<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
      <title>NYS Division of Homeland Security &amp; Emergency Services - Office of Cyber Security</title>
      <link>http://www.dhses.ny.gov/ocs/advisories/</link>
      <description>Cyber Security Advisory RSS Feed</description>
      <language>en-us</language>
      <lastbuilddate>Sun, 19 May 2013 16:21:02 GMT</lastbuilddate>
      
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-051.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox and Thunderbird applications, which could allow for remote code execution, information leakage, escalation of privileges and cross-site scripting (XSS). Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client.
 Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.
 
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2013-051</guid>
            <pubdate>Wed, 15 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe ColdFusion Allows Unauthorized File Access (APSA13-03)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-044b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe ColdFusion that could permit an unauthorized user to remotely retrieve files stored on a server.&amp;nbsp; Adobe ColdFusion is a widely distributed web application platform used for the development of rich internet applications.&amp;nbsp; Successful exploitation could result in an attacker gaining access to sensitive information.
 It should be noted that there is currently no patch available for this vulnerability and it is currently being exploited in the wild.
 May 15 - UPDATED OVERVIEW:
 Adobe has released a patch for this vulnerability. It is recommended to apply this patch immediately after appropriate testing.
SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2013-044 - Updated</guid>
            <pubdate>Wed, 15 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Word Could Allow Remote Code Execution (MS13-043)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-050.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Word that could result in remote code execution. Exploitation may occur if a user opens a specially crafted file in an affected version of Microsoft Word or Microsoft Word Viewer. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 
	 SYSTEMS AFFECTED: 
 
 Microsoft Office 2003 Service Pack 3
 Microsoft Word Viewer
 
 RISK: 
 Government:
 
 Large and medium government entities: High
 Small government entities: High
 
 Businesses:
 
 Large and ...]]></description>
            
            <guid>2013-050</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (MS13-042)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-049.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Publisher which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This file may be received as an email attachment, or downloaded via the web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2013-049</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS13-037)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-048.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 10
 Internet Explorer 9
 Internet Explorer 8
 Internet Explorer 7
 Internet Explorer 6
 
 RISK: 
 Government:
 
 Large and medium government entities: High ...]]></description>
            
            <guid>2013-048</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat Could Allow For Remote Code Execution (APSB13-15)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-047.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow an attacker to take control of the affected system. Adobe Reader is used for viewing, printing, signing and commenting on PDF documents and Adobe Acrobat is a family of application software developed to view, create, manipulate, print and manage files in PDF format. &amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2013-047</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-046.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow remote code execution. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user access. Failed exploit attempts will likely cause denial-of-service conditions. 
 SYSTEMS AFFECTED: 
 
 Adobe Flash Player ...]]></description>
            
            <guid>2013-046</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe ColdFusion Allows for Remote Code Execution (APSB13-13)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-045.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe ColdFusion that could allow remote code execution on a system running ColdFusion. Adobe ColdFusion is a widely distributed web application platform used for the development of rich internet applications.&amp;nbsp; Successful exploitation could result in the attacker running arbitrary code in the context of the application. Depending on the privileges associated with the application, the attacker could then install programs; view, change or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Adobe ColdFusion 10
 Adobe ColdFusion 9.0.2
 Adobe ColdFusion 9.0.1
 Adobe ColdFusion 9
 
 &amp;nbsp;RISK: 
 Government: ...]]></description>
            
            <guid>2013-045 </guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-042c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer version 8, which could allow remote code execution. Exploitation may occur if a user visits or is redirected to a specially crafted web page designed to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
 It should ...]]></description>
            
            <guid>2013-042 Updated</guid>
            <pubdate>Tue, 14 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe ColdFusion Allows Unauthorized File Access (APSA13-03)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-044.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe ColdFusion that could permit an unauthorized user to remotely retrieve files stored on a server.&amp;nbsp; Adobe ColdFusion is a widely distributed web application platform used for the development of rich internet applications.&amp;nbsp; Successful exploitation could result in an attacker gaining access to sensitive information.
 It should be noted that there is currently no patch available for this vulnerability and it is currently being exploited in the wild.
 SYSTEMS AFFECTED:
 
 Adobe ColdFusion 10
 Adobe ColdFusion 9.0.2
 Adobe ColdFusion 9.0.1
 Adobe ColdFusion 9
 
 RISK:
 Government:
 
 Large and medium government entities: High ...]]></description>
            
            <guid>2013-044</guid>
            <pubdate>Fri, 10 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-042b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer version 8, which could allow remote code execution. Exploitation may occur if a user visits or is redirected to a specially crafted web page designed to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
 It should ...]]></description>
            
            <guid>2013-042 Updated</guid>
            <pubdate>Thu, 09 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities In Adobe ColdFusion Could Allow Security Bypass</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-043.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe ColdFusion that could permit an unauthorized user to take complete control of an affected system.&amp;nbsp; Adobe ColdFusion is a widely distributed web application platform used for the development of rich internet applications.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as ColdFusion Administrator which will provide complete control of the affected server.
 SYSTEMS AFFECTED:
 
 Adobe ColdFusion 9.0.2
 Adobe ColdFusion 9.0.1
 Adobe ColdFusion 9.0
 Adobe ColdFusion 10
 
 RISK:
 Government:
 
 Large and medium government entities: High
 Small government entities: High
 
 Businesses:
 
 Large and medium business entities: ...]]></description>
            
            <guid>2013-043</guid>
            <pubdate>Tue, 07 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability In Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-042.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer version 8, which could allow remote code execution. Exploitation may occur if a user visits or is redirected to a specially crafted web page designed to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
 It should ...]]></description>
            
            <guid>2013-042</guid>
            <pubdate>Mon, 06 May 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability In Oracle Java Runtime Environment Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-041.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of this vulnerability does require limited user interaction and could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could execute arbitrary code in the context ...]]></description>
            
            <guid>2013-041</guid>
            <pubdate>Tue, 23 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (MS13-035)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-040.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft&apos;s HTML sanitization component used in Microsoft Office, SharePoint and Groove could allow elevation of privilege.&amp;nbsp; Microsoft&apos;s HTML sanitization component restricts the HTML to elements that can be safely displayed in a browser. Exploitation may occur if a user if a user visits a specially crafted website. &amp;nbsp;Successful exploitation could allow the attacker to read content or use the victim&apos;s identity to take actions on the targeted site or application.
 SYSTEMS AFFECTED:
 
 Microsoft InfoPath 2010
 Microsoft SharePoint Server 2010
 Microsoft Groove Server 2010
 Microsoft SharePoint Foundation 2010
 Microsoft Office Web Apps 2010
 
 RISK: ...]]></description>
            
            <guid>2013-040</guid>
            <pubdate>Tue, 09 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in MS Remote Desktop Client Could Allow Remote Code Execution (MS13-029)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-039.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Remote Desktop Client that could allow for remote code execution.&amp;nbsp; Remote desktop client is installed on Microsoft Windows operating systems by default, and is used to remotely log in to systems hosting the remote desktop service. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of these vulnerabilities could result in the attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; ...]]></description>
            
            <guid>2013-039</guid>
            <pubdate>Tue, 09 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS13-028) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-038.cfm</link>
            <description><![CDATA[Vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow for remote code execution. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 10
 Internet Explorer 9
 Internet Explorer 8 ...]]></description>
            
            <guid>2013-038</guid>
            <pubdate>Tue, 09 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Security Update available for Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-037.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow for remote code execution. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits, or is redirected to, a specially crafted web page. It may also be exploited when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2013-037</guid>
            <pubdate>Tue, 09 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Flash Player Vulnerabilities could allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-036.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow an attacker to crash and potentially allow an attacker to take control of the affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages.
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user access. Failed exploit attempts ...]]></description>
            
            <guid>2013-036</guid>
            <pubdate>Tue, 09 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-035.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow for remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
 Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2013-035</guid>
            <pubdate>Wed, 03 Apr 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Security Vulnerabilities in Google Chrome Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-034.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Google Chrome could allow for remote code execution in the context of the browser, cause denial-of-service conditions, and bypass security restrictions; other&amp;nbsp;attacks may also be possible. Google Chrome is a web browser used to access the Internet.
 Successful exploitation of these vulnerabilities may result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Google Chrome Prior to 26.0.1410.43 ...]]></description>
            
            <guid>2013-034</guid>
            <pubdate>Wed, 27 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Oracle Java SE Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-033.cfm</link>
            <description><![CDATA[Vulnerabilities have been discovered in Oracle Java SE that can lead to remote code execution. The Java Platform, Standard Edition (SE) is used to develop and deploy Java applications on desktops and servers. These vulnerabilities may be exploited if a user visits, or is redirected to a specifically crafted web page. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the Java application. Depending on the privileges associated with the application, an attacker could execute arbitrary code in the context of the application, and bypass security restrictions.
 SYSTEMS AFFECTED:
 
 Oracle Java 7 ...]]></description>
            
            <guid>2013-033</guid>
            <pubdate>Fri, 15 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X could allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-032.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple&apos;s Mac OS X and Mac OS X Server that could allow remote code execution. Mac OS X and OS X Server are operating systems for Apple computers.
 These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of OS X. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2013-032</guid>
            <pubdate>Fri, 15 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2807986)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-031.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Windows which could allow an attacker to gain system level access with a specially crafted USB device. Once the USB key is inserted, it makes the system execute specially crafted code at the Windows kernel level. An attacker could then install programs; view, change, or delete data; or create new accounts. 
SYSTEMS AFFECTED:

 Windows XP SP 3
 Windows XP x64 SP 2
 Windows Server 2003 and Itanium based systems SP 2
 Windows Server 2003 x64 SP 2
 Windows Vista, Vista x64 SP 2
 Windows Server 2008 32-bit, x64 and Itanium based systems ...]]></description>
            
            <guid>2013-031</guid>
            <pubdate>Wed, 13 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SharePoint Could Allow Elevation of Privilege (MS13-024)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-030.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been reported in Microsoft SharePoint Server and Microsoft SharePoint Foundation that could allow for elevation of privilege or denial of service attack. Depending on the privileges associated with the user, the attacker could install programs; view, change or delete data or create new accounts with full user rights. 
SYSTEMS AFFECTED:

 Microsoft SharePoint Server 2010
 Microsoft SharePoint Foundation 2010

RISK: 
 Government: 
 
 Large and medium government entities:&amp;nbsp;High
 Small government entities: High
 
 Businesses:
 
 Large and medium business entities:&amp;nbsp;High
 Small business entities:&amp;nbsp;High
 
 Home users:&amp;nbsp;Low
 DESCRIPTION:
There are a total of four vulnerabilities this advisory covers. ...]]></description>
            
            <guid>2013-030</guid>
            <pubdate>Wed, 13 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Adobe Flash Player Remote Code Execution Vulnerability (APSB13-09)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-029.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow an attacker to take control of the affected system. Adobe Flash Player is a multimedia application for multiple platforms. 
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user access. Failed exploit attempts will likely cause denial-of-service conditions. 
 SYSTEMS AFFECTED:
 
 Adobe Flash Player 11.6.602.171 and earlier versions for Windows and Macintosh ...]]></description>
            
            <guid>2013-029</guid>
            <pubdate>Tue, 12 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS13-021)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-028.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SYSTEM AFFECTED:

 Internet Explorer 10
 Internet Explorer 9
 Internet Explorer 8
 Internet Explorer 7
 Internet Explorer 6

RISK:
 Government:

 Large and medium government entities: High
 Small government entities: High

Businesses:

 Large and ...]]></description>
            
            <guid>2013-028</guid>
            <pubdate>Tue, 12 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Silverlight Could Allow Remote Code Execution (MS13-022)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-027.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft Silverlight is a web application framework that provides support for .NET applications and used for streaming media. The vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or runs a specially crafted Silverlight application.
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2013-027</guid>
            <pubdate>Tue, 12 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (MS13-023)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-026.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Visio Viewer 2010 has been identified that could allow for remote code execution. Microsoft Visio Viewer is a program commonly used to view flowcharts, network diagrams and other visual media that can be used in Microsoft Office products. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Microsoft Visio Viewer 2010
 
 RISK:
 Government:
 
 Large and medium ...]]></description>
            
            <guid>2013-026</guid>
            <pubdate>Tue, 12 Mar 2013 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-025.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2013-025</guid>
            <pubdate>Fri, 08 Mar 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Google Chrome Could Allow for Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Google Chrome could allow remote code execution, the bypass of security restrictions, or cause denial-of-service conditions. Google Chrome is a web browser used to access the Internet. Some of the vulnerabilities can likely be exploited if a user visits, or is redirected to a specially crafted web page.
 Successful exploitation of these vulnerabilities may result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2013-024</guid>
            <pubdate>Tue, 05 Mar 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Oracle Java Runtime Environment Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-023b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This zero-day vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could execute arbitrary code in the context of the application, and bypass ...]]></description>
            
            <guid>2013-023 - Update</guid>
            <pubdate>Tue, 05 Mar 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Oracle Java Runtime Environment Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-023.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This zero-day vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could execute arbitrary code in the context of the application, and bypass ...]]></description>
            
            <guid>2013-023</guid>
            <pubdate>Fri, 01 Mar 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow Remote Code Execution (APSB13-08)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-022.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player&amp;nbsp;that could allow an attacker to take control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
 It should be ...]]></description>
            
            <guid>2013-022</guid>
            <pubdate>Wed, 27 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Google Chrome Vulnerabilities Could Allow for Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-021.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Google Chrome that could allow remote code execution, the bypass of security restrictions, or cause denial-of-service conditions. Google Chrome is a web browser used to access the Internet Successful exploitation of these vulnerabilities may result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. 
 SYSTEM AFFECTED:
 
 Google Chrome for Windows and Linux versions prior to 25.0.1364.97 ...]]></description>
            
            <guid>2013-021</guid>
            <pubdate>Fri, 22 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat Could Allow For Remote Code Execution (APSA13-02)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-018b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service ...]]></description>
            
            <guid>2013-018 - Updated</guid>
            <pubdate>Thu, 21 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Oracle Java Runtime Environment (JRE) is prone to Multiple Security Vulnerabilities</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-020.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2013-020</guid>
            <pubdate>Wed, 20 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-019.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2013-019</guid>
            <pubdate>Wed, 20 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat Could Allow For Remote Code Execution (APSA13-02)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service ...]]></description>
            
            <guid>2013-018</guid>
            <pubdate>Thu, 14 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Shockwave Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-017.cfm</link>
            <description><![CDATA[Vulnerabilities have been discovered in Adobe Shockwave Player which could allow for remote code execution. Adobe Shockwave Player is a multimedia platform used to add animation and interactivity to web pages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 Adobe Shockwave Player 11.6.8.638 and earlier versions for Windows and Macintosh
 RISK:
 Government:
 
 Large and medium government entities: High
 Small government entities: ...]]></description>
            
            <guid>2013-017</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player and Adobe AIR Could Allow Remote Code Execution (APSB13-05)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-016.cfm</link>
            <description><![CDATA[Multiple security updates have been released for Adobe Flash Player and Adobe AIR. Adobe Flash Player and Adobe AIR are widely distributed multimedia and application players used to enhance the user experience when visiting web pages or reading email messages. Adobe Flash Player is prone to seventeen vulnerabilities that could allow for remote code execution or information disclosure.
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2013-016</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Vector Markup Language (VML) Could Allow Remote Code Execution (MS13-010)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-015.cfm</link>
            <description><![CDATA[Vulnerability has been discovered within Microsoft&apos;s web browser, Internet Explorer, which could allow for remote code execution. The vulnerability is caused by the way the Vector Markup Language (VML) is processed by Internet Explorer. VML is an XML-based language used to produce and render vector graphics. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the affected user, an attacker could then install programs, view, change, or delete data; or create accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 6
 Internet Explorer 7
 Internet ...]]></description>
            
            <guid>2013-015</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework Could Allow Elevation of Privilege (MS13-015)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-013.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page or runs a specially crafted Microsoft.NET application.&amp;nbsp; Successful exploitation of this vulnerability could allow an attacker to obtain complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2013-013</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS13-009)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-012.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer ...]]></description>
            
