<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0001" published="2003-01-17" seq="2003-0001" severity="Medium" type="CVE"><desc><descript source="cve">Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="AtStake.com" url="http://www.atstake.com/research/advisories/2003/a010603-1.txt">Ethernet frame padding information leakage</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/412115">Network device drivers reuse old frame buffer data to pad packets</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6535">bid 6535</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2"> More information regarding Etherleak</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html">20030110 More information regarding Etherleak</ref><ref source="MISC" url="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-025.html">RHSA-2003:025</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2665.html">OVAL2665</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-088.html">RHSA-2003:088</ref><ref source="OSVDB" url="http://www.osvdb.org/9962">9962</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665">oval:org.mitre.oval:def:2665</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7996">7996</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded">20030117 Re: More information regarding Etherleak</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5"/><vers num="1.5.1"/><vers num="1.5.2"/><vers num="1.5.3"/><vers num="1.6"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0002" published="2003-02-07" seq="2003-0002" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2">CSS on Microsoft Content Management Server</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp">Cumulative Patch for Microsoft Content Management Server (810487)</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/5922">bid 5922</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/10318.php">mcms-manuallogin-reasontxt-xss (10318)</ref><ref source="BID" url="http://www.securityfocus.com/bid/5922">5922</ref></refs><vuln_soft><prod name="Content Management Server" vendor="Microsoft"><vers num="2001 SP1"/><vers num="2001"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2003-0003" published="2003-02-07" seq="2003-0003" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp">Unchecked Buffer in Locator Service Could Lead to Code Execution (810833)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-03.html">Buffer Overflow in Windows Locator Service</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/610986">Microsoft Locator service contains buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6666">bid 6666</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11132">Microsoft Windows Locator service buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref><ref source="BID" url="http://www.securityfocus.com/bid/6666">6666</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103">oval:org.mitre.oval:def:103</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/><vers num="Server Japanese"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0004" published="2003-02-19" seq="2003-0004" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp">Unchecked Buffer in Windows Redirector Could Allow Privilege Elevation (810577)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6778">bid 6778</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/6778">6778</ref><ref source="XF" url="http://www.iss.net/security_center/static/11260.php">winxp-windows-redirector-bo(11260)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0007" published="2003-02-07" seq="2003-0007" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka &quot;Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp">Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure (812262)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6667">bid 6667</ref><ref source="BID" url="http://www.securityfocus.com/bid/6667">6667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11133">outlook-v1-certificate-plaintext(11133)</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0009" published="2003-03-07" seq="2003-0009" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft.com" url="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp">Flaw in Windows Me Help and Support Center Could Enable Code Execution (812709)</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2">MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6966">bid 6966</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11425.php">Windows Me HSC hcp:// buffer overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-047.shtml">N-047</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/489721">VU#489721</ref><ref source="OSVDB" url="http://www.osvdb.org/6074">6074</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Home"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0010" published="2003-03-24" seq="2003-0010" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104812108307645&amp;w=2">Heap Overflow in Windows Script Engine</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-008.asp">Flaw in Windows Script Engine Could Allow Code Execution (814078)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7146">bid 7146</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html">20030319 Windows Scripting Engine issue</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval200.html">OVAL200</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval794.html">OVAL794</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval795.html">OVAL795</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval134.html">OVAL134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:200">oval:org.mitre.oval:def:200</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:794">oval:org.mitre.oval:def:794</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:795">oval:org.mitre.oval:def:795</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:134">oval:org.mitre.oval:def:134</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26">20030319 Heap Overflow in Windows Script Engine</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0011" published="2003-03-24" seq="2003-0011" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-009.asp">Flaw In ISA Server DNS Intrusion Detection Filter Can Cause Denial Of Service (331065)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7145">bid 7145</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2000 SP1"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0012" published="2003-01-17" seq="2003-0012" severity="Low" type="CVE"><desc><descript source="cve">The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2">Security Advisory - remote database password disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6502">bid 6502</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/10971.php">Bugzilla data/mining directory changes to world writable</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-230">DSA-230</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref><ref source="BID" url="http://www.securityfocus.com/bid/6502">6502</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.17"/><vers num="2.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0013" published="2003-01-17" seq="2003-0013" severity="High" type="CVE"><desc><descript source="cve">The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2">Security Advisory - remote database password disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6501">bid 6501</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-230">DSA-230-1 bugzilla -- insecure permissions, spurious backup files</ref><ref source="BID" url="http://www.securityfocus.com/bid/6501">6501</ref><ref source="XF" url="http://www.iss.net/security_center/static/10970.php">bugzilla-htaccess-database-password(10970)</ref><ref source="OSVDB" url="http://www.osvdb.org/6351">6351</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.17"/><vers num="2.