systems. Exploitation may occur if a user opens a specially crafted file which supports VBA and can be exploited via email or through the Web. This can be a Word document, an Excel spreadsheet, a PowerPoint presentation or any other type of document that uses VBA. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an ...]]></description>
            
            <guid>2010-038</guid>
            <pubdate>Tue, 11 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft Windows Server Vulnerabilities</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-037.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in the Microsoft SMTP (Simple Mail Transfer Protocol) service that could lead to the disclosure of information. Microsoft Windows SMTP service is a component that allows emails to be sent and received. These vulnerabilities could be exploited if an attacker creates a specially crafted query that is designed to exploit these vulnerabilities. This could allow an attacker to redirect network traffic which could lead to the unauthorized disclosure of information.
	 Please note that both of these vulnerabilities were fixed by the patches referenced in MS10-024, dated April 13, 2010, but were not disclosed ...]]></description>
            
            <guid>2010-037</guid>
            <pubdate>Thu, 06 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-019b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker and Microsoft Producer which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP systems. Microsoft Producer is a downloadable add-in component for Microsoft Office PowerPoint that can be used open and edit video files. Exploitation may occur if a user visits a web page or opens an email attachment which is crafted specifically to take advantage of this vulnerability. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-019 Updated</guid>
            <pubdate>Tue, 04 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in HP Operations Manager</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-036.cfm</link>
            <description><![CDATA[HP has issued a patch to remedy a vulnerability in HP Operations Manager. HP Operations Manager is a management console that correlates data from the network infrastructure. This vulnerability exists in an ActiveX control that will allow an attacker to download malicious files. ActiveX controls are small programs or animations that are downloaded or embedded in websites which will typically enhance functionality and user experience. This vulnerability can be exploited if a user visits or is redirected to a specially crafted webpage hosting a malicious file designed to take advantage of the vulnerability. Successful exploitation may result in an ...]]></description>
            
            <guid>2010-036</guid>
            <pubdate>Tue, 20 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027 Updated</guid>
            <pubdate>Thu, 15 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Cisco Security Desktop</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-035.cfm</link>
            <description><![CDATA[A vulnerability exists in an ActiveX control on Cisco Secure Desktop (CSD) that will allow an attacker to download malicious files.&amp;nbsp; CSD is a tool provided by Cisco to extend the security of Secure Socket Layer Virtual Private Networks (SSL VPN) to a user&apos;s work station. ActiveX controls are small programs or animations that are downloaded or embedded in Web pages which will typically enhance functionality and user experience. Secure Socket Layer (SSL) is a protocol used for transmitting documents securely via the Internet. SSL is the most widely used protocol for secure network communication. A Virtual Private Network ...]]></description>
            
            <guid>2010-035</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-033.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This document may be received as an email attachment, or downloaded via the Web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2010-033</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media Player 9 </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-032.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the ActiveX control for Microsoft Windows Media Player 9 which is utilized when accessing online media content such as music or a video. Microsoft Windows Media Player 9 is installed on all versions of Windows XP &amp;amp; 2000 by default. When vulnerabilities are discovered in the ActiveX controls, attackers may use specially crafted web pages to exploit these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2010-032</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-034.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams. These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an email attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 Microsoft Visio 2002 
	 Microsoft Visio ...]]></description>
            
            <guid>2010-034</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-031.cfm</link>
            <description><![CDATA[Multiple vulnerabilities discovered in the Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. These vulnerabilities can be exploited if a user opens a specially crafted file designed to take advantage of the vulnerabilities. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2010-031</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (MS10-026)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft MPEG Layer-3 codecs that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress a digital media file, such as a song or video. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs, view, ...]]></description>
            
            <guid>2010-030</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Client Could Allow Remote Code Execution (MS10-020)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-029.cfm</link>
            <description><![CDATA[Five vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Client that could allow for remote code execution or denial of service. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. These vulnerabilities could be exploited if an attacker hosts a specially crafted SMB server that is designed to exploit these vulnerabilities and then convinces a user to initiate an SMB connection with the attacker. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user or cause a denial-of-service ...]]></description>
            