            <guid>2013-012</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Media Decompression Could Allow Remote Code Execution (MS13-011)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-011.cfm</link>
            <description><![CDATA[A remote code execution vulnerability exists in the way that Microsoft DirectShow handles media content. DirectShow is a media streaming architecture for Windows that allows video playback or capture. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office document (such as a .ppt file) that contains a specially crafted embedded media file, or by visiting a website with specially crafted streaming content designed to exploit this vulnerability. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an ...]]></description>
            
            <guid>2013-011</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (MS13-012)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-010.cfm</link>
            <description><![CDATA[Two vulnerabilities have been reported in Microsoft Exchange Server that could allow for remote code execution. Microsoft Exchange Server provides e-mail, calendar and contacts for corporate environments. Successful exploitation of one of the vulnerabilities could allow an attacker to run arbitrary code within the context of the LocalService account on the affected Microsoft Exchange Server. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
 SYSTEMS AFFECTED: 
 
 Microsoft Exchange Server 2007 
 Microsoft Exchange Server 2010 
 
 RISK: ...]]></description>
            
            <guid>2013-010</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow For Remote Code Execution (APSB13-04)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-009b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow remote code execution. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
 It should be noted that these vulnerabilities are ...]]></description>
            
            <guid>2013-009 - Updated</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in OLE Automation Could Allow Remote Code Execution (MS13-0020)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-014.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Object Linking and Embedding (OLE) Automation which could allow an attacker to take complete control of an affected system. OLE technology is a Windows protocol that provides a platform for applications to access and manipulate functionalities that are made available by other applications.&amp;nbsp; The vulnerability could allow remote code execution if a user opens a specially crafted file. Successful exploitation of this vulnerability could allow the attacker to could gain the same user rights as the logged on user. Depending on the privileges associated with the user, an attacker could then ...]]></description>
            
            <guid>2012-014</guid>
            <pubdate>Tue, 12 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow For Remote Code Execution (APSB13-04)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-009.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow remote code execution. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
 It should be noted that these vulnerabilities are ...]]></description>
            
            <guid>2013-009</guid>
            <pubdate>Fri, 08 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities In Oracle Java Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-008.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of these vulnerabilities could allow an attacker to gain the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2013-008</guid>
            <pubdate>Mon, 04 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-007.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise that could allow for remote code execution. Novell GroupWise is a collaborative software product that includes: e-mail, calendars, instant messaging and document management.&amp;nbsp; These vulnerabilities can be exploited if a user visits a specially crafted web page.&amp;nbsp; Successful exploitation could allow an attacker to gain the same privileges as the affected user. An attacker could then install programs; view, change, or delete data; or create new accounts. Unsuccessful exploitation attempts may result in a denial-of-service.
 SYSTEMS AFFECTED:
 
 GroupWise Client for Windows 8.0x up to and including 8.0.3 HP1
 GroupWise Client ...]]></description>
            
            <guid>2013-007</guid>
            <pubdate>Fri, 01 Feb 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Oracle Java Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-006b.cfm</link>
            <description><![CDATA[January 14 UPDATE SUMMARY: 
	 Oracle has released an updated Security Alert that contains further details regarding this vulnerability, and an additional vulnerability&amp;nbsp;affecting Java running in web browsers. &amp;nbsp;It is recommended that the patch from Oracle be applied immediately after appropriate testing (see UPDATED RECOMMENDATIONS below.) 
 ORIGINAL OVERVIEW: 
 A vulnerability has been discovered in Oracle Java that can lead to remote code execution. Java is used to enhance the user experience when visiting websites and is installed on a majority of desktops and servers. This vulnerability may be exploited if a user visits or is redirected to ...]]></description>
            
            <guid>2013-006 - Updated</guid>
            <pubdate>Mon, 14 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2012-097c.cfm</link>
            <description><![CDATA[January 14 - UPDATED SUMMARY: 
	 Microsoft has released a patch that fixes this vulnerability in security bulletin MS13-008.
 ORIGINAL OVERVIEW: 
 A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker ...]]></description>
            
            <guid>2012-097 - Updated</guid>
            <pubdate>Mon, 14 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability In Oracle Java Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-006.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java &amp;nbsp;that can lead to remote code execution. Java is used to enhance the user experience when visiting websites and is installed on a majority of desktops and servers. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the Java application. Depending on the privileges associated with the application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2013-006</guid>
            <pubdate>Fri, 11 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-005.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2013-005</guid>
            <pubdate>Wed, 09 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat Could Allow For Remote Code Execution (APSB13-02)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-004.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the user. Depending on the privileges associated with the user, an attacker could install programs; view, change, delete data or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2013-004</guid>
            <pubdate>Tue, 08 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player Could Allow For Remote Code Execution (APSB13-01)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-003.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player that could allow an attacker to take control of the affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
 SYSTEMS ...]]></description>
            
            <guid>2013-003</guid>
            <pubdate>Tue, 08 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in .NET Framework (MS13-004)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-002.cfm</link>
            <description><![CDATA[Four vulnerabilities have been discovered in the Microsoft.NET Framework, some of which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page. They can also be exploited if a user runs a specially crafted Microsoft.NET application. Successful exploitation of these vulnerabilities could allow an attacker to obtain complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2013-002</guid>
            <pubdate>Tue, 08 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (MS13-002)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2013-001.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Microsoft Core XML Services (MSXML), which could allow an attacker to take complete control of an affected system. Microsoft Core XML Services is software that allows users to develop XML based applications. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page using Microsoft Internet Explorer. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2013-001</guid>
            <pubdate>Tue, 08 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2013/2012-097b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result ...]]></description>
            
            <guid>2012-097 - Updated</guid>
            <pubdate>Wed, 02 Jan 2013 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-097.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result ...]]></description>
            
            <guid>2012-097</guid>
            <pubdate>Mon, 31 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Adobe Shockwave Player Remote Code Execution Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-096.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Shockwave, which could allow for remote code execution. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. This vulnerability may be exploited if a user visits, or is redirected to, a specially crafted web page. It may also be exploited when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2012-096</guid>
            <pubdate>Wed, 19 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in DirectPlay Could Allow Remote Code Execution (MS12-082)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-095.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the way Microsoft DirectPlay handles specially crafted content. DirectPlay is a network protocol that is shipped with Microsoft DirectX.&amp;nbsp; This vulnerability could allow for remote code execution if an attacker can convince a user to open a specially crafted Office document.&amp;nbsp; Successful exploitation of this vulnerability could result in the execution of arbitrary code with full administrative privileges resulting in full control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 SYSTEMS AFFECTED:
 
 Windows XP
 Windows Server 2003 ...]]></description>
            
            <guid>2012-095</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows File Handling Component Could Allow Remote Code Execution (MS12-081)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-094.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows that could allow for remote code execution. This vulnerability could be exploited by creating a specially crafted file or folder that is located on the local system, network share, or downloaded from an external source. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Windows XP
 Windows Server 2003
 Windows Vista
 Windows Server ...]]></description>
            
            <guid>2012-094</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (MS12-080)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-093.cfm</link>
            <description><![CDATA[Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (MS12-080)
 OVERVIEW: 
 Two vulnerabilities have been reported in Microsoft Exchange Server that could allow for remote code execution or Denial of Service (DoS) conditions. Microsoft Exchange Server provides e-mail, calendar and contacts for corporate environments. 
 Successful exploitation of one of the vulnerabilities could allow an attacker to run arbitrary code within the context of the LocalService account on the affected Microsoft Exchange Server. Typically, the LocalService account has minimum privileges on the system. Exploitation of the other vulnerability could cause Denial of Service (DoS) conditions.
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-093</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Word Could Allow Remote Code Execution (MS12-079)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-092.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Word that could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp;
 SYSTEMS AFFECTED:
 
 Microsoft Office 2003
 Microsoft Office 2007
 Microsoft Office 2010
 Microsoft Word Viewer
 Microsoft Office Compatibility Pack
 Microsoft SharePoint Server 2010
 Microsoft Office Web Apps 2010
 
 RISK: 
 Government:
 
 Large and medium government entities: High
 Small government entities: High
 
 Businesses:
 
 Large and ...]]></description>
            
            <guid>2012-092</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (MS12-078)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-091.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Windows that could allow for remote code execution.&amp;nbsp; These vulnerabilities are due to improper validation of input by Windows kernel-mode drivers. Exploitation of these vulnerabilities could result in the execution of arbitrary code with administrative privileges resulting in full control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 SYSTEMS AFFECTED:
 
 Windows XP
 Windows Server 2003
 Windows Vista
 Windows Server 2008
 Windows 7
 Windows 8
 Windows server 2012
 Windows RT
 
 RISK: 
 Government:
 
 Large and ...]]></description>
            
            <guid>2012-091</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-077)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-090.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 10
 Internet Explorer 9
 Internet Explorer 8
 Internet Explorer 7
 Internet Explorer 6
 
 RISK: 
 Government:
 
 Large and medium government entities: High ...]]></description>
            
            <guid>2012-090</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player and AIR Could Allow Remote Code Execution (APSB12-27)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-089.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR that could allow attackers to execute arbitrary code on the affected systems. Adobe Flash Player and Adobe AIR are widely distributed multimedia and application players used to enhance the user experience when visiting web pages or reading email messages. 
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will ...]]></description>
            
            <guid>2012-089</guid>
            <pubdate>Tue, 11 Dec 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-088.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-088</guid>
            <pubdate>Wed, 21 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in .NET Framework Could Allow Remote Code Execution (MS12-074)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-087.cfm</link>
            <description><![CDATA[Five vulnerabilities have been discovered in the Microsoft .NET framework, some of which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page, runs a specially crafted Microsoft .NET application, or loads a specially crafted proxy configuration file.
 Successful exploitation of these vulnerabilities could allow the attacker to obtain complete control of the affected system. An attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2012-087</guid>
            <pubdate>Tue, 13 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-071)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-086.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
 
 Internet Explorer 9
 
 RISK:
 Government:
 
 Large and medium government entities: High
 Small government entities: High
 
 Businesses:
 
 Large and medium business entities: High ...]]></description>
            
            <guid>2012-086</guid>
            <pubdate>Tue, 13 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (MS012-076)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-085.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Microsoft Office 2003
 Microsoft Office 2007
 Microsoft Office 2010
 Microsoft Office 2008 ...]]></description>
            
            <guid>2012-085</guid>
            <pubdate>Tue, 13 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (MS12-075)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-084.cfm</link>
            <description><![CDATA[Three vulnerabilities have been discovered in Microsoft Windows kernel-mode drivers that could allow for remote code execution. The kernel-mode drivers control window displays, screen output, and input from devices that the kernel, the main component of the operating system, passes to applications. Successful exploitation of these vulnerabilities could result in the execution of arbitrary code with full system privileges resulting in full control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 SYSTEMS AFFECTED:
 
 Windows XP
 Windows Server 2003
 Windows Vista
 Windows Server 2008 ...]]></description>
            
            <guid>2012-084</guid>
            <pubdate>Tue, 13 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-083.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2012-083</guid>
            <pubdate>Thu, 08 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow Remote Code Execution (APSB12-24)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-082.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions 
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-082</guid>
            <pubdate>Tue, 06 Nov 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow For Remote Code Execution (APSB12-23)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-081.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow for remote code execution. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-081</guid>
            <pubdate>Tue, 23 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-080.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2012-080</guid>
            <pubdate>Fri, 12 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Cisco Products Could Allow the Execution of Arbitrary Commands or Denial of Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-079.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Cisco products including the Cisco Adaptive Security Appliances (ASA) 5500 Series and Cisco Catalyst 6500 Series ASA Services Module. Cisco ASA products provide firewall, intrusion prevention, remote access, and other services. Successful exploitation of one of the vulnerabilities could lead to an attacker executing arbitrary commands on the system.&amp;nbsp;The remaining vulnerabilities could result in denial of service conditions or a reload on the affected device.
 SYSTEMS AFFECTED:
 
 Cisco Adaptive Security Appliances (ASA) 5500 Series
 Cisco Catalyst 6500 Series ASA Services Module (ASASM)
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small ...]]></description>
            
            <guid>2012-79</guid>
            <pubdate>Thu, 11 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-078.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-078</guid>
            <pubdate>Thu, 11 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (MS012-064)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-077.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Word that could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Microsoft Office 2003
 Microsoft Office 2007
 Microsoft Office 2010
 Microsoft Word Viewer
 Microsoft Office Compatibility Pack
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small government entities:&amp;nbsp;High
 
 Businesses:
 
 Large and medium business entities:&amp;nbsp;High
 Small business entities:&amp;nbsp;High
 
 Home users: High
 DESCRIPTION:
 Two ...]]></description>
            
            <guid>2012-077</guid>
            <pubdate>Tue, 09 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player and AIR Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-076.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR that could allow attackers to take complete control of affected systems. Adobe Flash Player and Adobe AIR are widely distributed multimedia and application players used to enhance the user experience when visiting web pages or reading e-mail messages. 
 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely ...]]></description>
            
            <guid>2012-076</guid>
            <pubdate>Tue, 09 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-075.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise client and GroupWise Internet Agent (GWIA) which could allow remote code execution. Novell GroupWise is a collaborative software product, which includes e-mail, calendars, instant messaging and document management. The GWIA is a server component that provides communication to other e-mail systems and conversion of e-mail messages to GroupWise format.
 Successful exploitation could allow an attacker to gain the same privileges as the affected application. An attacker could then install programs; view, change, or delete data; or create new accounts. Unsuccessful exploitation attempts may result in a denial of service.
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-075</guid>
            <pubdate>Mon, 01 Oct 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Denial of Service Vulnerabilities in Cisco Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-074.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in several Cisco products including Cisco Catalyst 4500E Series Switches, Cisco devices running Cisco IOS and Cisco IOS EX, as well as Cisco&apos;s Unified Communications Manager.&amp;nbsp;Successful exploitation of these vulnerabilities could result in denial of service conditions or reboot the affected device.
 SYSTEMS AFFECTED:
 
 Cisco Catalyst 4500E Series Switch with Cisco Catalyst Supervisor Engine 7L-E
 Cisco IOS 
 Cisco IOS EX 3.2.xXO
 Cisco Unified Communications Manager 6.x, Cisco Unified Communications Manager 7.x, Cisco Unified Communications Manager 8.x
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small government entities:&amp;nbsp;High
 
 Businesses:
 
 Large ...]]></description>
            
            <guid>2012-074</guid>
            <pubdate>Thu, 27 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player Could Allow For Remote Code Execution (APSB12-19)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-073.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player that could allow an attacker to take control of the affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial of service conditions. ...]]></description>
            
            <guid>2012-073</guid>
            <pubdate>Wed, 26 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-072.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple Mac OS X and Mac OS X Server that could allow remote code execution. Mac OS X is a desktop operating system for the Apple Mac. Mac OS X Server is a server operating system for the Apple Mac.
 These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker ...]]></description>
            
            <guid>2012-072</guid>
            <pubdate>Mon, 24 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-063)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-071.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 6
 Internet Explorer 7
 Internet Explorer 8
 Internet Explorer 9
 
 RISK:
 Government:
 
 Large and medium government entities: High
 Small government entities: High ...]]></description>
            
            <guid>2012-071</guid>
            <pubdate>Fri, 21 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-069c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result ...]]></description>
            
            <guid>2012-069 - Updated</guid>
            <pubdate>Fri, 21 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-069b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result ...]]></description>
            
            <guid>2012-069 - Updated</guid>
            <pubdate>Wed, 19 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Novell GroupWise Internet Agent Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-070.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Novell GroupWise Internet Agent (GWIA) which could allow remote code execution. Novell GroupWise is a collaborative software product, which includes e-mail, calendars, instant messaging and document management. The GroupWise Internet Agent is a server component that provides communication to other e-mail systems and conversion of e-mail messages to GroupWise format. 
 Successful exploitation could allow an attacker to gain the same privileges as the affected application. An attacker could then install programs; view, change, or delete data; or create new accounts. Unsuccessful exploitation attempts may result in a denial of service.
 Please note ...]]></description>
            