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0014" published="2003-01-11" seq="2003-0014" severity="Medium" type="CVE"><desc><descript source="cve">gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><sols><sol source="nvd">For the stable distribution this problem has been fixed in version 1.2-14.2. For the unstable distribution this problem has been fixed in version 1.2-17.</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-633">DSA-633</ref><ref adv="1" patch="1" source="BID" url="http://securityfocus.org/bid/12229">12229</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18823">bmv-symlink(18823)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012847">1012847</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13793">13793</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13796">13796</ref></refs><vuln_soft><prod name="BMV" vendor="BMV"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-06" name="CVE-2003-0015" published="2003-02-07" seq="2003-0015" severity="High" type="CVE"><desc><descript source="cve">Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11108">CVS malformed directory name </ref><ref adv="1" patch="1" source="Security E-matters" url="http://security.e-matters.de/advisories/012003.html">CVS remote vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2003-013.html">Updated CVS packages available</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6650">bid 6650</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/650937">Concurrent Versions System (CVS) server improperly deallocates memory</ref><ref source="MISC" url="http://lists.netsys.com/pipermail/full-disclosure/2003-January/003606.html">http://lists.netsys.com/pipermail/full-disclosure/2003-January/003606.html</ref><ref source="" url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14"></ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html">20030120 Advisory 01/2003: CVS remote vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2">20030124 Test program for CVS double-free.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2">20030202 Exploit for CVS double free() for Linux pserver</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-02.html">CA-2003-02</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-233">DSA-233</ref><ref source="FREEBSD" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2">FreeBSD-SA-03:01</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009">MDKSA-2003:009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-032.shtml">N-032</ref><ref source="BID" url="http://www.securityfocus.com/bid/6650">6650</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="5.0"/></prod><prod name="CVS" vendor="CVS"><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0016" published="2003-02-07" seq="2003-0016" severity="High" type="CVE"><desc><descript source="cve">Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apacheweek.com/issues/03-01-24#security">http://www.apacheweek.com/issues/03-01-24#security</ref><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">Apache 2.0.44 Released</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6659">bid 6659</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6662">bid 6662</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/979793">VU#979793</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/825177">VU#825177</ref><ref source="BID" url="http://www.securityfocus.com/bid/6659">6659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11124">apache-device-name-dos(11124)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11125">apache-device-code-execution(11125)</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2003-0017" published="2003-02-07" seq="2003-0017" severity="Medium" type="CVE"><desc><descript source="cve">Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as &quot;&gt;&quot;, which causes a different filename to be processed and served.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">Apache 2.0.44 Released</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6660">bid 6660</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0018" published="2003-02-19" seq="2003-0018" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-025.html">Updated 2.4 kernel fixes various vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6763">bid 6763</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11249.php">Linux kernel O_DIRECT information leak</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-423">DSA-423-1 linux-kernel-2.4.17-ia64 -- several vulnerabilities</ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-358">DSA-358</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014">MDKSA-2003:014</ref><ref source="BID" url="http://www.securityfocus.com/bid/6763">6763</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0019" published="2003-02-19" seq="2003-0019" severity="High" type="CVE"><desc><descript source="cve">uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-056.html">Updated kernel-utils packages fix setuid vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6801">bid 6801</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11276.php">Red Hat Linux uml_net utility could allow an attacker to gain privileges</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/134025">VU#134025</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-044.shtml">N-044</ref><ref source="BID" url="http://www.securityfocus.com/bid/6801">6801</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0020" published="2003-03-18" seq="2003-0020" severity="Medium" type="CVE"><desc><descript source="cve">Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">Terminal Emulator Security Issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9930">Apache Error Log Escape Sequence Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11412.php">Apache HTTP Server error log terminal escape sequence injection</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</ref><ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050">MDKSA-2003:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-083.html">RHSA-2003:083</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150">oval:org.mitre.oval:def:150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114">oval:org.mitre.oval:def:4114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109">oval:org.mitre.oval:def:100109</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0021" published="2003-03-03" seq="2003-0021" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;screen dump&quot; feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user&apos;s terminal, e.g. when the user views a file containing the malicious sequence.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6936">bid 6936</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11413.php">Multiple vendor terminal emulator screen dump file overwrite</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref><ref source="BID" url="http://www.securityfocus.com/bid/6936">6936</ref></refs><vuln_soft><prod name="Eterm" vendor="Michael Jennings"><vers num="0.8.10"/><vers num="0.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0022" published="2003-03-03" seq="2003-0022" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;screen dump&quot; feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user&apos;s terminal, e.g. when the user views a file containing the malicious sequence.