            <guid>2010-029</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Could Allow Remote Code Execution (MS10-019)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-028.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Windows Authenticode Signature Verification function which could allow for remote code execution. Authenticode is a digital signature format that is used to determine the origin and integrity of software files. These vulnerabilities can be exploited when a user opens a specially crafted signed portable executable (PE)&#xc2;&#xa0; or cabinet file (CAB) which is a file that has been compressed, or reduced in size, to save storage space and allow faster transferring across a network. Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-028</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016 Updated</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027</guid>
            <pubdate>Fri, 09 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in VMware Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-026.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in VMware products that could allow an attacker to gain unauthorized access or take complete control of a vulnerable system. VMware products are used to create and/or run multiple virtual operating systems on a single device. Virtualization is becoming increasingly popular in order to minimize infrastructure costs. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user or specialized processes. Depending on the privileges associated with the user or specialized processes, an attacker could install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2010-026</guid>
            <pubdate>Fri, 09 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits or is redirected to a webpage or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-025</guid>
            <pubdate>Wed, 31 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player Could Allow for Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player. QuickTime Player is used to play multimedia files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits a malicious webpage or opens a malicious file, including an e-mail attachment, using a vulnerable version of QuickTime Player. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-024</guid>
            <pubdate>Wed, 31 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-023.cfm</link>
            <description><![CDATA[Ten vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Windows ...]]></description>
            
            <guid>2010-023</guid>
            <pubdate>Tue, 30 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 March 11- UPDATED OVERVIEW:
 Exploit code is publicly available. The exploit code has also been added ...]]></description>
            
            <guid>2010-021 Updated</guid>
            <pubdate>Tue, 30 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-022.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. The Mozilla applications (Firefox and SeaMonkey) utilize the same framework to display application specific information (e.g. webpages, emails, chats).
	 These vulnerabilities may be exploited if a user visits a webpage or opens a malicious file specifically crafted to take advantage of these ...]]></description>
            
            <guid>2010-022</guid>
            <pubdate>Wed, 24 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 March 11 - UPDATED OVERVIEW:
Exploit code is publicly available. The exploit code has also been added to ...]]></description>
            
            <guid>2010-021 Updated</guid>
            <pubdate>Thu, 11 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: At this time, Microsoft is aware of targeted attacks attempting to exploit this vulnerability.&amp;nbsp; ...]]></description>
            
            <guid>2010-021</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-020.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office Excel, Microsoft&apos;s spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel document. The document may be received as an email attachment, or downloaded via the Web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Excel 2002
	 Microsoft Excel 2003
	 Microsoft Excel 2007 ...]]></description>
            
            <guid>2010-020</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-019.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker and Microsoft Producer which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP systems. Microsoft Producer is a downloadable add-in component for Microsoft Office PowerPoint that can be used open and edit video files. Exploitation may occur if a user visits a web page or opens an email attachment which is crafted specifically to take advantage of this vulnerability. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-019</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Security Vulnerabilities found </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Apache Software Foundation&apos;s Apache HTTP Server. Apache HTTP Server is one of the most widely used web servers. Successful exploitation of one of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts. Failed attacks may result in denial-of-service conditions.
	 SYSTEMS AFFECTED:
	 
	 Apache Software Foundation Apache 2.2.14 and prior
	 
	 RISK:
	 Government:
	 
	 Large and medium government entities: High
	 Small government entities: High
	 
	 Businesses: 
	 
	 Large and medium business entities: High
	 Small business entities: ...]]></description>
            
            <guid>2010-018</guid>
            <pubdate>Mon, 08 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in IBM Lotus Domino</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-017.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in IBM Lotus Domino Web Access ActiveX control that could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are embedded in Web pages which will typically enhance functionality and user experience. Domino Web Access, also known as Lotus iNotes, is a browser-based web client for Lotus Domino. IBM Lotus Domino is a server product designed for collaborative working environments such as email, scheduling, and instant messaging. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged ...]]></description>
            
            <guid>2010-017</guid>
            <pubdate>Tue, 02 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016 Updated</guid>
            <pubdate>Tue, 02 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016</guid>
            <pubdate>Mon, 01 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox and Mozilla SeaMonkey applications which could allow remote code execution as well as cross domain scripting. Mozilla Firefox is a web browser used to access the Internet. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. The Mozilla applications (Firefox and SeaMonkey) utilize the same framework to display application specific information (e.g. Web pages, emails, chats).
	 These vulnerabilities may be exploited if a user visits a webpage or opens a malicious file specifically crafted to take advantage of these vulnerabilities. ...]]></description>
            
            <guid>2010-015</guid>
            <pubdate>Thu, 18 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player, Adobe AIR, Adobe Reader, and Adobe Acrobat. Adobe Flash Player is a multimedia application for Microsoft Windows, Mozilla, and Apple technologies used to enhance the user experience when visiting web sites. Adobe AIR is a cross-platform runtime for developing internet applications on the desktop. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files.
	 An attacker can exploit the Adobe Acrobat and Reader vulnerabilities by users opening a specially crafted PDF document. An attacker can ...]]></description>
            