            <guid>2012-070</guid>
            <pubdate>Mon, 17 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-069.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result ...]]></description>
            
            <guid>2012-069</guid>
            <pubdate>Mon, 17 Sep 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Oracle Java Runtime Environment is prone to a remote code execution vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-067c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment that can lead to remote code execution.&amp;nbsp;The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This&amp;nbsp;vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file.&amp;nbsp;&amp;nbsp;
 Please note that there have been reports of active exploitation of this vulnerability and public exploit code is currently available. At this time, no patch is available from Oracle to mitigate this vulnerability.
 August 29 - UPDATED OVERVIEW ...]]></description>
            
            <guid>2012-067 - Updated</guid>
            <pubdate>Thu, 30 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-068.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. &amp;nbsp;Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-068</guid>
            <pubdate>Wed, 29 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Oracle Java Runtime Environment is prone to a remote code execution vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-067b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment that can lead to remote code execution.&amp;nbsp;The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This&amp;nbsp;vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file.&amp;nbsp;&amp;nbsp;
 Please note that there have been reports of active exploitation of this vulnerability and public exploit code is currently available. At this time, no patch is available from Oracle to mitigate this vulnerability.
 August 29 - UPDATED OVERVIEW ...]]></description>
            
            <guid>2012-067 - Updated</guid>
            <pubdate>Wed, 29 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Oracle Java Runtime Environment is prone to a remote code execution vulnerability.</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-067.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Oracle Java Runtime Environment that can lead to remote code execution.&amp;nbsp;The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on most desktops and servers. This&amp;nbsp;vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file.&amp;nbsp;&amp;nbsp;
 Please note that there have been reports of active exploitation of this vulnerability and public exploit code is currently available. At this time, no patch is available from Oracle to mitigate this vulnerability.
 SYSTEMS AFFECTED:
 
 Oracle JRE ...]]></description>
            
            <guid>2012-067</guid>
            <pubdate>Tue, 28 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Flash Player Could Allow For Remote Code Execution (APSB12-19)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-066.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow an attacker to take control of the affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial of service conditions. ...]]></description>
            
            <guid>2012-066</guid>
            <pubdate>Wed, 22 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Could Allow Remote Code Execution (MS12-057)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-065.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in a component of Microsoft Office, which is Microsoft&apos;s business application suite, that could allow remote code execution. Exploitation may occur if a user opens a specially crafted Computer Graphics Metafile (CGM) graphics file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Microsoft Office 2007 
 Microsoft Office 2010 
 
 RISK:
 Government:
 
 Large and ...]]></description>
            
            <guid>2012-065</guid>
            <pubdate>Wed, 15 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Networking Components Could Allow Remote Code Execution (MS12-054)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-064.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Windows networking components that could allow remote code execution and denial of service attacks&amp;nbsp;on the affected system.&amp;nbsp; Successful exploitation could result in an attacker gaining SYSTEM level privileges&amp;nbsp;which can result in the complete compromise of affected systems. An attacker could then install programs, view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Windows XP
 Windows Server 2003
 Windows Vista
 Windows Sever 2008
 Windows Sever 2008 R2
 Windows 7
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small government entities:&amp;nbsp;High
 
 Businesses:
 
 Large and medium ...]]></description>
            
            <guid>2012-064</guid>
            <pubdate>Wed, 15 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Remote Desktop Could Allow Remote Code Execution (MS12-053) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-063.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems. RDP provides a graphical interface for users to establish a virtual session to other computers. Successfully exploiting this vulnerability could allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. 
 It should be noted that we have historically identified a large amount of scanning for RDP as well as brute force attempts against systems running this service.&amp;nbsp;
 SYSTEMS AFFECTED:
 
 Windows XP
 
 RISK:
 Government:
 
 Large and medium government ...]]></description>
            
            <guid>2012-063</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player Could Allow For Remote Code Execution (APSB12-18)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-062.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player that could allow an attacker to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial of service ...]]></description>
            
            <guid>2012-062</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow For Code Execution (APSB12-17)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-061.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2012-061</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat Could Allow For Remote Code Execution (APSB12-16)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-060.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow an attacker to take complete control of an affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause ...]]></description>
            
            <guid>2012-060</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Code Execution (MS12-056)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-059.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft JScript and VBScript scripting engines on 64-bit systems. Jscript and VBScript are scripting languages used to enhance the user experience when visiting web pages such as displaying animated content. This vulnerability can be exploited if a user visits a specially crafted website. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a ...]]></description>
            
            <guid>2012-059</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Visio Could Allow Remote Code Execution (MS12-059)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-058.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Visio has been identified that could allow for remote code execution. Microsoft Visio is a program commonly used to develop flowcharts, network diagrams and other visual media that can be used in Office-based products. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Microsoft Visio Viewer 2010
 Microsoft Visio 2010
 
 RISK:
 Government:
 
 Large and medium government ...]]></description>
            
            <guid>2012-058</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Exchange Server WebReady Document Viewing Could Allow Remote Code Execution (MS12-058)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-057.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been reported in Microsoft Exchange Server WebReady Document Viewing that could allow remote code execution. Microsoft Exchange Server provides e-mail, calendar and contacts for corporate environments.&amp;nbsp; MS Exchange Server Web Ready Document viewing is a feature that allows Outlook Web Access (OWA) users to view attachments such as Microsoft Office documents within the browser. 
 Successful exploitation could allow an attacker to run arbitrary code within the context of the LocalService account on the affected Microsoft Exchange Server. Typically, the LocalService account has minimum privileges on the system.
 SYSTEMS AFFECTED: 
 
 Microsoft Exchange Server 2007 ...]]></description>
            
            <guid>2012-057</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-052)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-056.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 SYSTEMS AFFECTED:
 
 Internet Explorer 6 
 Internet Explorer 7 
 Internet Explorer 8 
 Internet Explorer 9 
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small ...]]></description>
            
            <guid>2012-056</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Common Controls Could Allow Remote Code Execution (MS12-060)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-055.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows common controls that could allow an attacker to take complete control of a vulnerable system. Windows common controls are a set of interfaces that enable a user to interact with an application and are used by all supported versions of the Windows Operating System.
 This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs, ...]]></description>
            
            <guid>2012-055</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS12-043)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-045c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Core XML Services (MSXML) which could allow an attacker to take complete control of an affected system. Microsoft Core XML Services is software which allows users to develop XML based applications. This vulnerability can be exploited if a user with a vulnerable MSXML package visits or is redirected to a specially crafted web page using Microsoft Internet Explorer. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2012-045 - Updated</guid>
            <pubdate>Tue, 14 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Denial of Service Vulnerabilities in Cisco Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-054.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in several Cisco products.&amp;nbsp;The Cisco products affected range from network devices such as firewalls, intrusion prevention systems and switches to software for virtualization and mobile VPN clients. Successful exploitation of these vulnerabilities could result in denial of service conditions.
 SYSTEMS AFFECTED:
 

 Cisco ASA 5500 with software versions 8.2 through 8.4
 Cisco IOS 12.0, 12.2, 12.3, 12.4, 15.0, 15.1, and 15.2
 Cisco NX-OS 4.2, 5.0, 5.1, and 5.2
 Cisco Unified Computing System (UCS) 1.4 and 2.0
 Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057
 
 RISK:
 Government:
 
 Large and medium government entities:&amp;nbsp;High
 Small ...]]></description>
            
            <guid>2012-054</guid>
            <pubdate>Wed, 08 Aug 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-053.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2012-053</guid>
            <pubdate>Wed, 18 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (MS12-048)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-052.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell which could allow an attacker to take complete control of an affected system. The Windows Shell is used to run applications and manage the Windows operating system. Exploitation may occur if a user opens a file or directory which is specifically crafted to take advantage of this vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2012-052</guid>
            <pubdate>Tue, 10 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution (MS12-045)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-051.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Data Access Components (DAC) that could allow remote code execution which may permit an attacker to take complete control of an affected system. Microsoft Data Access Components is a collection of components that allow programs to access databases and to manipulate the data. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft ...]]></description>
            
            <guid>2012-051</guid>
            <pubdate>Tue, 10 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-044)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-050.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user.
	 Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 9
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities: High
	 Small government entities: High
	 
	 Businesses: 
	 
	 Large and ...]]></description>
            
            <guid>2012-050</guid>
            <pubdate>Tue, 10 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS12-043)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-045b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Core XML Services (MSXML) which could allow an attacker to take complete control of an affected system. Microsoft Core XML Services is software which allows users to develop XML based applications. This vulnerability can be exploited if a user with a vulnerable MSXML package visits or is redirected to a specially crafted web page using Microsoft Internet Explorer. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2012-045 - Updated</guid>
            <pubdate>Tue, 10 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Novell GroupWise is Prone to a Directory-Traversal Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-049.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Novell GroupWise that could allow an attacker to obtain sensitive information that could aid in further attacks. Novell GroupWise is a collaborative software product that includes e-mail, calendars, instant messaging, and document management. Successful exploitation of this vulnerability could result in an attacker gaining access to files and directories in the context of the application.
	 SYSTEMS AFFECTED:
	 
	 Novell GroupWise 8.0 prior to Support Pack 3
	 Novell GroupWise prior to 8.03
	 
	 RISK:
 Government:
	 
	 Large and medium government entities: High
	 Small government entities: High
	 
	 Businesses:
	 
	 Large and medium business entities: ...]]></description>
            
            <guid>2012-049</guid>
            <pubdate>Mon, 02 Jul 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Cisco WebEx and Advanced Recording Format Players Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-048.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Cisco WebEx WRF (WebEx Recording Format) and ARF (Advanced Recording Format) players, which could allow remote code execution. The WebEx meeting service is a hosted multimedia conferencing solution that is managed and maintained by Cisco WebEx. Sessions established during meetings can be saved to WRF and ARF files and later replayed with Cisco WebEx Players. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; ...]]></description>
            
            <guid>2012-048</guid>
            <pubdate>Wed, 27 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Cisco AnyConnect VPN Software Could Lead to Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-047.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Cisco AnyConnect Virtual Private Network (VPN) client software that could allow for remote code execution. Cisco AnyConnect is VPN client software used to gain access to private networks. The application is prone to multiple vulnerabilities; some of which could result in remote code execution on the client. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts ...]]></description>
            
            <guid>2012-047</guid>
            <pubdate>Thu, 21 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Denial of Service Vulnerability in Cisco ASA products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-046.cfm</link>
            <description><![CDATA[A denial of service vulnerability has been discovered in Cisco Adaptive Security Appliance (ASA) 5500 series and ASA services modules (ASASM) for Catalyst 6500 series switches. Cisco ASA products provide firewall, intrusion prevention, remote access, and other services. Successful exploitation could result in denial of service conditions or a reboot on the affected device. 
	 SYSTEMS AFFECTED:
 
 Cisco ASA 5500 series running software versions prior to 8.4 (4.1), 8.5 (1.11), and 8.6 (1.3)
 Cisco Catalyst 6500 series ASASM running software&amp;nbsp;versions prior to 8.4 (4.1), 8.5 (1.11), and 8.6 (1.3)
 
	 RISK: 
 Government: 
	 
	 Large and medium ...]]></description>
            
            <guid>2012-046</guid>
            <pubdate>Thu, 21 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-037)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-044b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 June 19 - UPDATED OVERVIEW: 
 OCS is aware of active exploitation for one of the vulnerabilities reported in MS12-037 (CVE-2012-1875). &amp;nbsp;Reports indicate that there are &amp;quot;limited attacks&amp;quot; exploiting ...]]></description>
            
            <guid>2012-044 - Updated</guid>
            <pubdate>Tue, 19 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-045.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft XML Core Services (MSXML) which could allow an attacker to take complete control of an affected system. Microsoft XML Core Services is software which allows users to develop XML based applications. This vulnerability can be exploited if a user with a vulnerable MSXML package visits or is redirected to a specially crafted webpage using Microsoft Internet Explorer. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2012-045</guid>
            <pubdate>Wed, 13 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-037)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-044.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:&amp;nbsp;
	 
	 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
	 Internet Explorer 9
	 
	 RISK: 
 Government:&amp;nbsp;
	 
	 Large and medium government entities: High
	 Small government ...]]></description>
            
            <guid>2012-044</guid>
            <pubdate>Tue, 12 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework Could Allow Remote Code Execution (MS12-038)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-043.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability can be exploited if a user visits or is redirected to a specially crafted webpage, or runs a specially crafted Microsoft .NET application. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2012-043</guid>
            <pubdate>Tue, 12 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Remote Desktop Protocol Could Allow Remote Code Execution (MS12-036)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-042.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems or cause a Denial of Service. RDP provides a graphical interface for users to establish a virtual session to other computers. Successfully exploiting this vulnerability could allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in Denial of Service conditions on targeted systems.
	 It should be noted that we have historically identified a large amount of scanning for RDP as well as brute force attempts ...]]></description>
            
            <guid>2012-042</guid>
            <pubdate>Tue, 12 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple F5 Products Could Allow Unauthorized Access</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-041.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in multiple F5 BIG-IP based products which could allow remote unauthorized access to an affected device. BIG-IP is a network appliance developed by F5. A remote attacker can exploit this issue to gain unauthorized access to affected devices. Successfully exploiting this issue allows an attacker to completely compromise the device.
	 SYSTEMS AFFECTED: 
	 
 BIG-IP prior to 9.4.8-HF5 
	 BIG-IP prior to 10.2.4 
	 BIG-IP prior to 11.0.0-HF2 
	 BIG-IP prior to 11.1.0-HF3 
	 Enterprise Manager prior to 2.1.0-HF2
	 Enterprise Manager prior to 2.2.0-HF1 
	 Enterprise Manager prior to 2.3.0-HF3 
	 
	 RISK: ...]]></description>
            
            <guid>2012-041</guid>
            <pubdate>Tue, 12 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in MySQL Could Allow Authentication Bypass</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-040.cfm</link>
            <description><![CDATA[An authentication bypass vulnerability has been discovered in multiple versions of MySQL that could allow attackers to take complete control of affected databases. &amp;nbsp;MySQL is a relational database management system that is used to correlate and organize data. &amp;nbsp; 
	 Successful exploitation could result in an attacker gaining access to the database. Depending on the privileges associated with the user, an attacker could then insert, view, change, or delete data in the database; or create new database accounts with full user rights. &amp;nbsp; Failed exploit attempts will likely cause denial-of-service conditions. 
	 It should be noted that although a ...]]></description>
            
            <guid>2012-040</guid>
            <pubdate>Tue, 12 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player Could Allow For Remote Code Execution (APSB12-14)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-039.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-039</guid>
            <pubdate>Mon, 11 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-038b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2012-038 - UPDATED</guid>
            <pubdate>Thu, 07 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-038.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2012-038</guid>
            <pubdate>Wed, 06 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Unauthorized Digital Certificates Could Allow Spoofing</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-037.cfm</link>
            <description><![CDATA[Microsoft has released information regarding active attacks using unauthorized digital certificates derived from a Microsoft Certificate Authority. Digital certificates are electronic files, issued by organizations known as certificate authorities (CA) that provide non-repudiation and enable secure electronic communication between entities on the Internet. An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.
	 This issue affects all supported releases of Microsoft Windows as well as Windows Mobile and Windows Phone devices. Please note that there is currently no patch available for Windows Mobile or Windows Phone.&amp;nbsp;
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server ...]]></description>
            
            <guid>2012-037</guid>
            <pubdate>Mon, 04 Jun 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-036.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime that could allow remote code execution. Apple QuickTime is used to play media files on Microsoft Windows and Apple Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple QuickTime. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2012-036</guid>
            <pubdate>Wed, 16 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-035.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple&apos;s Mac OS X and Mac OS X Server that could allow remote code execution. Mac OS X is a desktop operating system for the Apple Mac. Mac OS X Server is a server operating system for the Apple Mac.
	 These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of OS X.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            
            <guid>2012-035</guid>
            <pubdate>Mon, 14 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow For Code Execution (APSB12-13)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-034.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow for remote code execution.&amp;nbsp; Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-034</guid>
            <pubdate>Wed, 09 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (MS12-030)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-033.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office, specifically in Microsoft Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Microsoft Excel 2003
	 Microsoft Excel 2007
	 Microsoft ...]]></description>
            