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6938">bid 6938</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11413.php">Multiple vendor terminal emulator screen dump file overwrite</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref><ref source="BID" url="http://www.securityfocus.com/bid/6938">6938</ref></refs><vuln_soft><prod name="rxvt" vendor="rxvt"><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.7.5"/><vers num="2.7.6"/><vers num="2.7.7"/><vers num="2.7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0023" published="2003-03-03" seq="2003-0023" severity="Medium" type="CVE"><desc><descript source="cve">The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6947">bid 6947</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11416.php">Multiple vendor terminal emulator menuBar modification command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref><ref source="BID" url="http://www.securityfocus.com/bid/6947">6947</ref></refs><vuln_soft><prod name="rxvt" vendor="rxvt"><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.7.5"/><vers num="2.7.6"/><vers num="2.7.7"/><vers num="2.7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0024" published="2003-03-03" seq="2003-0024" severity="High" type="CVE"><desc><descript source="cve">The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref source="Security Focus" url="http://online.securityfocus.com/bid/6949">bid 6949</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11416.php">Multiple vendor terminal emulator menuBar modification command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/6949">6949</ref></refs><vuln_soft><prod name="aterm" vendor="aterm"><vers num="0.42"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0025" published="2003-01-17" seq="2003-0025" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-229">imp -- SQL injection</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2">IMP 2.x SQL injection vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6559">bid 6559</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306268">20030108 Re: IMP 2.x SQL injection vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/6559">6559</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005904">1005904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8087">8087</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8177">8177</ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0026" published="2003-01-17" seq="2003-0026" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-01.html">CERT Advisory CA-2003-01 Buffer Overflows in ISC DHCPD Minires Library</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/284857">ISC DHCPD minires library contains multiple buffer overflows</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-011.html">Updated dhcp packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-231">DSA-231-1 dhcp3 -- stack overflows</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:007">MDKSA-2003:007</ref><ref source="SUSE" url="http://www.suse.com/de/security/2003_006_dhcp.html">SuSE-SA:2003:0006</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-031.shtml">N-031</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11073">dhcpd-minires-multiple-bo(11073)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562">CLA-2003:562</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007">MDKSA-2003:007</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html">OpenPKG-SA-2003.002</ref><ref source="BID" url="http://www.securityfocus.com/bid/6627">6627</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005924">1005924</ref></refs><vuln_soft><prod name="DHCPD" vendor="ISC"><vers num="3.0"/><vers num="3.0.1 rc8"/><vers num="3.0.1 rc7"/><vers num="3.0.1 rc6"/><vers num="3.0.1 rc5"/><vers num="3.0.1 rc4"/><vers num="3.0.1 rc3"/><vers num="3.0.1 rc2"/><vers num="3.0.1 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0027" published="2003-02-07" seq="2003-0027" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Entercept.com" url="http://www.entercept.com/news/uspr/01-22-03.asp">KCMS Library Service Daemon Arbitrary File Retrieval Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/850785">Sun KCMS library service daemon does not adequately validate location of KCMS profiles</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6665">bid 6665</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104">50104</ref><ref source="BID" url="http://www.securityfocus.com/bid/6665">6665</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11129">solaris-kcms-directory-traversal(11129)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120">oval:org.mitre.oval:def:120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195">oval:org.mitre.oval:def:195</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592">oval:org.mitre.oval:def:2592</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-30" name="CVE-2003-0028" published="2003-03-25" seq="2003-0028" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2"> [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref><ref adv="1" source="Eeye.com" url="http://www.eeye.com/html/Research/Advisories/AD20030318.html">XDR Integer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7123">bid 7123</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-10.html">CERT Advisory CA-2003-10 Integer overflow in Sun RPC XDR library routines</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104810574423662&amp;w=2">20030319 EEYE: XDR Integer Overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html">20030319 EEYE: XDR Integer Overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/516825">VU#516825</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-282">DSA-282</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-089.html">RHSA-2003:089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811415301340&amp;w=2">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html">ESA-20030321-010</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-272">DSA-272</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104860855114117&amp;w=2">20030325 GLSA:  glibc (200303-22)</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:037">MDKSA-2003:037</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc">NetBSD-SA2003-008</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_027_glibc.html">SuSE-SA:2003:027</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878237121402&amp;w=2">2003-0014</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval230.html">OVAL230</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:230">oval:org.mitre.oval:def:230</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316931/30/25250/threaded">20030331 GLSA: dietlibc (200303-29)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037">MDKSA-2003:037</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/315638/30/25430/threaded">20030319 RE: EEYE: XDR Integer Overflow</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20"/></prod><prod name="UNICOS" vendor="Cray"><vers num="6.0E"/><vers num="6.0"/><vers num="6.1"/><vers num="7.0"/><vers num="8.0"/><vers num="8.3"/><vers num="9.0"/><vers num="9.0.2.5"/><vers num="9.2.4"/><vers num="9.2"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20 Series 800"/><vers num="10.20 Series 700"/><vers num="10.20"/><vers num="10.24"/><vers num="11.04"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/></prod><prod name="Kerberos 5" vendor="MIT"><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod><prod name="glibc" vendor="Gnu"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.2"/></prod><prod name="OpenAFS" vendor="OpenAFS"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4a"/><vers num="1.0.4"/><vers num="1.1"/><vers num="1.1.1a"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2b"/><vers num="1.2.2a"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4"/><vers num="4.5 Stable"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/><vers num="2.8"/><vers num="2.9"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0030" published="2003-03-18" seq="2003-0030" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/247545">Protegrity Secure.Data for Microsoft SQL Server 2000 contains buffer overflows in extended stored procedures</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104758650516677&amp;w=2">Protegrity buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7084">bid 7084</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7085">bid 7085</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7083">bid 7083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8294">8294</ref></refs><vuln_soft><prod name="Secure.Data" vendor="Protegrity"><vers num="2.2.3.7"/><vers num="2.2.