<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Pythian Blog &#187; vulnerability</title>
	<atom:link href="http://www.pythian.com/news/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pythian.com/news</link>
	<description>News and views from Pythian DBAs</description>
	<lastBuildDate>Fri, 10 Feb 2012 09:54:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Oracle&#8217;s January 2010 Critical Patch Update is out</title>
		<link>http://www.pythian.com/news/7121/oracles-january-2010-critical-patch-update-is-out/</link>
		<comments>http://www.pythian.com/news/7121/oracles-january-2010-critical-patch-update-is-out/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:23:11 +0000</pubDate>
		<dc:creator>Marc Fielding</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Oracle E-Business Suite]]></category>
		<category><![CDATA[Technical Blog]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.pythian.com/news/?p=7121</guid>
		<description><![CDATA[Oracle has just released their January installment of their critical patch update (CPU). Vulnerability CVE-2010-0071 is particularly critical, with a CVSS score of 10, the highest possible. It&#8217;s a remotely-exploitable listener vulnerability that&#8217;s particularly severe on Windows platforms. Full details are on Oracle&#8217;s security site.]]></description>
		<wfw:commentRss>http://www.pythian.com/news/7121/oracles-january-2010-critical-patch-update-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Dynamically Call PL/SQL Procedure in Oracle</title>
		<link>http://www.pythian.com/news/2733/how-to-dynamically-call-plsql-procedure-in-oracle/</link>
		<comments>http://www.pythian.com/news/2733/how-to-dynamically-call-plsql-procedure-in-oracle/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 06:29:56 +0000</pubDate>
		<dc:creator>Alex Gorbachev</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[dynamic]]></category>
		<category><![CDATA[pl/sql]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[stored procedure]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.pythian.com/news/?p=2733</guid>
		<description><![CDATA[Just got an interesting note on Twitter that you can&#8217;t call a stored procedure dynamically in Oracle from a PL/SQL block like passing the procedure name in a variable. Well, yes we can! And the answer is EXECUTE IMMEDIATE &#8212; it can be used to run anonymous PL/SQL blog and not just a SQL statement. [...]]]></description>
		<wfw:commentRss>http://www.pythian.com/news/2733/how-to-dynamically-call-plsql-procedure-in-oracle/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Critical security vulnerability in SQL Server 2005 announced</title>
		<link>http://www.pythian.com/news/1215/critical-security-vulnerability-in-sql-server-2005-announced/</link>
		<comments>http://www.pythian.com/news/1215/critical-security-vulnerability-in-sql-server-2005-announced/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 20:45:10 +0000</pubDate>
		<dc:creator>Paul Vallee</dc:creator>
				<category><![CDATA[SQL Server]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.pythian.com/blogs/1215/critical-security-vulnerability-in-sql-server-2005-announced</guid>
		<description><![CDATA[All, I&#8217;m writing to help get the word out that Microsoft announced a major security vulnerability in GDI+, a component that is included and vulnerable to remote code execution exploits in every supported release of SQL Server 2005. You can find our more about the vulnerabilities and affected products (there&#8217;s a long list, not just [...]]]></description>
		<wfw:commentRss>http://www.pythian.com/news/1215/critical-security-vulnerability-in-sql-server-2005-announced/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