            <guid>2012-033</guid>
            <pubdate>Wed, 09 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (MS12-031) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-032.cfm</link>
            <description><![CDATA[A vulnerability in Microsoft Visio Viewer has been identified that could allow for remote code execution. Microsoft Visio Viewer is a program used for viewing flowcharts and diagrams. &amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Visio Viewer 2010 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities: High 
	 Small government entities: High ...]]></description>
            
            <guid>2012-032</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in .NET Framework Could Allow Remote Code Execution (MS12-035)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-031.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework which could allow for remote code execution. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET application.
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-031</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (MS12-029)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Word.&amp;nbsp; This vulnerability can be exploited by opening a specially crafted Word document received as an e-mail attachment, or by visiting a website that is hosting a specially crafted Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. &amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Microsoft Office 2003 
	 Microsoft Office 2007 
	 Microsoft Office 2008 for Mac ...]]></description>
            
            <guid>2012-030</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (MS12-034)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-029.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&amp;nbsp;Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight.&amp;nbsp;Microsoft Office is Microsoft&apos;s business application suite. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media.
	 The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. Successful exploitation of this vulnerability could result in the attacker gaining the same privileges as ...]]></description>
            
            <guid>2012-029</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Input Vulnerability in PHP Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-028b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in PHP which could allow an attacker to remotely disclose source code and potentially execute arbitrary code. PHP is a programming language originally designed for use in web based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web based software applications.&amp;nbsp; Successful exploitation could result in an attacker viewing the PHP source code of a web based application or website and potentially executing arbitrary code.
	 Public exploit code is available in the form of a Metasploit module that is capable of triggering the vulnerability by delivering ...]]></description>
            
            <guid>2012-028 </guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Input Vulnerability in PHP Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-028.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in PHP which could allow an attacker to remotely disclose source code and potentially execute arbitrary code. PHP is a programming language originally designed for use in web based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web based software applications.&amp;nbsp; Successful exploitation could result in an attacker viewing the PHP source code of a web based application or website and potentially executing arbitrary code.
	 Public exploit code is available in the form of a Metasploit module that is capable of triggering the vulnerability by delivering ...]]></description>
            
            <guid>2012-028</guid>
            <pubdate>Tue, 08 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Adobe Flash Player Object Confusion Remote Code Execution Vulnerability </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-027.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. &amp;nbsp;Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. &amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. &amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-027</guid>
            <pubdate>Fri, 04 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Oracle Database Server 'TNS Listener' </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-026.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Oracle database server&apos;s &apos;TNS Listener&apos; service, which could allow&amp;nbsp;for multiple remote attacks against an Oracle database.&amp;nbsp;This vulnerability may be remotely exploitable without authentication. Oracle database&amp;nbsp;is an enterprise database server available for multiple operating systems.&amp;nbsp;&apos;TNS Listener&apos; is a component that routes connections from the client to the database server based on a naming convention (instance name). 
	 Successful exploitation of this vulnerability could result in an attacker altering the naming convention and routing the database information to the attackers system. 
	 SYSTEMS AFFECTED: 
	 
	 Oracle Database 11g Release 2, versions 11.2.0.2, 11.2.0.3 ...]]></description>
            
            <guid>2012-026</guid>
            <pubdate>Tue, 01 May 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-025</guid>
            <pubdate>Wed, 25 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2012-024</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Common Controls</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-023.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Common Controls that could allow an attacker to take complete control of a vulnerable system. Windows Common Controls are a set of interfaces that enable a user to interact with an application and are used by all supported versions of the Windows Operating System. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs, ...]]></description>
            
            <guid>2012-023</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-022.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. The vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET application. 
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2012-022</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Could Allow Remote Code Execution (MS12-024)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-021.cfm</link>
            <description><![CDATA[A new vulnerability has been reported in the Microsoft Windows Operating System. Exploitation may occur if a user opens a specially crafted, signed portable executable (PE) file. In order to exploit this vulnerability, an attacker could append specially crafted code to a digitally signed portable executable file without invalidating the signature and then have a user run or install the program. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2012-021</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS12-023)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-020.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 
	 Internet Explorer 9 
	 
	 RISK: 
 Government: 
	 
	 Large and medium ...]]></description>
            
            <guid>2012-020</guid>
            <pubdate>Tue, 10 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-019b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-019 - UPDATED</guid>
            <pubdate>Thu, 05 Apr 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-019.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2012-019</guid>
            <pubdate>Wed, 28 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Remote Desktop </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-016b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Windows Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems or cause a denial-of-service. RDP provides a graphical interface for users to establish a virtual session to other hosts on the network. Successfully exploiting this vulnerability would allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; This could also result in producing a denial-of-service condition on targeted systems.&amp;nbsp;
 	 Please note that Microsoft is strongly&amp;nbsp;encouraging entities to make a special priority of applying this particular update. Through our Managed Security ...]]></description>
            
            <guid>2012-016 - UPDATED</guid>
            <pubdate>Fri, 16 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Cisco ASA 5500 Series Products and Cisco ASA Modules for Catalyst 6500 Switches</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Cisco Adaptive Security Appliance (ASA) 5500 series appliances and ASA modules for Catalyst 6500 series switches. Cisco ASA products provide firewall, intrusion prevention, remote access, and other services. Successful exploitation could lead to the attacker taking control of a client machine or cause the appliance to reload, creating denial-of-service conditions.
	 SYSTEMS AFFECTED: 
	 
 Cisco ASA 5500 Series Appliances 
 Cisco Catalyst 6500 series ASA Service Modules
 
	 RISK: 
 Government: 
	 
 Large and medium government entities:&amp;nbsp;High 
	 Small government entities:&amp;nbsp;High 
	 
	 Businesses: 
	 
 Large and medium business entities:&amp;nbsp;High ...]]></description>
            
            <guid>2012-018</guid>
            <pubdate>Thu, 15 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-017.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and&amp;nbsp;SeaMonkey&amp;nbsp;applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla&amp;nbsp;SeaMonkey&amp;nbsp;is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or bypass security restrictions. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2012-017</guid>
            <pubdate>Wed, 14 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Remote Desktop </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-016.cfm</link>
            <description><![CDATA[Multiple vulnerabilities in Windows Remote Desktop Protocol (RDP) could allow an attacker to take complete control of affected systems or cause a denial-of-service. RDP provides a graphical interface for users to establish a virtual session to other hosts on the network. Successfully exploiting this vulnerability would allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; This could also result in producing a denial-of-service condition on targeted systems.&amp;nbsp;
 	 Please note that Microsoft is strongly&amp;nbsp;encouraging entities to make a special priority of applying this particular update. Through our Managed Security ...]]></description>
            
            <guid>2012-016</guid>
            <pubdate>Tue, 13 Mar 2012 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. 
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely result in denial-of-service conditions. ...]]></description>
            
            <guid>2012-015</guid>
            <pubdate>Tue, 06 Mar 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages.
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely result in denial-of-service conditions. ...]]></description>
            
            <guid>2012-014</guid>
            <pubdate>Thu, 16 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in C Run-Time Library</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-013.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&#xe2;??s C Run-Time Library which could allow an attacker to take complete control of an affected system. The C Run-Time Library is a collection of support files used to implement basic functions such as input/output and memory management. The vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted media file hosted on a website or sent as an e-mail attachment.
 	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            
            <guid>2012-013</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in .NET Framework and Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-012.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media. The vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application.
 	 Successful exploitation could result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2012-012</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-011.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Windows that could allow for remote code execution due to improper validation of input by a Windows kernel-mode driver. The vulnerable driver controls window displays, screen output, and input from devices which it passes to applications. Successful exploitation of these vulnerabilities could result in the execution of arbitrary code with full administrative privileges resulting in full control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 	 SYSTEMS AFFECTED: 
 
 Windows XP
 Windows Server 2003
 Windows Vista ...]]></description>
            
            <guid>2012-011</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Viewer 2010</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-010.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Visio Viewer 2010, a program used for viewing flowcharts and diagrams. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
 	 SYSTEMS AFFECTED: 
 
 Microsoft Visio Viewer 2010 
 
 RISK: 
 Government: 
	 
	 Large and medium government entities:&amp;nbsp;High 
	 Small government entities:&amp;nbsp;High 
	 
	 Businesses: 
	 
	 Large and medium business entities:&amp;nbsp;High 
	 Small ...]]></description>
            
            <guid>2012-010</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-009.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Internet Explorer, Microsoft&apos;s web browser, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 	 SYSTEMS AFFECTED: 
 
 Internet Explorer 6
 Internet Explorer 7
 Internet Explorer 8 
 Internet Explorer 9 
 
 RISK: 
 Government: 
	 
	 Large and medium government ...]]></description>
            
            <guid>2012-009</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-008.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2012-008</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-007.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2012-007</guid>
            <pubdate>Tue, 14 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-006.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple&apos;s OS X and OS X Server that could allow remote code execution. OS X is a desktop operating system for the Apple Mac. OS X Server is a server operating system for the Apple Mac. 
	 These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, while using a vulnerable version of OS X.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2012-006</guid>
            <pubdate>Fri, 03 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-005.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2012-005</guid>
            <pubdate>Wed, 01 Feb 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Symantec pcAnywhere - Updated</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-004b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Symantec pcAnywhere which could allow remote code execution. pcAnywhere is a remote access software solution. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Symantec has released a statement indicating&amp;nbsp;that users should not use pcAnywhere or, at minimum, should block the ports used by pcAnywhere at the perimeter.&amp;nbsp;This is due to a breach in which the source code for ...]]></description>
            
            <guid>2012-004 -UPDATED</guid>
            <pubdate>Mon, 30 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Symantec pcAnywhere</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Symantec pcAnywhere which could allow remote code execution. pcAnywhere is a remote access software solution. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Symantec has released a statement indicating&amp;nbsp;that users should not use pcAnywhere or, at minimum, should block the ports used by pcAnywhere at the perimeter.&amp;nbsp;This is due to a breach in which the source code for ...]]></description>
            
            <guid>2012-004</guid>
            <pubdate>Thu, 26 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-003.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of&amp;nbsp;an affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create and edit&amp;nbsp;PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2012-003</guid>
            <pubdate>Wed, 11 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Could Allow Remote Code Execution (MS12-005)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-002.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in a component of Microsoft Windows.&amp;nbsp;Exploitation may occur if a user opens a specially crafted Microsoft Office file. Successful exploitation&amp;nbsp;will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP
	 Microsoft Vista
	 Microsoft Windows 7
	 Microsoft Windows Server 2003
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government:
	 
	 Large and medium government entities: High
	 	 Small ...]]></description>
            
            <guid>2012-002</guid>
            <pubdate>Tue, 10 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Windows Media Could Allow Remote Code Execution (MS12-004)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2012/2012-001.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Media.&amp;nbsp; One has been identified in the Microsoft Windows Media Player application and another in DirectShow, both of which could allow remote code execution. Windows Media Player is a media library application that is used for playing audio, video, and viewing images.&amp;nbsp; DirectShow is used for streaming media on Windows operating systems. It is a part of DirectX, which is a set of low level Application Programming Interfaces (APIs) used by Windows programs for multimedia support. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as ...]]></description>
            
            <guid>2012-001</guid>
            <pubdate>Tue, 10 Jan 2012 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Reported in the .NET Framework (MS11-100)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-082.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been reported in the Microsoft .NET Framework, specifically in ASP.NET, that could allow remote code execution. ASP.NET allows developers to build dynamic web applications and web services. Successful exploitation of some of the vulnerabilities could result in an attacker gaining the same privileges as the targeted user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; One vulnerability will cause a Denial of Service condition.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft .NET Framework 1.1 
	 Microsoft .NET Framework 2.0 ...]]></description>
            
            <guid>2011-082</guid>
            <pubdate>Thu, 29 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-081.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. 
	 These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2011-081</guid>
            <pubdate>Tue, 20 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-072b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-072 - Updated</guid>
            <pubdate>Mon, 19 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Oracle JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-080.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could impede proper operations. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file.
	 Please note that this update is not part of the Oracle Quarterly Critical Patch Update.&amp;nbsp;&amp;nbsp;The last quarter update was in October 2011.&amp;nbsp;&amp;nbsp;The next update is scheduled for January 10, 2012. ...]]></description>
            
            <guid>2011-080</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-079.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Excel, a spreadsheet application. This vulnerability could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or accessed via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 	 Microsoft Office 2003
	 Microsoft Office 2004 for Mac
	 
	 RISK: ...]]></description>
            
            <guid>2011-079</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows OLE</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-078.cfm</link>
            <description><![CDATA[A remote code execution vulnerability has been discovered in Microsoft Windows Object Linking and Embedding (OLE) technology that could allow attackers to take complete control of affected systems. OLE technology is a Windows protocol that provides a platform for applications to access and manipulate functionalities that are made available by other applications. This vulnerability can be exploited by opening a rich document file format containing a specially crafted OLE object. Successful exploitation could result in an attacker gaining the same privileges as the logged on user.&amp;nbsp;Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-078</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-077.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-077</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-076.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, by visiting a website that is hosting a specially crafted PowerPoint file, or by opening a legitimate PowerPoint file that is located in the same network directory as a specially crafted library file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2011-076</guid>
            <pubdate>Wed, 14 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-075.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office, which is Microsoft&apos;s business application suite, that could allow attackers to take complete control of affected systems. This vulnerability can be exploited by opening a specially crafted Word file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office for Mac 2011 
	 Microsoft ...]]></description>
            
            <guid>2011-075</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX Kill Bits</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-074.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. Exploiting these vulnerabilities could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted e-mail which is specifically crafted to take advantage of one or more of these vulnerabilities. Successful exploitation of any of these vulnerabilities could allow an attacker to gain the same privileges as the ...]]></description>
            
            <guid>2011-074</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-073.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Windows Media Center and Media Player applications that could allow remote code execution. Windows Media Center is a digital video recorder and media player. Windows Media Player is a media library application that is used for playing audio, video, and viewing images. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-073</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-067b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of this vulnerability could result in the escalation of privileges, the creation of denial-of-service conditions, or the execution of arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
	 December 13 - UPDATED OVERVIEW:
 Microsoft has released a patch for this vulnerability in bulletin MS11-087
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP 
	 Microsoft Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2003 
	 Microsoft Windows ...]]></description>
            
            <guid>2011-067 - Updated</guid>
            <pubdate>Tue, 13 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-072.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Reader and Acrobat that could allow an attacker to take control of the affected system. Adobe Reader allows users to view Portable Document Format (PDF) files, while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-072</guid>
            <pubdate>Tue, 06 Dec 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-071.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-071</guid>
            <pubdate>Mon, 14 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-070.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox and Thunderbird applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2011-070</guid>
            <pubdate>Wed, 09 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-069.cfm</link>
            <description><![CDATA[Multiple memory corruption vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-069</guid>
            <pubdate>Wed, 09 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in TCP/IP </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-068.cfm</link>
            <description><![CDATA[A vulnerability has been identified in the Microsoft Windows TCP/IP stack that could allow for remote code execution.&amp;nbsp;The Microsoft Windows TCP/IP stack is an implementation of the TCP/IP protocol, which is used by computer systems worldwide to communicate and exchange data.&amp;nbsp;Successful exploitation could allow attackers to run arbitrary code with kernel mode privileges. This could allow attackers to install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Windows Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government: 
	 
	 Large and ...]]></description>
            
            <guid>2011-068</guid>
            <pubdate>Tue, 08 Nov 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-067.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of this vulnerability could result in the escalation of privileges, the creation of denial-of-service conditions, or the execution of arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
	 It should be noted that there is currently no patch available for this vulnerability and the vulnerability is being actively exploited on the Internet with malware known as Duqu.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Windows XP 
	 Microsoft ...]]></description>
            