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0031" published="2003-01-17" seq="2003-0031" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2">Multiple libmcrypt vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-228">libmcrypt -- buffer overflows and memory leak</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6510">bid 6510</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref><ref source="BID" url="http://www.securityfocus.com/bid/6510">6510</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006181">1006181</ref></refs><vuln_soft><prod name="libmcrypt" vendor="Mcrypt"><vers num="2.5 .0"/><vers num="2.5.1 r4"/><vers num="2.5.2"/><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0032" published="2003-01-17" seq="2003-0032" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2">Multiple libmcrypt vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-228">libmcrypt -- buffer overflows and memory leak</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6512">bid 6512</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/10988.php">libmcrypt libtool memory leak</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref><ref source="BID" url="http://www.securityfocus.com/bid/6512">6512</ref></refs><vuln_soft><prod name="libmcrypt" vendor="Mcrypt"><vers num="2.5 .0"/><vers num="2.5.1 r4"/><vers num="2.5.2"/><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0033" published="2003-03-07" seq="2003-0033" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951">Snort RPC Preprocessing Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/10956.php">snort-rpc-fragment-bo(10956)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6963">bid 6963</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/916785">Buffer overflow in Snort RPC preprocessor</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2">20030303 Snort RPC Vulnerability (fwd)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html">ESA-20030307-007</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2">GLSA-200304-06</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2">GLSA-200303-6.1</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029">MDKSA-2003:029</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref><ref source="OSVDB" url="http://www.osvdb.org/4418">4418</ref></refs><vuln_soft><prod name="Snort" vendor="Snort"><vers num="1.8.0"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5"/><vers num="1.8.6"/><vers num="1.8.7"/><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0034" published="2003-02-07" seq="2003-0034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.21.03.txt">Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:010">printer-drivers</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6656">bid 6656</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="BID" url="http://www.securityfocus.com/bid/6656">6656</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref></refs><vuln_soft><prod name="mtink" vendor="Jean-Jacques Sarton"><vers num="0.9.32"/><vers num="0.9.33"/><vers num="0.9.52"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0035" published="2003-02-07" seq="2003-0035" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.21.03.txt">Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6658">bid 6658</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:010">printer-drivers</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref source="BID" url="http://www.securityfocus.com/bid/6658">6658</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref></refs><vuln_soft><prod name="escputil" vendor="Robert Krawitz"><vers num="1.15.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0036" published="2003-02-07" seq="2003-0036" severity="Medium" type="CVE"><desc><descript source="cve">ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form &quot;mlg85p%d&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.21.03.txt">Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:010">printer-drivers</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref></refs><vuln_soft><prod name="ml85p" vendor="Rildo Pragana"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0037" published="2003-02-07" seq="2003-0037" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-244">noffle -- buffer overflows</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6695">bid 6695</ref><ref source="BID" url="http://www.securityfocus.com/bid/6695">6695</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11181">noffle-multiple-bo(11181)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7955">7955</ref></refs><vuln_soft><prod name="Noffle" vendor="Noffle"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0038" published="2003-02-07" seq="2003-0038" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111">Mailman: cross-site scripting bug</ref><ref patch="1" source="Source Forge" url="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-436">DSA-436-1 mailman -- several vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/6677">6677</ref><ref source="OSVDB" url="http://www.osvdb.org/9205">9205</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1005987">1005987</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11152">mailman-email-variable-xss(11152)</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0039" published="2003-02-07" seq="2003-0039" severity="Medium" type="CVE"><desc><descript source="cve">ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Gorup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2">DoS against DHCP infrastructure with isc dhcrelay</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-245">ignored counter boundary</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11187">ISC DHCP dhcrelay (dhcp-relay) denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616">CLSA-2003:616</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-034.html">RHSA-2003:034</ref><ref source="TURBO" url="http://cc.turbolinux.com/security/TLSA-2003-26.txt">TLSA-2003-26</ref><ref source="BUGTRAQ" url="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/149953">VU#149953</ref><ref source="BID" url="http://www.securityfocus.com/bid/6628">6628</ref></refs><vuln_soft><prod name="DHCPD" vendor="ISC"><vers num="3.0.1 rc9"/><vers num="3.0.1 rc8"/><vers num="3.0.1 rc7"/><vers num="3.0.1 rc6"/><vers num="3.0.1 rc5"/><vers num="3.0.1 rc4"/><vers num="3.0.1 rc3"/><vers num="3.0.1 rc2"/><vers num="3.0.1 rc10"/><vers num="3.0.1 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0040" published="2003-02-19" seq="2003-0040" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-247">courier-ssl -- missing input sanitizing</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6738">bid 6738</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11213">courierimap-authmysqllib-sql-injection(11213)</ref></refs><vuln_soft><prod name="Courier-IMAP" vendor="Inter7"><vers num="1.6"/></prod><prod name="Courier MTA" vendor="Double Precision Incorporated"><vers num="0.37.