<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CVE : Nchovy &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</title>
  <link type="text/html" href="http://nchovy.kr/security/cve" rel="alternate"/>
  <author>
    <name>NCHOVY &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</name>
    <email>xeraph@nchovy.kr</email>
  </author>
  <entry>
    <title>CVE-2012-2513</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2513</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2513" rel="alternate"/>
    <content>The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</content>
    <published>2012-05-15T13:21:43+0900</published>
    <updated>2012-05-15T13:21:43+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-1804</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-1804</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-1804" rel="alternate"/>
    <content>Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.</content>
    <published>2012-05-15T05:55:01+0900</published>
    <updated>2012-05-15T05:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2277</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2277</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2277" rel="alternate"/>
    <content>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many "batch begin untethered" commands.</content>
    <published>2012-05-15T07:55:01+0900</published>
    <updated>2012-05-15T07:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2514</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2514</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2514" rel="alternate"/>
    <content>The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</content>
    <published>2012-05-15T13:21:43+0900</published>
    <updated>2012-05-15T13:21:43+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2612</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2612</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2612" rel="alternate"/>
    <content>The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</content>
    <published>2012-05-15T13:21:43+0900</published>
    <updated>2012-05-15T13:21:43+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2333</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2333</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2333" rel="alternate"/>
    <content>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</content>
    <published>2012-05-15T07:55:03+0900</published>
    <updated>2012-05-15T07:55:03+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2511</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2511</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2511" rel="alternate"/>
    <content>The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</content>
    <published>2012-05-15T13:21:43+0900</published>
    <updated>2012-05-15T13:21:43+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-2611</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-2611</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-2611" rel="alternate"/>
    <content>The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.</content>
    <published>2012-05-15T13:21:43+0900</published>
    <updated>2012-05-15T13:21:43+0900</updated>
  </entry>
</feed>