            <guid>2011-067</guid>
            <pubdate>Fri, 04 Nov 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-066.cfm</link>
            <description><![CDATA[A security bypass vulnerability has been discovered in Microsoft Outlook Web Access (OWA).&amp;nbsp;Microsoft OWA is a browser-based application that is used to access e-mail, calendars, contacts, tasks, documents, and other Outlook mailbox content remotely.&amp;nbsp;This vulnerability will allow an attacker to login to Outlook user accounts without supplying the user&apos;s authentication credentials. Successful exploitation will result in an attacker gaining unrestricted access to the user&apos;s OWA account. The attacker could then send, view, change, or delete user data such as e-mail, calendar appointments, or tasks, or create auto-forward rules that may allow an attacker to obtain copies of the e-mails. ...]]></description>
            
            <guid>2011-066</guid>
            <pubdate>Wed, 26 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple Mac OS X and Apple Safari</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-065.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple Mac OS X and Apple Safari that could allow remote code execution. Apple Mac OS X is a desktop operating system for the Apple Mac. Apple Safari is a web browser available for Mac OS X and Microsoft Windows. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple Mac OS X or Apple Safari.&amp;nbsp;Successful exploitation will result in an attacker gaining the same privileges as the logged on ...]]></description>
            
            <guid>2011-065</guid>
            <pubdate>Thu, 13 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS11-081) </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-064.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED:
	 
	 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
	 Internet Explorer 9
	 
	 RISK: 
 Government:
	 
	 Large and medium government entities: High
	 Small government ...]]></description>
            
            <guid>2011-064</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-063.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Windows Kernel-Mode Driver. Exploitation of any of these vulnerabilities could result in the escalation of privileges, create Denial of Service conditions, or execute arbitrary code with kernel-level privileges resulting in full control of the affected system.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Windows XP 
	 Microsoft Vista 
	 Microsoft Windows 7 
	 Microsoft Windows Server 2003 
	 Microsoft Windows Server 2008 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities: ...]]></description>
            
            <guid>2011-063</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the Microsoft .NET Framework and Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-062.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and used for streaming media. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application. 
	 Successful exploitation could result in an attacker gaining the same privileges as ...]]></description>
            
            <guid>2011-062</guid>
            <pubdate>Tue, 11 Oct 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-061.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on ...]]></description>
            
            <guid>2011-061</guid>
            <pubdate>Thu, 29 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-060.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product that includes e-mail, calendars, instant messaging, and document management. Successful exploitation of four of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. Failed exploit attempts of these four vulnerabilities may result in a denial of service condition. The remaining vulnerabilities could allow for information disclosure.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-060</guid>
            <pubdate>Tue, 27 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-059.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 There are ...]]></description>
            
            <guid>2011-059</guid>
            <pubdate>Wed, 21 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-058.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Acrobat that could allow attackers to take complete control of affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-058</guid>
            <pubdate>Tue, 13 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-056.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office SharePoint Server 2007 
	 Microsoft Office SharePoint ...]]></description>
            
            <guid>2011-056</guid>
            <pubdate>Tue, 13 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-047b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2011-047 - Updated</guid>
            <pubdate>Thu, 01 Sep 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Remote Desktop Protocol Worm "Morto"</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-055.cfm</link>
            <description><![CDATA[There are reports of a new worm circulating that takes advantage of open port 3389/TCP to compromise systems. No user interaction is required for the host to become compromised. &amp;nbsp;The worm has the capability to infect and subsequently control the impacted hosts.&amp;nbsp;Anti-virus vendors are developing signatures to detect the worm. 
	 SYSTEMS AFFECTED: 
	 
	 All supported versions of Windows Operating Systems 
	 
	 RISK: 
 Government: 
	 
	 Large and medium government entities:&amp;nbsp;High
	 Small government entities:&amp;nbsp;High
	 
	 Businesses: 
	 
	 Large and medium business entities:&amp;nbsp;High
	 Small business entities:&amp;nbsp;High 
	 
	 Home users: High 
	 DESCRIPTION:
	 Over the past ...]]></description>
            
            <guid>2011-055</guid>
            <pubdate>Mon, 29 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-054.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools including a web browser and an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a specially crafted web page.&amp;nbsp;Successful exploitation of these vulnerabilities will result in either an attacker gaining the same privileges as the logged on user, or gaining session authentication credentials. Depending on the privileges ...]]></description>
            
            <guid>2011-054</guid>
            <pubdate>Wed, 17 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in BlackBerry Enterprise </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-053.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the BlackBerry Mobile Data System (MDS) Connection Service and BlackBerry Messaging Agent that could allow remote code execution on the affected BlackBerry Enterprise Server. The MDS Connection Service is used to provide wireless application management across mobile devices. The BlackBerry Messaging Agent is used to provide wireless messaging services to mobile devices. Exploitation of these vulnerabilities could result in the attacker gaining the same privileges as the BlackBerry Enterprise Server service account. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2011-053</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-052.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-052</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-051.cfm</link>
            <description><![CDATA[Multiple memory corruption vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-051</guid>
            <pubdate>Wed, 10 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (MS11-060)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-050.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams.&amp;nbsp;These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an e-mail attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Visio 2003 
	 Microsoft Visio 2007 ...]]></description>
            
            <guid>2011-050</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in DNS Server Could Allow Remote Code Execution (MS11-058)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-049.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Windows DNS Server. The Domain Name System (DNS) is used to translate IP addresses into human-readable domain names. Microsoft includes their implementation of DNS with their Windows Server operating systems. Both vulnerabilities can be exploited by sending a specially crafted DNS query to the affected system. Successful exploitation of the first vulnerability could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Successful exploitation of the second vulnerability could result in ...]]></description>
            
            <guid>2011-049</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer (MS11-057)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-048.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 
	 Internet Explorer 9 
	 
	 RISK: 
 Government: 
	 
	 Large and ...]]></description>
            
            <guid>2011-048</guid>
            <pubdate>Tue, 09 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-047.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2011-047</guid>
            <pubdate>Thu, 04 Aug 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-046.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird, and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a specially crafted file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the ...]]></description>
            
            <guid>2011-046</guid>
            <pubdate>Wed, 22 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-045.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page or if a user opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker ...]]></description>
            
            <guid>2011-045</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-044.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player, which could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted web page or if a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-044</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-043.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Reader and Adobe Acrobat that could allow attackers to take complete control of affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2011-043</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Kernel-Mode Drivers</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-042.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows that could allow for remote code execution when handling specially crafted OpenType fonts (a cross-platform font file format developed jointly by Adobe and Microsoft). OpenType fonts are fonts that are embedded in documents, such as Microsoft Word, or used in web pages. The vulnerability can be exploited if a user visits a network share containing a specially crafted OpenType font. This vulnerability can also be exploited if a user views a web site that contains a link to a network share containing a specially crafted OpenType font. Successful exploitation of this ...]]></description>
            
            <guid>2011-042</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-041.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Excel, a spreadsheet application. These vulnerabilities could allow for remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 Microsoft ...]]></description>
            
            <guid>2011-041</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the Microsoft .NET Common Language Runtime (CLR) and in Microsoft Silverlight</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-040.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and is used for streaming media. This vulnerability can be exploited if a user visits or is redirected to a specially crafted web page, or runs a specially crafted Microsoft .NET or Silverlight application. 
	 Successful exploitation could result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-040</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-039.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft.NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page.
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-039</guid>
            <pubdate>Wed, 15 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Vector Markup Language (VML)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-038.cfm</link>
            <description><![CDATA[A vulnerability has been discovered within Microsoft&apos;s web browser, Internet Explorer, that could allow for remote code execution.&amp;nbsp; Specifically, the vulnerability is in the way Vector Markup Language (VML) is processed by Internet Explorer. VML is an XML-based language used to produce and render vector graphics.&amp;nbsp; Successful exploitation could result in an attacker gaining the same privileges as the logged on user.&amp;nbsp; Depending on the privileges associated with the affected user, an attacker could then install programs, view, change, or delete data; or create accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet ...]]></description>
            
            <guid>2011-038</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-037.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Several of the vulnerabilities can also lead to information disclosure if successfully exploited. 
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6 
	 Internet Explorer 7 
	 Internet Explorer 8 ...]]></description>
            
            <guid>2011-037</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in OLE Automation</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-036.cfm</link>
            <description><![CDATA[A remote code execution vulnerability has been discovered in Microsoft Windows Object Linking and Embedding (OLE) Automation. OLE Automation is a Windows protocol that provides a platform for applications to access and manipulate functionalities that are made available by other applications. This vulnerability can be exploited if a user views a specially crafted Windows Metafile (WMF) image on a web page or by opening a specially crafted WMF file as an e-mail attachment. 
	 Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the ...]]></description>
            
            <guid>2011-036</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft PowerPoint Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-033b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a website that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 June 14 - UPDATED OVERVIEW: 
 Microsoft has announced that the ...]]></description>
            
            <guid>2011-033 - Updated</guid>
            <pubdate>Tue, 14 Jun 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-035b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 One of ...]]></description>
            
            <guid>2011-035 - Updated</guid>
            <pubdate>Wed, 25 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-035.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player that could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. 
	 One of ...]]></description>
            
            <guid>2011-035</guid>
            <pubdate>Fri, 13 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in WINS Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-034.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Windows Internet Name Service (WINS) that could allow remote code execution. WINS is a service that translates computer names to numeric addresses which are needed for computers to communicate with each other. Successful exploitation of this vulnerability could allow an attacker to take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. Failed exploitation attempts may result in a denial-of-service condition. 
	 SYSTEMS AFFECTED: 
	 
	 Windows Server 2003
	 Windows Server 2008
	 
	 RISK:
	 Government:
	 
	 Large and medium government ...]]></description>
            
            <guid>2011-034</guid>
            <pubdate>Tue, 10 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft PowerPoint Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-033.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a website that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft ...]]></description>
            
            <guid>2011-033</guid>
            <pubdate>Tue, 10 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-032.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Mozilla Firefox, Thunderbird and SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same ...]]></description>
            
            <guid>2011-032</guid>
            <pubdate>Mon, 02 May 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-031.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2011-031</guid>
            <pubdate>Fri, 22 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017c.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017 Updated</guid>
            <pubdate>Fri, 22 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017b.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017 Updated</guid>
            <pubdate>Mon, 18 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft HTML Help</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft HTML Help which could allow remote code execution. Microsoft HTML Help allows users to view HTML help files for Windows operating systems.&amp;nbsp;The vulnerability can be exploited if a user opens a specially crafted Microsoft HTML Help file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-030</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Fax Cover Page Editor</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-029.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Fax Cover Page Editor. Windows Fax Cover Page Editor enables users to create, modify, or view computer generated fax cover pages. Windows Fax Cover Page Editor is installed by default on Windows Vista Business Edition, Windows Vista Ultimate Edition, and in all supported editions of Windows 7. &amp;nbsp;This vulnerability can be exploited if a user views a malicious web page, views a specially crafted Windows Fax Cover Page, or opens an e-mail attachment containing a specially crafted image file designed to exploit the vulnerabilities. 
	 Successful exploitation will result in ...]]></description>
            
            <guid>2011-029</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in GDI+ </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-028.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Graphics Device Interface (GDI+). Microsoft GDI+ enables various applications to display images. Microsoft GDI+ is installed by default on all Microsoft Windows operating systems. This vulnerability can be exploited if a user views a malicious web page, views or previews a malicious e-mail message, or opens an e-mail attachment containing a specially crafted image file designed to exploit the vulnerability. 
	 Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, the attacker could then install programs; ...]]></description>
            
            <guid>2011-028</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in JScript and VBScript Scripting Engines</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-027.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft JScript and VBScritping scripting engines. Jscript and VBScript are scripting languages used to enhance the user experience when visiting web pages such as those that display animated content. This vulnerability can be exploited if a user visits a web page with specially crafted content designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-027</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the OpenType Compact Font Format (CFF) Driver </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-026.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows OpenType Compact Font Format driver that could allow for remote code execution. OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or Web pages. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2011-026</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file or a legitimate Microsoft Office file that&amp;nbsp;is located in the same network directory as&amp;nbsp;a malicious library file. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office ...]]></description>
            
            <guid>2011-025</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office ...]]></description>
            
            <guid>2011-024</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Excel </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-023.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office 2007
	 Microsoft Office ...]]></description>
            
            <guid>2011-023</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-022.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a malicious web page while using a Web browser that supports XAML Browser Applications (XBAPs). XAML Browser Applications are applications designed to run in a web browser, utilizing portions of Web Services as well as rich-client (Windows Forms) technologies. 
	 The vulnerability could also allow an attacker to execute ...]]></description>
            
            <guid>2011-022</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX Kill Bits </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-021.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft products that utilize ActiveX controls. Exploiting these vulnerabilities could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted e-mail which is specifically crafted to take advantage of one or more of these vulnerabilities. Successful exploitation of any of these vulnerabilities could allow an attacker to gain the same privileges as the logged on ...]]></description>
            
            <guid>2011-021</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-020.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution. SMB is used to provide shared access to files, printers, serial ports, and for other miscellaneous communications between network devices. Successful exploitation of this vulnerability could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 
	 RISK:
 Government:
	 
	 Large and medium government entities: ...]]></description>
            
            <guid>2011-020</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Client</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-019.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Server Message Block (SMB) Client that could allow for remote code execution. SMB is used to provide shared access to files, printers, serial ports, and for other miscellaneous communication between network devices. These vulnerabilities could be exploited if an attacker hosts a website with a specially crafted Uniform Resource Identifier (URI) or by sending a specially crafted browser message to the victim machine. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user or cause a denial-of-service condition. Depending on the privileges ...]]></description>
            
            <guid>2011-019</guid>
            <pubdate>Wed, 13 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update for Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Several of the vulnerabilities can also lead to information disclosure if successfully exploited.
	 SYSTEMS AFFECTED: 
	 
	 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
	 
	 RISK:
 Government: ...]]></description>
            
            <guid>2011-018</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-017.cfm</link>
            <description><![CDATA[A&amp;nbsp;vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2011-017</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft PowerPoint </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-006b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft PowerPoint, a program used for creating presentations. This vulnerability can be exploited by opening a specially crafted PowerPoint file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note that there is currently no patch available for this vulnerability.
	 UPDATED OVERVIEW:
 Microsoft has ...]]></description>
            
            <guid>2011-006 Updated</guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office Excel </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-005b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
	 Please note that there are ...]]></description>
            
            <guid>2011-005 Updated </guid>
            <pubdate>Tue, 12 Apr 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player - UPDATED</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-016b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player which could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment.Successful exploitation may cause the Adobe Flash Player application to crash and could also result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-016 - Updated</guid>
            <pubdate>Tue, 22 Mar 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-016.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player which could allow attackers to take complete control of affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment.Successful exploitation may cause the Adobe Flash Player application to crash and could also result in an attacker gaining the same privileges ...]]></description>
            
            <guid>2011-016</guid>
            <pubdate>Tue, 15 Mar 2011 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Media</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Windows Media technologies, specifically Windows Media Player, Windows Media Center, and DirectShow.&amp;nbsp; Windows Media Player and Windows Media Center are digital media applications used for playing audio, video, and viewing images. DirectShow is a component of Windows for streaming media and to perform various operations with media files. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2011-015</guid>
            <pubdate>Wed, 09 Mar 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications, which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client. These vulnerabilities may be exploited if a user visits or is redirected to a web page, or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker ...]]></description>
            
            <guid>2011-014</guid>
            <pubdate>Thu, 03 Mar 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Flash Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-013.cfm</link>
            <description><![CDATA[Thirteen security vulnerabilities have been identified in Adobe Flash Player. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the users experience when visiting web pages or reading e-mail messages. These vulnerabilities can be exploited if a user visits a malicious website or opens an e-mail containing Flash media designed to exploit these vulnerabilities. Successful exploitation of one of these vulnerabilities may result in an attacker gaining the same privileges as the logged on user. If the user is logged in with administrator privileges, an attacker could then install programs; view, change, or delete ...]]></description>
            