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0041" published="2003-02-19" seq="2003-0041" severity="High" type="CVE"><desc><descript source="cve">Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-020.html">Updated kerberos packages fix vulnerability in ftp client</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html">20030128 MIT Kerberos FTP client remote shell commands execution</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:021">MDKSA-2003:021</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021">MDKSA-2003:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7979">7979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8114">8114</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.2"/><vers edition="i386" num="7.0"/><vers edition="i386" num="7.1"/><vers edition="IA64" num="7.2"/><vers edition="i386" num="7.2"/><vers edition="i386" num="7.3"/><vers edition="i386" num="8.0"/></prod><prod name="Kerberos FTP Client" vendor="MIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0042" published="2003-02-07" seq="2003-0042" severity="Medium" type="CVE"><desc><descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/"></ref><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">Apache Tomcat 3.3.1a</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6721">bid 6721</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2">Apache Jakarta Tomcat 3 URL parsing vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-246">DSA-246-1 tomcat -- information exposure, cross site scripting</ref><ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref><ref source="BID" url="http://www.securityfocus.com/bid/6721">6721</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11194">tomcat-null-directory-listing(11194)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7972">7972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7977">7977</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.3"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0043" published="2003-02-07" seq="2003-0043" severity="Medium" type="CVE"><desc><descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/"></ref><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">Apache Tomcat 3.3.1a</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6722">bid 6722</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11195">Apache Tomcat web.xml could be used to read files</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-246">DSA-246</ref><ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref><ref source="BID" url="http://www.securityfocus.com/bid/6722">6722</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.3"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0044" published="2003-02-07" seq="2003-0044" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/"></ref><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">Apache Tomcat 3.3.1a</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6720">bid 6720</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-246">DSA-246-1 tomcat -- information exposure, cross site scripting</ref><ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref><ref source="BID" url="http://www.securityfocus.com/bid/6720">6720</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11196">tomcat-web-app-xss(11196)</ref><ref source="OSVDB" url="http://www.osvdb.org/9203">9203</ref><ref source="OSVDB" url="http://www.osvdb.org/9204">9204</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7972">7972</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0045" published="2003-02-07" seq="2003-0045" severity="Medium" type="CVE"><desc><descript source="cve">Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt">Apache Tomcat 3.3.1a</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/12102">Jakarta Tomcat MS-DOS device name request denial of service</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.3"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0046" published="2003-02-19" seq="2003-0046" severity="Medium" type="CVE"><desc><descript source="cve">AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.28.03.txt">SSH2 Clients Insecurely Store Passwords</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6725">bid 6725</ref><ref adv="1" source="Celestial Software" url="http://www.celestialsoftware.net/telnet/beta_software.html">Celestial Software AbsoluteTelnet version 2.12 RC13</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref><ref source="BID" url="http://www.securityfocus.com/bid/6725">6725</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006013">1006013</ref><ref source="OSVDB" url="http://www.osvdb.org/7686">7686</ref></refs><vuln_soft><prod name="AbsoluteTelnet" vendor="Celestial Software"><vers num="2.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0047" published="2003-02-19" seq="2003-0047" severity="Medium" type="CVE"><desc><descript source="cve">SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.28.03.txt">SSH2 Clients Insecurely Store Passwords</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6726">bid 6726</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref><ref source="BID" url="http://www.securityfocus.com/bid/6726">6726</ref><ref source="BID" url="http://www.securityfocus.com/bid/6727">6727</ref><ref source="BID" url="http://www.securityfocus.com/bid/6728">6728</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006010">1006010</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006011">1006011</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006012">1006012</ref></refs><vuln_soft><prod name="Entunnel" vendor="Van Dyke Technologies"><vers num="1.0.2" prev="1"/></prod><prod name="SecureFX" vendor="Van Dyke Technologies"><vers num="2.1.2"/><vers num="2.0.4"/></prod><prod name="SecureCRT" vendor="Van Dyke Technologies"><vers num="3.4.7"/><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0048" published="2003-02-19" seq="2003-0048" severity="Medium" type="CVE"><desc><descript source="cve">PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/01.28.03.txt">SSH2 Clients Insecurely Store Passwords</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6724">bid 6724</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref><ref source="BID" url="http://www.securityfocus.com/bid/6724">6724</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006014">1006014</ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.48"/><vers num="0.49"/><vers num="0.53b"/><vers num="0.53"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0049" published="2003-03-03" seq="2003-0049" severity="High" type="CVE"><desc><descript source="cve">Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6860">bid 6860</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11333.php">Mac OS X Apple File Protocol (AFP) unauthorized access</ref><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/6860">6860</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006107">1006107</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2 (Jaguar)"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0050" published="2003-03-07" seq="2003-0050" severity="High" type="CVE"><desc><descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11401.php">QuickTime and Darwin Streaming Server parse_xml.cgi command execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6954">bid 6954</ref><ref source="BID" url="http://www.securityfocus.com/bid/6954">6954</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0051" published="2003-03-07" seq="2003-0051" severity="Medium" type="CVE"><desc><descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server&apos;s installation path via a NULL file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11402.php">QuickTime and Darwin Streaming Server