            <guid>2010-014</guid>
            <pubdate>Wed, 17 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Security Update of ActiveX Kill Bits</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-013.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. ActiveX controls are small programs or animations that are downloaded or embedded in Web pages which will typically enhance functionality and user experience. Many web design and development tools have built ActiveX support into their products, allowing developers to both create and make use of ActiveX controls in their programs. There are more than 1,000 existing ActiveX controls available for use today.
	 SYSTEMS AFFECTED: 
	 
	 Windows 2000
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 
	 RISK:
	 Government:
	 
	 Large ...]]></description>
            
            <guid>2010-013</guid>
            <pubdate>Wed, 10 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-012.cfm</link>
            <description><![CDATA[Six new vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint presentation (.PPT or .PPS file) received as an email attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft ...]]></description>
            
            <guid>2010-012</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-011.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office which could allow an attacker to take complete control of an affected system. The vulnerability can be exploited by opening a specially crafted Office file received as an email attachment, or by visiting a web site that is hosting a specially crafted Office file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-011</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell Handler</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-010.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell Handler which could allow an attacker to take complete control of an affected system. The Windows Shell Handler is used to run applications and manage the Windows operating system. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2010-010</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft DirectShow</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-009.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft DirectShow that could allow a remote attacker to take complete control of a vulnerable system. DirectShow is a component of Windows for streaming media and to perform various operations with media files on Microsoft Windows operating systems. This vulnerability can be exploited when a user opens a specially crafted media file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-009</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-008.cfm</link>
            <description><![CDATA[Four vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution, denial of service, or privilege escalation. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Successful exploitation of these vulnerabilities could result in an attacker gaining complete control of the affected system, causing denial of service conditions, or privilege escalation. 
	 SYSTEMS AFFECTED: 
	 
	 Windows 2000
	 Windows XP
	 Windows Vista
	 Windows 7
	 Windows Server 2003
	 Windows Server 2008
 
	 RISK:
 Government:
 
 Large and medium government entities: High
	 Small ...]]></description>
            
            <guid>2010-008</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the Microsoft SMB Client Could Allow Remote Code Execution (MS10-006)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-007.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Server Message Block (SMB) client that could allow a remote attacker to take complete control of a vulnerable system. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts.
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-007</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-006.cfm</link>
            <description><![CDATA[Eight vulnerabilities have been discovered in Microsofts web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Internet Explorer 6
	Microsoft Internet ...]]></description>
            
            <guid>2010-006</guid>
            <pubdate>Thu, 21 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-003 Updated</guid>
            <pubdate>Thu, 21 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in CiscoWorks Internetwork Performance Monitor Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-005.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in CiscoWorks Internetwork Performance Monitor (IPM) which could allow remote code execution. CiscoWorks IPM is a troubleshooting component used within the management solutions for CiscoWorks products which are used to configure, administer and monitor networks. Successful exploitation could result in an attacker gaining the same privileges as the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed attacks will likely cause denial-of-service conditions. 
	 SYSTEMS AFFECTED: 
	 
	 CiscoWorks IPM 2.6 and earlier for Windows operating systems
	 
	 RISK: 
	 Government: ...]]></description>
            
            <guid>2010-005</guid>
            <pubdate>Wed, 20 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple iTunes and Quick Time Could Allow For Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple iTunes and Quick Time player. Apple iTunes and QuickTime are used to play media files on Microsoft Windows and MAC OS X platforms. This vulnerability can be exploited if a user views the malicious file on a webpage or opens a malicious file, including an email attachment, using a vulnerable version of Apple QuickTime Player or iTunes. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2010-004</guid>
            <pubdate>Tue, 19 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-003 Updated</guid>
            <pubdate>Tue, 19 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2010-003</guid>
            <pubdate>Fri, 15 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-002.cfm</link>
            <description><![CDATA[Multiple vulnerabilities discovered in the Adobe Acrobat and Adobe Reader applications could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-002</guid>
            <pubdate>Wed, 13 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2009-086c.cfm</link>
            <description><![CDATA[A vulnerability discovered in the Adobe Acrobat and Adobe Reader applications could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 It ...]]></description>
            
            <guid>2009-086 Updated</guid>
            <pubdate>Wed, 13 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-001.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Embedded OpenType Font Engine that could allow for remote code execution. Embedded OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or Web pages. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2010-001</guid>
            <pubdate>Tue, 12 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
  </channel>
  </rss>