            <guid>2011-013</guid>
            <pubdate>Wed, 09 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-012.cfm</link>
            <description><![CDATA[Twenty-one vulnerabilities have been discovered in Adobe Shockwave, which could allow an attacker to take complete control of an affected system. Adobe Shockwave is a multimedia platform used to add animation and interactivity to web pages. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2011-012</guid>
            <pubdate>Wed, 09 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-011.cfm</link>
            <description><![CDATA[Twenty-nine vulnerabilities have been discovered in the Adobe Reader and Adobe Acrobat applications, which could allow an attacker to take complete control of an affected system. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the ...]]></description>
            
            <guid>2011-011</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-010.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams. These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an e-mail attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Visio 2002
	 Microsoft Visio 2003
	 Microsoft ...]]></description>
            
            <guid>2011-010</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in the OpenType Compact Font Format (CFF) Driver</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-009.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows OpenType Compact Font Format driver that could allow for remote code execution. OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or web pages. These vulnerabilities can be exploited if a user visits a specially crafted web page or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2011-009</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Information Services (IIS) FTP Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-008.cfm</link>
            <description><![CDATA[A buffer overrun vulnerability has been discovered in Microsoft Internet Information Services (IIS) when using the File Transfer Protocol (FTP) server component. IIS is a set of Internet-based services running on Microsoft Windows servers. FTP is a simple way to exchange files over the file transfer protocol.&amp;nbsp;An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Unsuccessful exploitation attempts may result in a denial of service.
	 SYSTEMS AFFECTED:
	 
	 Windows Vista - Microsoft FTP Service ...]]></description>
            
            <guid>2011-008</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-007.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Internet Explorer 6
	 Internet Explorer 7
	 Internet Explorer 8
 
	 RISK:
 Government: 
	 
 Large and medium government entities: High
	 Small government entities: High ...]]></description>
            
            <guid>2011-007</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft PowerPoint </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-006.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft PowerPoint, a program used for creating presentations. This vulnerability can be exploited by opening a specially crafted PowerPoint file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note that there is currently no patch available for this vulnerability. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2011-006</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-005.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
	 Please note that there are ...]]></description>
            
            <guid>2011-005</guid>
            <pubdate>Tue, 08 Feb 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Novell GroupWise Internet Agent</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Novell GroupWise Internet Agent. Novell GroupWise is a collaborative software product, which includes e-mail, calendars, instant messaging and document management. The GroupWise Internet Agent (GWIA) is a server component that provides communication to other e-mail systems and conversion of e-mail messages to GroupWise format. Successful exploitation could allow an attacker to gain SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Unsuccessful exploitation attempts may result in a denial of service.
	 SYSTEMS AFFECTED: 
	 
 Novell GroupWise Internet Agent 
	 Novell ...]]></description>
            
            <guid>2011-004</guid>
            <pubdate>Wed, 26 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-003.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the BlackBerry Enterprise Server; not the BlackBerry mobile device. Exploitation of this vulnerability may occur when a BlackBerry smartphone user opens a specially crafted PDF file. This could occur by opening an e-mail attachment or clicking on a link in an e-mail or while browsing the Internet. Successful exploitation could result in an attacker gaining the same privileges as the Blackberry Attachment Service. Depending ...]]></description>
            
            <guid>2011-003</guid>
            <pubdate>Wed, 12 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Data Access Components</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-002.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Data Access Components which could allow an attacker to take complete control of an affected system. Microsoft Data Access Components (MDAC) is a collection of applications that make it easy for programs to access databases. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2011-002</guid>
            <pubdate>Wed, 12 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2010-108b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp;Failed exploit attempts may result in ...]]></description>
            
            <guid>2010-108 Updated</guid>
            <pubdate>Tue, 11 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Graphics Rendering Engine</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2011/2011-001.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows Graphics Rendering Engine, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user views a specially crafted thumbnail image.&amp;nbsp;In an e-mail or web-based attack scenario, exploitation may occur if a user opens or previews a document containing a specially crafted thumbnail image received as an e-mail attachment or hosted on a website. Alternatively, an attacker can place the specially crafted thumbnail image on a network share and if a user navigates to the file location using Windows Explorer exploitation will occur. Successful ...]]></description>
            
            <guid>2011-001</guid>
            <pubdate>Wed, 05 Jan 2011 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-108.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp;Failed exploit attempts may result in ...]]></description>
            
            <guid>2010-108</guid>
            <pubdate>Tue, 21 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-107.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of the BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the BlackBerry Enterprise Server; not the BlackBerry mobile device.&amp;nbsp;Successful exploitation could result in an attacker gaining the same privileges&amp;nbsp;as the Blackberry Attachment Service. Depending on the privileges associated with the service, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
	 SYSTEMS AFFECTED: 
	 
	 BlackBerry ...]]></description>
            
            <guid>2010-107</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple vulnerabilities in Microsoft Office Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-106.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This file may be received as an e-mail attachment, or downloaded via the Web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2010-106</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Graphics Filters</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-105.cfm</link>
            <description><![CDATA[Seven vulnerabilities have been discovered in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities can be exploited by opening a specially crafted Microsoft Office document received as an e-mail attachment, or downloaded via the Web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions.
	 SYSTEMS AFFECTED:&amp;nbsp;
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 Microsoft ...]]></description>
            
            <guid>2010-105</guid>
            <pubdate>Wed, 15 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the OpenType Font (OTF) Driver </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-104.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Microsoft Windows OpenType Font (OTF) driver that could allow for remote code execution. OpenType fonts are fonts that are embedded in documents or used in web pages. The vulnerabilities can be exploited if a user visits a network share that contains a specially crafted OpenType Font. These vulnerabilities are triggered by the Details and Preview panes in Windows Explorer. These vulnerabilities can also be exploited if a user&amp;nbsp;views a specially crafted OpenType font using a third-party web browser. In this scenario, the vulnerability could be triggered if a user views a web ...]]></description>
            
            <guid>2010-104</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-103.cfm</link>
            <description><![CDATA[Seven vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet ...]]></description>
            
            <guid>2010-103</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097 - Updated</guid>
            <pubdate>Tue, 14 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-102.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to a web page or opens a malicious file that is specifically designed to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker ...]]></description>
            
            <guid>2010-102</guid>
            <pubdate>Fri, 10 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-100a.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted file and can be exploited via e-mail or through the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 UPDATED OVERVIEW:
Microsoft has released a patch which addresses the vulnerabilities in Microsoft Office 2008 for Mac.
	 SYSTEMS ...]]></description>
            
            <guid>2010-100 -  Updated</guid>
            <pubdate>Fri, 10 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-101.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an e-mail attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2010-101</guid>
            <pubdate>Wed, 08 Dec 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095 - Updated</guid>
            <pubdate>Wed, 17 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-100.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office, which is Microsoft&apos;s business application suite. These vulnerabilities could allow remote code execution if a user opens a specially crafted file and can be exploited via e-mail or through the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft Office 2004 for Mac
	 Microsoft Office 2007 ...]]></description>
            
            <guid>2010-100</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-099.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint file received as an e-mail attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Microsoft Office XP
	 Microsoft Office 2003
	 Microsoft ...]]></description>
            
            <guid>2010-099</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-098.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product that includes e-mail, calendars, instant messaging and document management. Successful exploitation of four of these vulnerabilities could result in an attacker gaining system level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. The remaining vulnerabilities could allow for information disclosure. Failed exploit attempts may result in a denial of service condition.
	 SYSTEMS AFFECTED:
	 
 Novell GroupWise ...]]></description>
            
            <guid>2010-098</guid>
            <pubdate>Tue, 09 Nov 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095 - Updated</guid>
            <pubdate>Fri, 05 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097 - Updated</guid>
            <pubdate>Thu, 04 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-097.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 It should be noted that ...]]></description>
            
            <guid>2010-097</guid>
            <pubdate>Wed, 03 Nov 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-096.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page. Exploitation may also occur when a user opens a specially crafted Shockwave (SWF) file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2010-096</guid>
            <pubdate>Fri, 29 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-093b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a widely used multimedia application used to display animations and video when visiting websites. This vulnerability can be exploited by visiting a web page that contains a malicious Adobe Shockwave file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user within the scope of the application. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2010-093 - Updated</guid>
            <pubdate>Fri, 29 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-095.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Flash Player, Reader, and Acrobat that could allow remote code execution. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is used to view animations and movies using a web browser. This vulnerability can be exploited if a user visits a specially crafted web page or opens a malicious Flash Player, Reader, or Acrobat file designed to exploit this vulnerability. Successful exploitation may result in an attacker gaining the same privileges as the ...]]></description>
            
            <guid>2010-095</guid>
            <pubdate>Thu, 28 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-094b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered for Mozilla Firefox that could allow attackers to execute arbitrary code on affected systems. Mozilla Firefox is a web browser used to access the Internet. Exploitation can occur if a user visits a webpage designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition. ...]]></description>
            
            <guid>2010-094 Updated</guid>
            <pubdate>Thu, 28 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-094.cfm</link>
            <description><![CDATA[An vulnerability has been discovered for Mozilla Firefox that could allow attackers to execute arbitrary code on affected systems. Mozilla Firefox is a web browser used to access the Internet. Exploitation can occur if a user visits a webpage designed to take advantage of this vulnerability. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition. ...]]></description>
            
            <guid>2010-094</guid>
            <pubdate>Wed, 27 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-093.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Shockwave Player that could allow remote code execution. Adobe Shockwave Player is a widely used multimedia application used to display animations and video when visiting websites. This vulnerability can be exploited by visiting a web page that contains a malicious Adobe Shockwave file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user within the scope of the application. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. ...]]></description>
            
            <guid>2010-093</guid>
            <pubdate>Thu, 21 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-092.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an e-mail client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an e-mail client.
	 Exploitation may occur if a user visits, or is redirected to, a web page or opens a malicious file that is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the ...]]></description>
            
            <guid>2010-092</guid>
            <pubdate>Wed, 20 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in BlackBerry Attachment Service</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-091.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the BlackBerry Attachment Service. The BlackBerry Attachment Service is a component of BlackBerry Enterprise Server and BlackBerry Professional Software that is used to process e-mail attachments. This vulnerability affects the Blackberry Enterprise Server; not the Blackberry mobile device. Successful exploitation may result in an attacker gaining complete control of the Blackberry Enterprise Server. Depending on the privileges associated with the service, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.
 
 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-091</guid>
            <pubdate>Thu, 14 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Windows Kernel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-090.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in the Microsoft Windows Kernel-Mode driver which could allow for privilege escalation. Utilizing these vulnerabilities, an attacker could escalate privileges and execute arbitrary code with kernel-level privileges resulting in full control of the affected machine.&amp;nbsp; An attacker could then install programs; view, change, or delete data; or create new accounts with full system rights.
 
 Microsoft has reported that this vulnerability is being actively exploited at this time as part of the Stuxnet worm.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 Windows Server 2008 R2 ...]]></description>
            
            <guid>2010-090</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in COM Validation in Windows Shell and WordPad</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-089.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Windows Shell and WordPad which could allow remote code execution.&amp;nbsp; Windows Shell provides users with access to objects necessary for running applications and managing the Windows Operating System.&amp;nbsp; WordPad is a word processor application that is included in Microsoft Windows. This vulnerability may be exploited by opening a malicious WordPad document received as an e-mail attachment, or by visiting a website that is hosting a malicious WordPad document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an ...]]></description>
            
            <guid>2010-089</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-088.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Windows Media Player. Windows Media Player is a digital media player and media library application that is used for playing audio, video, and viewing images. Exploitation can occur if a user visits a specially crafted website. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
	 Windows XP
	 Windows Server 2003
	 Windows Vista ...]]></description>
            
            <guid>2010-088</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Common Control Library</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-087.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Windows Common Control Library that could allow an attacker to take complete control of a vulnerable system. The Windows Common Control Library is a set of interfaces that enables a user to interact with an application and is used by all supported versions of the Windows Operating System. Many popular third-party programs utilize this interface including web browsers such as Mozilla Firefox and Google Chrome.
&amp;nbsp;
This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same ...]]></description>
            
            <guid>2010-087</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-086.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an e-mail attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Windows Office XP 
 Windows Office 2003
 Windows Office 2007 ...]]></description>
            
            <guid>2010-086</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Word</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-085.cfm</link>
            <description><![CDATA[Eleven vulnerabilities have been discovered in Microsoft Office Word. These vulnerabilities can be exploited by opening a malicious Word document received as an email attachment, or by visiting a website that is hosting a malicious Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
	 SYSTEMS AFFECTED:
	 
 Windows Office XP 
 Windows Office 2003
 Windows ...]]></description>
            
            <guid>2010-085</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in .NET Framework</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-084.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft .NET Framework which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. This vulnerability may be exploited if a user visits or is redirected to a malicious web server running a specially crafted ASP.NET page. 
	 Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2010-084</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows Embedded OpenType Engine</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-083.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Embedded OpenType (EOT) Font Engine that could allow for remote code execution. EOT Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or web pages. This vulnerability can be exploited if a user visits a specially crafted web page or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or ...]]></description>
            
            <guid>2010-083</guid>
            <pubdate>Wed, 13 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-082.cfm</link>
            <description><![CDATA[Ten vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED:
	 
 Internet Explorer ...]]></description>
            
            <guid>2010-082</guid>
            <pubdate>Tue, 12 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player, Adobe Reader, Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077d.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 - Updated</guid>
            <pubdate>Wed, 06 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Adobe Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-074b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated ...]]></description>
            
            <guid>2010-074 - Updated</guid>
            <pubdate>Wed, 06 Oct 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Flash Player - Updated 9/21</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 Updated</guid>
            <pubdate>Tue, 21 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Flash Player - Updated 9/20</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077 Updated</guid>
            <pubdate>Mon, 20 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Remote Procedure Call</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-081.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the way Microsoft Windows handles a specially crafted RPC response. Remote Procedure Call (RPC) is a protocol that is used to request a service from a program that is located on another computer that is on the same network.
	 This vulnerability may be exploited by sending a specially crafted RPC response. Successful exploitation will result in an attacker gaining the same privileges as the RPC client application. Depending on the privileges associated with the RPC client application, an attacker could then install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2010-081</guid>
            <pubdate>Wed, 15 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (MS10-063)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-080.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Windows and Microsoft Office which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; The vulnerability is caused when Windows or Office incorrectly parses specific font types.&amp;nbsp;This may be exploited if a user opens a specially crafted document or web page viewed in an application which supports embedded OpenType fonts. OpenType is a modern font format developed by Adobe and Microsoft to provide users with an accessible and advanced typographic toolset. Successful exploitation of this vulnerability will result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-080</guid>
            <pubdate>Wed, 15 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in MPEG-4 Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-079.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft MPEG-4 Codec that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress digital media content, such as a song or video. This vulnerability may be exploited if a user opens a specially crafted file, visits or is redirected to a specifically crafted web page. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-079</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Print Spooler</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-078.cfm</link>
            <description><![CDATA[A vulnerability has been identified in the Microsoft Print Spooler service. The Print Spooler service is used for local and remote printing and is enabled on Windows systems by default. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Successful exploitation of this vulnerability could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. 
	 Microsoft has reported that the vulnerability is being actively exploited at this time. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-078</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Flash Player, Adobe Reader, and</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-077.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Flash Player, Adobe Acrobat, and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems.&amp;nbsp; Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading email messages. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. 
	 This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when ...]]></description>
            
            <guid>2010-077</guid>
            <pubdate>Tue, 14 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Here You Have - Email Worm</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-076.cfm</link>
            <description><![CDATA[A mass mailing worm has recently been propagating aggressively across the Internet with the subject lines &amp;quot;Here you have&amp;quot; or &amp;quot;Just For you&amp;quot;. The email includes a link disguised to look like a .PDF or a .WMV file, but is actually a link to a .SCR file that contains malicious code. Clicking on the malicious hyperlink will result in compromise of the affected machine and spread of the mass mailing worm to other computers.
	 In&amp;nbsp;addition to the media accounts of impacted businesses, we have received reports that several states that have been impacted by this mass mailing email worm. ...]]></description>
            