parse_xml.cgi path disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6956">bid 6956</ref><ref source="BID" url="http://www.securityfocus.com/bid/6956">6956</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0052" published="2003-03-07" seq="2003-0052" severity="Medium" type="CVE"><desc><descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11403.php">QuickTime and Darwin Streaming Server parse_xml.cgi directory disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6955">bid 6955</ref><ref source="BID" url="http://www.securityfocus.com/bid/6955">6955</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0053" published="2003-03-07" seq="2003-0053" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11404.php">QuickTime and Darwin Streaming Server parse_xml.cgi cross-site scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6958">bid 6958</ref><ref source="BID" url="http://www.securityfocus.com/bid/6958">6958</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0054" published="2003-03-07" seq="2003-0054" severity="High" type="CVE"><desc><descript source="cve">Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11405.php">QuickTime and Darwin Streaming Server RTSP DESCRIBE cross-site scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6960">bid 6960</ref><ref source="BID" url="http://www.securityfocus.com/bid/6960">6960</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0055" published="2003-03-07" seq="2003-0055" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2">QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11406.php">QuickTime and Darwin Streaming Server MP3 broadcasting buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6957">bid 6957</ref><ref source="BID" url="http://www.securityfocus.com/bid/6957">6957</ref></refs><vuln_soft><prod name="Quicktime MP3 Broadcaster" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0056" published="2003-02-19" seq="2003-0056" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-252">DSA-252-1 slocate -- buffer overflow</ref><ref adv="1" source="USQ.org.uk" url="http://www.usg.org.uk/advisories/2003.001.txt">USG Security Advisory (slocate)</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2">GLSA: slocate</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6676">bid 6676</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:015">MDKSA-2003:015</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</ref><ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt">CSSA-2003-009.0</ref><ref source="CONECTIVA" url="http://www.net-security.org/advisory.php?id=2010">CLA-2003:643</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015">MDKSA-2003:015</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-041.html">RHSA-2004:041</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7982">7982</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8007">8007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8236">8236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10720">10720</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7947">7947</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8118/">8118</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8749">8749</ref></refs><vuln_soft><prod name="slocate" vendor="slocate"><vers num="2.5"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0057" published="2003-02-19" seq="2003-0057" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2">Hypermail buffer overflows</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6689">bid 6689</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6690">bid 6690</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html">20030126 Hypermail buffer overflows</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-248">DSA-248</ref><ref source="BID" url="http://www.securityfocus.com/bid/6689">6689</ref><ref source="BID" url="http://www.securityfocus.com/bid/6690">6690</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11157">hypermail-mail-attachment-bo(11157)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11158">hypermail-long-hostname-bo(11158)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8030">8030</ref></refs><vuln_soft><prod name="HyperMail" vendor="HyperMail"><vers num="2.0b25"/><vers num="2.1 .0"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0058" published="2003-02-19" seq="2003-0058" severity="Medium" type="CVE"><desc><descript source="cve">MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">MIT krb5 Security Advisory 2003-001</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/661243">MIT Kerberos V5 KDC vulnerable to denial-of-service via null pointer dereference</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6683">bid 6683</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142">50142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110">oval:org.mitre.oval:def:1110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/10099">kerberos-kdc-null-pointer-dos(10099)</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/></prod><prod name="Sun Enterprise Authentication Mechanism" vendor="Sun"><vers num="1.0"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0059" published="2003-02-19" seq="2003-0059" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">MIT krb5 Security Advisory 2003-001</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/684563">MIT Kerberos V5 allows inter-realm user impersonation by malicious realm controllers with shared keys</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6714">bid 6714</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11188">kerberos-kdc-user-spoofing(11188)</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.2.1"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0060" published="2003-02-19" seq="2003-0060" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt">MIT krb5 Security Advisory 2003-001</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/787523">MIT Kerberos V5 KDC logging routines use unsafe format strings</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6712">bid 6712</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11189">kerberos-kdc-format-string(11189)</ref><ref source="OSVDB" url="http://www.osvdb.org/4879">4879</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0061" published="2002-01-11" seq="2003-0061" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2003-0062" published="2003-02-19" seq="2003-0062" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11282.php">NOD32 for UNIX long pathname buffer overflow</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/02.10.03.txt">Buffer Overflow In NOD32 Antivirus Software for Unix</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6803">bid 6803</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</ref><ref source="BID" url="http://www.securityfocus.com/bid/6803">6803</ref></refs><vuln_soft><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.12"/><vers num="1.