            <guid>2010-076</guid>
            <pubdate>Fri, 10 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-075.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla&amp;nbsp;SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla&amp;nbsp;SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. 
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities will result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-075</guid>
            <pubdate>Fri, 10 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-074.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated ...]]></description>
            
            <guid>2010-074</guid>
            <pubdate>Thu, 09 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-071b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2010-071 Updated</guid>
            <pubdate>Tue, 07 Sep 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-073.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. This vulnerability can be exploited&amp;nbsp;if a user visits or is redirected to a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2010-073</guid>
            <pubdate>Tue, 31 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows Applications</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-072.cfm</link>
            <description><![CDATA[A new exploitation technique has been identified for a previously known vulnerability affecting Microsoft Windows applications which could allow an attacker to take complete control of an affected system. Microsoft Windows applications are any applications that run on the Microsoft Windows operating system. An attacker can exploit this vulnerability when a user runs a Windows application that does not load external libraries securely. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-072</guid>
            <pubdate>Fri, 27 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-071.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat and Adobe Reader applications which could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files while Adobe Acrobat offers users additional features such as the ability to create PDF files. This vulnerability may be exploited if a user visits or is redirected to a specially crafted web page or when a user opens a specially crafted PDF file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges ...]]></description>
            
            <guid>2010-071</guid>
            <pubdate>Thu, 26 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-070.cfm</link>
            <description><![CDATA[Adobe has provided an update which&amp;nbsp;addresses multiple vulnerabilities in Adobe Shockwave Player. These vulnerabilities could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specially crafted web page. Exploitation may also occur when a user opens a specially crafted Shockwave (SWF) file. Successful exploitation will result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could ...]]></description>
            
            <guid>2010-070</guid>
            <pubdate>Wed, 25 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-067b.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a website hosting malicious content or opens an email attachment containing Flash media designed to exploit these vulnerabilities.
	 Successful exploitation of five of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-067 Updated</guid>
            <pubdate>Fri, 20 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-056b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 There ...]]></description>
            
            <guid>2010-056 Updated</guid>
            <pubdate>Fri, 20 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple QuickTime Player</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-069.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple QuickTime Player that could allow remote code execution. Apple QuickTime Player is used to play media files on Microsoft Windows and Mac OS X operating systems. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including an email attachment, using a vulnerable version of Apple QuickTime Player. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2010-069</guid>
            <pubdate>Tue, 17 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Flash Media Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-068.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Media Server that could allow an attacker to take complete control of an application. Adobe Flash Media Server is an application server product which can stream rich content applications. Successful exploitation of one of these vulnerabilities could result in remote code execution. The attacker could then perform actions in the context of the application. The remaining vulnerabilities could allow for a denial-of-service condition.
 SYSTEMS AFFECTED: 
 
 Adobe Flash Media Server (FMS) 3.5.3 and earlier for Windows and UNIX
 Adobe Flash Media Server 3.0.5 and earlier versions for Windows and UNIX ...]]></description>
            
            <guid>2010-068</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-067.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a website hosting malicious content or opens an email attachment containing Flash media designed to exploit these vulnerabilities. 
	 Successful exploitation of five of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-067</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-066.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Internet ...]]></description>
            
            <guid>2010-066</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-065.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP and Vista systems. This vulnerability could allow remote code execution if a user opens a specially crafted Windows Movie Maker project file (.MSWMM). The file may be received as an email attachment, on removable media, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-065</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft MPEG Layer-3 Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-064.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft MPEG Layer-3 Codec for Microsoft DirectShow that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress digital media content, such as a song or video. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then ...]]></description>
            
            <guid>2010-064</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Cinepak Codec</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-063.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Cinepak Codec, which is used to compress and decompress digital media files. Cinepak is the primary video codec application for Microsoft Video for Windows and is used to compress and decompress digital media files. This vulnerability could allow remote code execution if a user opens a specially crafted media file (e.g. an AVI file). This vulnerability can be exploited via an email attachment or through the web. Successful exploitation of this vulnerability could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with ...]]></description>
            
            <guid>2010-063</guid>
            <pubdate>Wed, 11 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-062.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office Excel, a spreadsheet application. This vulnerability could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
 	SYSTEMS AFFECTED: 
 	
 	 Microsoft Office XP
 	 Microsoft Office 2003 ...]]></description>
            
            <guid>2010-062</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Word</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-061.cfm</link>
            <description><![CDATA[Four vulnerabilities have been discovered in Microsoft Office Word. These vulnerabilities can be exploited by opening a malicious Word document received as an email attachment, or by visiting a website that is hosting a malicious Word document. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploitation could result in denial-of-service conditions. 
 	SYSTEMS AFFECTED: 
 	
 Microsoft Office XP 
 	 Microsoft ...]]></description>
            
            <guid>2010-061</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-060.cfm</link>
            <description><![CDATA[Three vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution or denial of service. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Successful exploitation of one of these vulnerabilities could result in an attacker gaining complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The other vulnerabilities will result in denial of service conditions.
	 SYSTEMS AFFECTED: 
	 
	 Windows XP
 Windows Server 2003 ...]]></description>
            
            <guid>2010-060</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the Microsoft .NET</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-059.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft .NET Framework and Microsoft Silverlight which could allow an attacker to take complete control of an affected system. Microsoft .NET is a software framework for applications designed to run under Microsoft Windows. Microsoft Silverlight is a web application framework that provides support for .NET applications and used for streaming media. These vulnerabilities can be exploited if a user visits or is redirected to a malicious web page, runs a specially crafted Microsoft .NET application or runs a specially crafted Silverlight application. Successful exploitation could result in an attacker gaining the same ...]]></description>
            
            <guid>2010-059</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS10-051)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-058.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft XML Core Services which could allow remote code execution. Microsoft XML Core Services is installed by default on all Windows systems, and is used to enhance the user experience on web pages. This vulnerability may be exploited if a user visits, or is redirected to, a specifically crafted web page or opens a specially crafted HTML formatted email. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. If the user is logged in with administrative privileges, an attacker could then install programs; view, change, or ...]]></description>
            
            <guid>2010-058</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SChannel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-057.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft SChannel which could allow an attacker to take complete control of a vulnerable system. Microsoft SChannel, or Secure Channel, implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. SSL and TLS are commonly used to implement secure communications for web browsing and other network services. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. If successfully exploited, the attacker could gain SYSTEM level privileges and install programs, view, change, or delete data, or create new accounts with full ...]]></description>
            
            <guid>2010-057</guid>
            <pubdate>Tue, 10 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products Vulnerability</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-056.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. ...]]></description>
            
            <guid>2010-056</guid>
            <pubdate>Thu, 05 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053d.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 Updated</guid>
            <pubdate>Mon, 02 Aug 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Mozilla Firefox</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-055.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Mozilla Firefox which could allow for remote code execution. Mozilla Firefox is a web browser used to access the Internet.
	 This vulnerability requires that a user visit or be redirected to a web page, or open a malicious file crafted to take advantage of this specific vulnerability. This vulnerability, if exploited, could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts ...]]></description>
            
            <guid>2010-055</guid>
            <pubdate>Mon, 26 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-054.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-054</guid>
            <pubdate>Wed, 21 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 - Updated</guid>
            <pubdate>Wed, 21 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053 - Updated</guid>
            <pubdate>Tue, 20 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-053.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell, component of Microsoft Windows Operating System, that could allow automatic file execution. Specifically this vulnerability exists because Microsoft Windows incorrectly parses shortcuts (LNK files) in such a way that malicious code may be executed when the user views the displayed icon of a specially crafted shortcut. Successful exploitation may result in an attacker gaining at least the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user ...]]></description>
            
            <guid>2010-053</guid>
            <pubdate>Sat, 17 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Novell GroupWise</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-052.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Novell GroupWise applications that could allow an attacker to take complete control of a vulnerable system. Novell GroupWise is a collaborative software product which includes email, calendars, instant messaging and document management. Successful exploitation of two of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges on the affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full privileges. The remaining vulnerabilities could allow for information disclosure. Failed exploit attempts may result in denial of service condition.
	 SYSTEMS AFFECTED: 
	 
	 Novell Groupwise ...]]></description>
            
            <guid>2010-052</guid>
            <pubdate>Fri, 16 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution (MS10-044)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-051.cfm</link>
            <description><![CDATA[Vulnerabilities have been discovered in Microsoft Office Access ActiveX control that could allow an attacker to take complete control of a vulnerable system. Microsoft Office Access is a database management system. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Exploitation may occur if a user visits a web page, or opens an HTML-formatted email, which are specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could allow an attacker to gain the same privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-051</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution (MS10-045)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-050.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Office Outlook. Microsoft Office Outlook is an email client.&amp;nbsp; Exploitation of this vulnerability requires that a user open an attachment in a specially crafted e-mail message with a vulnerable version of Microsoft Office Outlook. Successful exploitation of the vulnerability could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 2007 ...]]></description>
            
            <guid>2010-050</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046d.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Tue, 13 Jul 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040 - Updated</guid>
            <pubdate>Tue, 29 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-049.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits, or is redirected to, a web page or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the ...]]></description>
            
            <guid>2010-049</guid>
            <pubdate>Wed, 23 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Novell Netware</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-048.cfm</link>
            <description><![CDATA[This advisory only pertains to organizations that use Novell Netware for local area network services. Novell Netware provides services such as browsing or accessing NetWare directories, transferring or sharing files, and printing services. A vulnerability has been discovered in the Novell Netware Server Message Block (SMB) which could cause a buffer-overflow to occur. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. This vulnerability will allow an attacker to execute arbitrary code on the affected system. If successfully exploited, the attacker could gain kernel level privileges and install programs, ...]]></description>
            
            <guid>2010-048</guid>
            <pubdate>Thu, 17 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046c.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Wed, 16 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-047.cfm</link>
            <description><![CDATA[Thirty vulnerabilities have been discovered in Adobe Flash Player and Adobe AIR. Adobe Flash Player is a widely distributed multimedia and application player for Microsoft Windows, Mozilla, and Apple systems. It is used to enhance the user experience when visiting web pages or reading email messages. Adobe AIR is a cross-platform runtime for developing Internet applications on the desktop. These vulnerabilities can be exploited if a user visits a malicious website or opens an email attachment containing Flash media designed to exploit these vulnerabilities. 
	 Successful exploitation of twenty seven of these vulnerabilities could result in an attacker gaining ...]]></description>
            
            <guid>2010-047</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046b.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046 - Updated</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040 - Updated</guid>
            <pubdate>Fri, 11 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-046.cfm</link>
            <description><![CDATA[Two vulnerabilities have been identified in Microsoft Windows Help and Support Center that could allow an attacker to take complete control of an affected system. The Help and Support Center is a feature in Windows that provides help on a variety of topics. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published ...]]></description>
            
            <guid>2010-046</guid>
            <pubdate>Thu, 10 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in COM Validation in Microsoft Office Could Allow Remote Code Execution (MS10-036)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-045.cfm</link>
            <description><![CDATA[A vulnerability has been identified in Microsoft Office, Microsoft&apos;s business application suite. This vulnerability could allow remote code execution if a user opens a specially crafted Office document. The document may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP 
	 Microsoft Office 2003 
	 2007 Microsoft ...]]></description>
            
            <guid>2010-045</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-044.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office Excel, a spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The file may be received as an email attachment, or downloaded via the web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Office XP
	 Microsoft Office 2003
	 2007 Microsoft Office System ...]]></description>
            
            <guid>2010-044</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Cumulative Security Update of ActiveX</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-043.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. ActiveX controls are small programs or animations that are downloaded or embedded in web pages which will typically enhance functionality and user experience. Many web design and development tools have built ActiveX support into their products, allowing developers to both create and make use of ActiveX controls in their programs. There are more than 1,000 existing ActiveX controls available for use today.
	 When vulnerabilities are discovered in ActiveX controls, attackers may use specially crafted web pages to exploit these vulnerabilities. Successful exploitation will result in ...]]></description>
            
            <guid>2010-043</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Media Decompression</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-042.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in Microsoft Windows that could allow a remote attacker to take complete control of an affected system. The vulnerabilities exist in the way Microsoft Windows handles media files. Exploitation can occur if a user visits a malicious web page or opens a malicious media file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-042</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer Could Allow Remote Code Execution (MS10-035)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-041.cfm</link>
            <description><![CDATA[Six vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-041</guid>
            <pubdate>Tue, 08 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-040.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Adobe Acrobat, Adobe Reader and Adobe Flash Player applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Adobe Flash Player is a multimedia and application player used to enhance the user experience when visiting web pages or other media which incorporate Flash (.swf) files.
	 Exploitation can occur if a user visits or is redirected to a malicious webpage or if a user opens a ...]]></description>
            
            <guid>2010-040</guid>
            <pubdate>Mon, 07 Jun 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027c.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027 Updated</guid>
            <pubdate>Wed, 19 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Adobe Shockwave Player Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-039.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Shockwave Player which could allow an attacker to take complete control of an affected system. Adobe Shockwave Player is a prevalent multimedia application used to display animations and video. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted Shockwave (SWF) file. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2010-039</guid>
            <pubdate>Wed, 12 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Visual Basic</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-038.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Visual Basic for Applications (VBA). VBA is used for developing client desktop packaged applications and integrating them with existing data and systems. Exploitation may occur if a user opens a specially crafted file which supports VBA and can be exploited via email or through the Web. This can be a Word document, an Excel spreadsheet, a PowerPoint presentation or any other type of document that uses VBA. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an ...]]></description>
            
            <guid>2010-038</guid>
            <pubdate>Tue, 11 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Microsoft Windows Server Vulnerabilities</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-037.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in the Microsoft SMTP (Simple Mail Transfer Protocol) service that could lead to the disclosure of information. Microsoft Windows SMTP service is a component that allows emails to be sent and received. These vulnerabilities could be exploited if an attacker creates a specially crafted query that is designed to exploit these vulnerabilities. This could allow an attacker to redirect network traffic which could lead to the unauthorized disclosure of information.
	 Please note that both of these vulnerabilities were fixed by the patches referenced in MS10-024, dated April 13, 2010, but were not disclosed ...]]></description>
            
            <guid>2010-037</guid>
            <pubdate>Thu, 06 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-019b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker and Microsoft Producer which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP systems. Microsoft Producer is a downloadable add-in component for Microsoft Office PowerPoint that can be used open and edit video files. Exploitation may occur if a user visits a web page or opens an email attachment which is crafted specifically to take advantage of this vulnerability. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-019 Updated</guid>
            <pubdate>Tue, 04 May 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in HP Operations Manager</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-036.cfm</link>
            <description><![CDATA[HP has issued a patch to remedy a vulnerability in HP Operations Manager. HP Operations Manager is a management console that correlates data from the network infrastructure. This vulnerability exists in an ActiveX control that will allow an attacker to download malicious files. ActiveX controls are small programs or animations that are downloaded or embedded in websites which will typically enhance functionality and user experience. This vulnerability can be exploited if a user visits or is redirected to a specially crafted webpage hosting a malicious file designed to take advantage of the vulnerability. Successful exploitation may result in an ...]]></description>
            
            <guid>2010-036</guid>
            <pubdate>Tue, 20 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027b.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027 Updated</guid>
            <pubdate>Thu, 15 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Cisco Security Desktop</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-035.cfm</link>
            <description><![CDATA[A vulnerability exists in an ActiveX control on Cisco Secure Desktop (CSD) that will allow an attacker to download malicious files.&amp;nbsp; CSD is a tool provided by Cisco to extend the security of Secure Socket Layer Virtual Private Networks (SSL VPN) to a user&apos;s work station. ActiveX controls are small programs or animations that are downloaded or embedded in Web pages which will typically enhance functionality and user experience. Secure Socket Layer (SSL) is a protocol used for transmitting documents securely via the Internet. SSL is the most widely used protocol for secure network communication. A Virtual Private Network ...]]></description>
            
            <guid>2010-035</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office Publisher</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-033.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Publisher, which could allow an attacker to take complete control of an affected system. Microsoft Publisher, a component of Microsoft Office, is an application that allows users to create marketing materials and other types of publications. Exploitation may occur if a user opens a specially crafted Publisher file. This document may be received as an email attachment, or downloaded via the Web. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; ...]]></description>
            
            <guid>2010-033</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Media Player 9 </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-032.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the ActiveX control for Microsoft Windows Media Player 9 which is utilized when accessing online media content such as music or a video. Microsoft Windows Media Player 9 is installed on all versions of Windows XP &amp;amp; 2000 by default. When vulnerabilities are discovered in the ActiveX controls, attackers may use specially crafted web pages to exploit these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, ...]]></description>
            
            <guid>2010-032</guid>
            <pubdate>Wed, 14 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Visio</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-034.cfm</link>
            <description><![CDATA[Two new vulnerabilities have been discovered in Microsoft Visio, a program used for creating flowcharts and diagrams. These vulnerabilities can be exploited by opening a specially crafted Visio file (.VSD) received as an email attachment, or by visiting a website and opening a specially crafted Visio file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 Microsoft Visio 2002 
	 Microsoft Visio ...]]></description>
            
            <guid>2010-034</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Reader and Adobe Acrobat Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-031.cfm</link>
            <description><![CDATA[Multiple vulnerabilities discovered in the Adobe Acrobat and Adobe Reader applications that could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. These vulnerabilities can be exploited if a user opens a specially crafted file designed to take advantage of the vulnerabilities. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, ...]]></description>
            
            <guid>2010-031</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (MS10-026)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-030.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft MPEG Layer-3 codecs that could allow an attacker to take complete control of a vulnerable system. A codec is software that is used to compress or decompress a digital media file, such as a song or video. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs, view, ...]]></description>
            
            <guid>2010-030</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Client Could Allow Remote Code Execution (MS10-020)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-029.cfm</link>
            <description><![CDATA[Five vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Client that could allow for remote code execution or denial of service. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. These vulnerabilities could be exploited if an attacker hosts a specially crafted SMB server that is designed to exploit these vulnerabilities and then convinces a user to initiate an SMB connection with the attacker. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user or cause a denial-of-service ...]]></description>
            
            <guid>2010-029</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Windows Could Allow Remote Code Execution (MS10-019)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-028.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Windows Authenticode Signature Verification function which could allow for remote code execution. Authenticode is a digital signature format that is used to determine the origin and integrity of software files. These vulnerabilities can be exploited when a user opens a specially crafted signed portable executable (PE)&#xc2;&#xa0; or cabinet file (CAB) which is a file that has been compressed, or reduced in size, to save storage space and allow faster transferring across a network. Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending ...]]></description>
            
            <guid>2010-028</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016 Updated</guid>
            <pubdate>Tue, 13 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in the JRE Java Platform</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-027.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Oracle Java (formerly known as Sun Java) Runtime Environment (JRE) that could allow attackers to take complete control of a vulnerable system. The Java Runtime Environment is used to enhance the user experience when visiting web sites and is installed on most desktops and servers. These vulnerabilities may be exploited if a user visits or is redirected to a specifically crafted web page, or opens a specially crafted file. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the ...]]></description>
            
            <guid>2010-027</guid>
            <pubdate>Fri, 09 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in VMware Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-026.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in VMware products that could allow an attacker to gain unauthorized access or take complete control of a vulnerable system. VMware products are used to create and/or run multiple virtual operating systems on a single device. Virtualization is becoming increasingly popular in order to minimize infrastructure costs. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same privileges as the logged on user or specialized processes. Depending on the privileges associated with the user or specialized processes, an attacker could install programs; view, change, or delete data; or create new ...]]></description>
            
            <guid>2010-026</guid>
            <pubdate>Fri, 09 Apr 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-025.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client.
	 These vulnerabilities may be exploited if a user visits or is redirected to a webpage or opens a malicious file specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in either an attacker gaining the same ...]]></description>
            
            <guid>2010-025</guid>
            <pubdate>Wed, 31 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Apple QuickTime Player Could Allow for Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-024.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Apple QuickTime Player. QuickTime Player is used to play multimedia files on Microsoft Windows and Mac OS X operating systems. These vulnerabilities can be exploited if a user visits a malicious webpage or opens a malicious file, including an e-mail attachment, using a vulnerable version of QuickTime Player. Successful exploitation may result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-024</guid>
            <pubdate>Wed, 31 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-023.cfm</link>
            <description><![CDATA[Ten vulnerabilities have been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
 Windows ...]]></description>
            
            <guid>2010-023</guid>
            <pubdate>Tue, 30 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 March 11- UPDATED OVERVIEW:
 Exploit code is publicly available. The exploit code has also been added ...]]></description>
            
            <guid>2010-021 Updated</guid>
            <pubdate>Tue, 30 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-022.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox, Mozilla Thunderbird and Mozilla SeaMonkey applications which could allow remote code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Thunderbird is an email client. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. The Mozilla applications (Firefox and SeaMonkey) utilize the same framework to display application specific information (e.g. webpages, emails, chats).
	 These vulnerabilities may be exploited if a user visits a webpage or opens a malicious file specifically crafted to take advantage of these ...]]></description>
            
            <guid>2010-022</guid>
            <pubdate>Wed, 24 Mar 2010 04:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 March 11 - UPDATED OVERVIEW:
Exploit code is publicly available. The exploit code has also been added to ...]]></description>
            
            <guid>2010-021 Updated</guid>
            <pubdate>Thu, 11 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-021.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: At this time, Microsoft is aware of targeted attacks attempting to exploit this vulnerability.&amp;nbsp; ...]]></description>
            
            <guid>2010-021</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft Office Excel</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-020.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been identified in Microsoft Office Excel, Microsoft&apos;s spreadsheet application. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel document. The document may be received as an email attachment, or downloaded via the Web. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&amp;nbsp; 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Excel 2002
	 Microsoft Excel 2003
	 Microsoft Excel 2007 ...]]></description>
            
            <guid>2010-020</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Movie Maker</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-019.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Movie Maker and Microsoft Producer which could allow an attacker to take complete control of an affected system. Windows Movie Maker is a video editing application available for Microsoft Windows, which is installed by default on Windows XP systems. Microsoft Producer is a downloadable add-in component for Microsoft Office PowerPoint that can be used open and edit video files. Exploitation may occur if a user visits a web page or opens an email attachment which is crafted specifically to take advantage of this vulnerability. Depending on the privileges associated with the user, ...]]></description>
            
            <guid>2010-019</guid>
            <pubdate>Tue, 09 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Security Vulnerabilities found </title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-018.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Apache Software Foundation&apos;s Apache HTTP Server. Apache HTTP Server is one of the most widely used web servers. Successful exploitation of one of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts. Failed attacks may result in denial-of-service conditions.
	 SYSTEMS AFFECTED:
	 
	 Apache Software Foundation Apache 2.2.14 and prior
	 
	 RISK:
	 Government:
	 
	 Large and medium government entities: High
	 Small government entities: High
	 
	 Businesses: 
	 
	 Large and medium business entities: High
	 Small business entities: ...]]></description>
            
            <guid>2010-018</guid>
            <pubdate>Mon, 08 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in IBM Lotus Domino</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-017.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in IBM Lotus Domino Web Access ActiveX control that could allow an attacker to take complete control of an affected system. ActiveX controls are small programs or animations that are embedded in Web pages which will typically enhance functionality and user experience. Domino Web Access, also known as Lotus iNotes, is a browser-based web client for Lotus Domino. IBM Lotus Domino is a server product designed for collaborative working environments such as email, scheduling, and instant messaging. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged ...]]></description>
            
            <guid>2010-017</guid>
            <pubdate>Tue, 02 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016 Updated</guid>
            <pubdate>Tue, 02 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-016.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 Please note: Proof of concept code has been published and is publically available. However, we have ...]]></description>
            
            <guid>2010-016</guid>
            <pubdate>Mon, 01 Mar 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Mozilla Products Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-015.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in the Mozilla Firefox and Mozilla SeaMonkey applications which could allow remote code execution as well as cross domain scripting. Mozilla Firefox is a web browser used to access the Internet. Mozilla SeaMonkey is a cross platform Internet suite of tools ranging from a web browser to an email client. The Mozilla applications (Firefox and SeaMonkey) utilize the same framework to display application specific information (e.g. Web pages, emails, chats).
	 These vulnerabilities may be exploited if a user visits a webpage or opens a malicious file specifically crafted to take advantage of these vulnerabilities. ...]]></description>
            
            <guid>2010-015</guid>
            <pubdate>Thu, 18 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities Discovered in Adobe Products</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-014.cfm</link>
            <description><![CDATA[Multiple vulnerabilities have been discovered in Adobe Flash Player, Adobe AIR, Adobe Reader, and Adobe Acrobat. Adobe Flash Player is a multimedia application for Microsoft Windows, Mozilla, and Apple technologies used to enhance the user experience when visiting web sites. Adobe AIR is a cross-platform runtime for developing internet applications on the desktop. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files.
	 An attacker can exploit the Adobe Acrobat and Reader vulnerabilities by users opening a specially crafted PDF document. An attacker can ...]]></description>
            
            <guid>2010-014</guid>
            <pubdate>Wed, 17 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Security Update of ActiveX Kill Bits</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-013.cfm</link>
            <description><![CDATA[Microsoft has released a security update which addresses vulnerabilities discovered in multiple ActiveX controls. ActiveX controls are small programs or animations that are downloaded or embedded in Web pages which will typically enhance functionality and user experience. Many web design and development tools have built ActiveX support into their products, allowing developers to both create and make use of ActiveX controls in their programs. There are more than 1,000 existing ActiveX controls available for use today.
	 SYSTEMS AFFECTED: 
	 
	 Windows 2000
	 Windows XP
	 Windows Server 2003
	 Windows Vista
	 Windows Server 2008
	 Windows 7
	 
	 RISK:
	 Government:
	 
	 Large ...]]></description>
            
            <guid>2010-013</guid>
            <pubdate>Wed, 10 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Microsoft PowerPoint</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-012.cfm</link>
            <description><![CDATA[Six new vulnerabilities have been discovered in Microsoft PowerPoint, a program used for creating presentations. These vulnerabilities can be exploited by opening a specially crafted PowerPoint presentation (.PPT or .PPS file) received as an email attachment, or by visiting a web site that is hosting a specially crafted PowerPoint file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: 
	 
	 Microsoft ...]]></description>
            
            <guid>2010-012</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Office</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-011.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft Office which could allow an attacker to take complete control of an affected system. The vulnerability can be exploited by opening a specially crafted Office file received as an email attachment, or by visiting a web site that is hosting a specially crafted Office file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-011</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Windows Shell Handler</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-010.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Windows Shell Handler which could allow an attacker to take complete control of an affected system. The Windows Shell Handler is used to run applications and manage the Windows operating system. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts ...]]></description>
            
            <guid>2010-010</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft DirectShow</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-009.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft DirectShow that could allow a remote attacker to take complete control of a vulnerable system. DirectShow is a component of Windows for streaming media and to perform various operations with media files on Microsoft Windows operating systems. This vulnerability can be exploited when a user opens a specially crafted media file. Successful exploitation could allow an attacker to gain the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-009</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in SMB Server</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-008.cfm</link>
            <description><![CDATA[Four vulnerabilities have been discovered in Microsoft Server Message Block (SMB) Server that could allow for remote code execution, denial of service, or privilege escalation. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Successful exploitation of these vulnerabilities could result in an attacker gaining complete control of the affected system, causing denial of service conditions, or privilege escalation. 
	 SYSTEMS AFFECTED: 
	 
	 Windows 2000
	 Windows XP
	 Windows Vista
	 Windows 7
	 Windows Server 2003
	 Windows Server 2008
 
	 RISK:
 Government:
 
 Large and medium government entities: High
	 Small ...]]></description>
            
            <guid>2010-008</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in the Microsoft SMB Client Could Allow Remote Code Execution (MS10-006)</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-007.cfm</link>
            <description><![CDATA[Two vulnerabilities have been discovered in the Microsoft Server Message Block (SMB) client that could allow a remote attacker to take complete control of a vulnerable system. SMB is used to provide shared access to files, printers, serial ports, and other miscellaneous communication between network devices. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining SYSTEM-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts.
	 SYSTEMS AFFECTED: 
	 
	 Windows ...]]></description>
            
            <guid>2010-007</guid>
            <pubdate>Tue, 09 Feb 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Multiple Vulnerabilities in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-006.cfm</link>
            <description><![CDATA[Eight vulnerabilities have been discovered in Microsofts web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of these vulnerabilities. Successful exploitation of these vulnerabilities could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
	 SYSTEMS AFFECTED: 
	 
	 Microsoft Internet Explorer 6
	Microsoft Internet ...]]></description>
            
            <guid>2010-006</guid>
            <pubdate>Thu, 21 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003c.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-003 Updated</guid>
            <pubdate>Thu, 21 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in CiscoWorks Internetwork Performance Monitor Could Allow Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-005.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in CiscoWorks Internetwork Performance Monitor (IPM) which could allow remote code execution. CiscoWorks IPM is a troubleshooting component used within the management solutions for CiscoWorks products which are used to configure, administer and monitor networks. Successful exploitation could result in an attacker gaining the same privileges as the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed attacks will likely cause denial-of-service conditions. 
	 SYSTEMS AFFECTED: 
	 
	 CiscoWorks IPM 2.6 and earlier for Windows operating systems
	 
	 RISK: 
	 Government: ...]]></description>
            
            <guid>2010-005</guid>
            <pubdate>Wed, 20 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Apple iTunes and Quick Time Could Allow For Remote Code Execution</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-004.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Apple iTunes and Quick Time player. Apple iTunes and QuickTime are used to play media files on Microsoft Windows and MAC OS X platforms. This vulnerability can be exploited if a user views the malicious file on a webpage or opens a malicious file, including an email attachment, using a vulnerable version of Apple QuickTime Player or iTunes. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; ...]]></description>
            
            <guid>2010-004</guid>
            <pubdate>Tue, 19 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003b.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full ...]]></description>
            
            <guid>2010-003 Updated</guid>
            <pubdate>Tue, 19 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Internet Explorer</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-003.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in Microsoft&apos;s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. At this point in time, no patches are available for this vulnerability. Exploitation may occur if a user visits a web page which is specifically crafted to take advantage of this vulnerability. Successful exploitation of the vulnerability could allow an attacker to gain the same user rights as the local user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with ...]]></description>
            
            <guid>2010-003</guid>
            <pubdate>Fri, 15 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerabilities in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-002.cfm</link>
            <description><![CDATA[Multiple vulnerabilities discovered in the Adobe Acrobat and Adobe Reader applications could allow attackers to execute arbitrary code on affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 SYSTEMS AFFECTED: ...]]></description>
            
            <guid>2010-002</guid>
            <pubdate>Wed, 13 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Adobe Reader and Acrobat</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2009-086c.cfm</link>
            <description><![CDATA[A vulnerability discovered in the Adobe Acrobat and Adobe Reader applications could allow attackers to execute arbitrary code on the affected systems. Adobe Reader allows users to view Portable Document Format (PDF) files. Adobe Acrobat offers users additional features such as the ability to create PDF files. Successful exploitation could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.
	 It ...]]></description>
            
            <guid>2009-086 Updated</guid>
            <pubdate>Wed, 13 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
          <item>
            <title>Vulnerability in Microsoft Windows</title>
            <link>http://www.dhses.ny.gov/ocs/advisories/2010/2010-001.cfm</link>
            <description><![CDATA[A vulnerability has been discovered in the Microsoft Windows Embedded OpenType Font Engine that could allow for remote code execution. Embedded OpenType Fonts are fonts that get embedded in documents such as Microsoft Word, Power Point, or Web pages. This vulnerability can be exploited if a user visits a specially crafted webpage or opens a specially crafted file, including e-mail attachments.
	 Successful exploitation may result in an attacker gaining the same user privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create ...]]></description>
            
            <guid>2010-001</guid>
            <pubdate>Tue, 12 Jan 2010 05:00:00 GMT</pubdate>
          </item>
        
  </channel>
  </rss>