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0063" published="2003-03-03" seq="2003-0063" severity="High" type="CVE"><desc><descript source="cve">The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6940">bid 6940</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref><ref source="BID" url="http://www.securityfocus.com/bid/6940">6940</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.3"/><vers num="4.1.0"/><vers num="4.2.0"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0064" published="2003-03-03" seq="2003-0064" severity="High" type="CVE"><desc><descript source="cve">The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6942">bid 6942</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="HP" url="http://www.securityfocus.com/advisories/6236">HPSBUX0401-309</ref><ref source="BID" url="http://www.securityfocus.com/bid/6942">6942</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.24"/><vers num="10.26"/><vers num="10.30"/><vers num="10.34"/><vers num="11.04"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/></prod><prod name="IRIX" vendor="SGI"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0065" published="2003-03-03" seq="2003-0065" severity="High" type="CVE"><desc><descript source="cve">The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6945">bid 6945</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/6945">6945</ref></refs><vuln_soft><prod name="uxterm" vendor="National University of Singapore"><vers num="2.3"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0066" published="2003-03-03" seq="2003-0066" severity="High" type="CVE"><desc><descript source="cve">The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6953">bid 6953</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="GENTOO" url="http://www.securityfocus.com/advisories/5137">200303-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003">MDKSA-2003:003</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref><ref source="BID" url="http://www.securityfocus.com/bid/6953">6953</ref></refs><vuln_soft><prod name="rxvt" vendor="rxvt"><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.7.5"/><vers num="2.7.6"/><vers num="2.7.7"/><vers num="2.7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-18" name="CVE-2003-0067" published="2003-03-18" seq="2003-0067" severity="High" type="CVE"><desc><descript source="cve">The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref></refs><vuln_soft><prod name="aterm" vendor="aterm"><vers num="0.42"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0068" published="2003-03-03" seq="2003-0068" severity="High" type="CVE"><desc><descript source="cve">The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6941">bid 6941</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-496">DSA-496</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref><ref source="BID" url="http://www.securityfocus.com/bid/10237">10237</ref></refs><vuln_soft><prod name="Eterm" vendor="Michael Jennings"><vers num="0.8.10"/><vers num="0.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-18" name="CVE-2003-0069" published="2003-03-18" seq="2003-0069" severity="High" type="CVE"><desc><descript source="cve">The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="OSVDB" url="http://www.osvdb.org/8347">8347</ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.53"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0070" published="2003-03-03" seq="2003-0070" severity="High" type="CVE"><desc><descript source="cve">VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6948">bid 6948</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-053.html">RHSA-2003:053</ref><ref source="GENTOO" url="http://seclists.org/lists/bugtraq/2003/Mar/0010.html">GLSA-200303-2</ref></refs><vuln_soft><prod name="gnome-terminal" vendor="GNOME"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.2"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0071" published="2003-03-03" seq="2003-0071" severity="Low" type="CVE"><desc><descript source="cve">The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6950">bid 6950</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11415.php">Multiple vendor terminal emulator DEC UDK denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref><ref source="BID" url="http://www.securityfocus.com/bid/6950">6950</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.3"/><vers num="4.1.0"/><vers num="4.2.0"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0072" published="2003-04-02" seq="2003-0072" severity="Medium" type="CVE"><desc><descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka &quot;array overrun&quot;).</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt">Buffer overrun and underrun in principal name handling</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-266">krb5 -- several</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref><ref source="BID" url="http://www.securityfocus.com/bid/7184">7184</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2.Beta1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3 alpha1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2003-0073" published="2003-02-19" seq="2003-0073" severity="Medium" type="CVE"><desc><descript source="cve">Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MySQL.com" url="http://www.mysql.com/doc/en/News-3.23.55.html">Changes in release 3.23.55</ref><ref adv="1" patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:013">MYSQL</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2">OpenPKG Security Advisory (mysql)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6718">bid 6718</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-303">DSA-303-1 mysql -- privilege escalation</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html">ESA-20030220-004</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013">MDKSA-2003:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-094.html">RHSA-2003:094</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-166.html">RHSA-2003:166</ref><ref source="BID" url="http://www.securityfocus.com/bid/6718">6718</ref><ref source="XF" url="http://www.iss.net/security_center/static/11199.php">mysql-mysqlchangeuser-doublefree-dos(11199)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436">oval:org.mitre.oval:def:436</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.31"/><vers num="3.23.36"/><vers num="3.23.41"/><vers num="3.23.47"/><vers num="3.23.52"/><vers num="3.23.53"/><vers num="3.23.54a"/><vers num="3.23.54"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0074" published="2003-02-19" seq="2003-0074" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2">Local root vuln in SuSE 8.0 plptools package</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2">Re: Local root vuln in SuSE 8.0 plptools package</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6715">bid 6715</ref><ref source="XF" url="http://www.iss.net/security_center/static/11193.php">plptools-plpnsfd-format-string(11193)</ref></refs><vuln_soft><prod name="plptools" vendor="plptools"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0075" published="2003-02-19" seq="2003-0075" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a &quot;fmt&quot; wave chunk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11227.php">BladeEnc myFseek() code execution</ref><ref adv="1" patch="1" source="Pivx.com" url="http://www.pivx.com/luigi/adv/blade942-adv.txt">Bladeenc 0.94.2 code execution</ref><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2">GLSA: bladeenc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6745">bid 6745</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2">20030202 Bladeenc 0.94.2 code execution</ref></refs><vuln_soft><prod name="BladeEnc" vendor="BladeEnc"><vers num="0.92.7"/><vers num="0.93.10"/><vers num="0.94.0"/><vers num="0.94.1"/><vers num="0.94.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0076" published="2003-02-19" seq="2003-0076" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Ketelhot.de" url="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html">Security bug in versions &lt; 0.2.2</ref><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2">GLSA: qt-dcgui</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11246.php">qt-dcgui directory parser could allow attacker to download files</ref></refs><vuln_soft><prod name="dcgui" vendor="dcgui"><vers num="0.2"/><vers num="0.2.1"/></prod><prod name="qt-dcgui" vendor="qt-dcgui"><vers num="0.2"/><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-18" name="CVE-2003-0077" published="2003-03-18" seq="2003-0077" severity="High" type="CVE"><desc><descript source="cve">The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user&apos;s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11414.php">Multiple vendor terminal emulator window title command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref><ref source="OSVDB" url="http://www.osvdb.org/4917">4917</ref></refs><vuln_soft><prod name="hanterm-xf" vendor="Hanterm"><vers num="2.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0078" published="2003-03-03" seq="2003-0078" severity="Medium" type="CVE"><desc><descript source="cve">ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the &quot;Vaudenay timing attack.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="OpenSSL" url="http://www.openssl.org/news/secadv_20030219.txt">OpenSSL Security Advisory</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2003/dsa-253">DSA-253-1 openssl -- information leak</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2"> OpenPKG Security Advisory (openssl)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6884">bid 6884</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11369.php">Multiple SSL/TLS implementation CBC ciphersuites information leak</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2">20030219 OpenSSL 0.9.7a and 0.9.6i released</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570">CLSA-2003:570</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html">ESA-20030220-005</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2">GLSA-200302-10</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-062.html">RHSA-2003:062</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-063.html">RHSA-2003:063</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-205.html">RHSA-2003:205</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2003/0005">2003-0005</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020">MDKSA-2003:020</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc">NetBSD-SA2003-001</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-051.shtml">N-051</ref><ref source="BID" url="http://www.securityfocus.com/bid/6884">6884</ref><ref source="OSVDB" url="http://www.osvdb.org/3945">3945</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.8 pre"/><vers num="5.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.1"/><vers num="3.2"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.1c"/><vers num="0.9.2b"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5a"/><vers num="0.9.5"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.6b"/><vers num="0.9.6a"/><vers num="0.9.6"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0079" published="2003-03-03" seq="2003-0079" severity="Low" type="CVE"><desc><descript source="cve">The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">Terminal Emulator Security Issues</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6944">bid 6944</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11415.php">Multiple vendor terminal emulator DEC UDK denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref><ref source="BID" url="http://www.securityfocus.com/bid/6944">6944</ref><ref source="OSVDB" url="http://www.osvdb.org/4918">4918</ref></refs><vuln_soft><prod name="hanterm-xf" vendor="Hanterm"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0080" published="2003-03-31" seq="2003-0080" severity="High" type="CVE"><desc><descript source="cve">The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-072.html">Updated Gnome-lokkit packages fix vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7128">bid 7128</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11552">GNOME Lokkit FORWARD chain bypasses firewall</ref><ref source="OSVDB" url="http://www.osvdb.org/4400">4400</ref></refs><vuln_soft><prod name="Gnome-lokkit" vendor="GNOME"><vers num="0.50_21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0081" published="2003-03-18" seq="2003-0081" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Guninski.com" url="http://www.guninski.com/etherre.html">Ethereal format string bug, yet still ethereal much better than windows</ref><ref adv="1" patch="1" source="Ethereal.com" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html">SOCKS string format vulnerability in Ethereal 0.9.9</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7049">bid 7049</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-258">ethereal -- format string vulnerability</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html">20030308 Ethereal format string bug, yet still ethereal much better than windows</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627">CLSA-2003:627</ref><ref source="GENTOO" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html">GLSA-200303-10</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-076.html">RHSA-2003:076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11497">ethereal-socks-format-string(11497)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54">oval:org.mitre.oval:def:54</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.18"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0082" published="2003-04-02" seq="2003-0082" severity="Medium" type="CVE"><desc><descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka &quot;buffer underrun&quot;).</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt">Buffer overrun and underrun in principal name handling</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-266">krb5 -- several</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval244.html">OVAL244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2536.html">OVAL2536</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4430.html">OVAL4430</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244">oval:org.mitre.oval:def:244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536">oval:org.mitre.oval:def:2536</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430">oval:org.mitre.oval:def:4430</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref><ref source="BID" url="http://www.securityfocus.com/bid/7185">7185</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2.Beta1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3 alpha1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0083" published="2003-04-02" seq="2003-0083" severity="Medium" type="CVE"><desc><descript source="cve">Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache" url="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25">CVS log for apache-1.3/src/modules/standard/mod_log_config.c</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2">LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">Updated httpd packages fix security vulnerabilities.</ref><ref source="CONFIRM" url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval151.html">OVAL151</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024081011678&amp;w=2">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:151">oval:org.mitre.oval:def:151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8146">8146</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0084" published="2003-05-12" seq="2003-0084" severity="High" type="CVE"><desc><descript source="cve">mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2003-114.html">Updated mod_auth_any packages are available</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7448">bid 7448</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-113.html">RHSA-2003:113</ref><ref source="" url="http://www.itlab.musc.edu/webNIS/mod_auth_any.html">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-090.shtml">N-090</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11893">modauthany-command-execution(11893)</ref></refs><vuln_soft><prod name="mod_auth_any" vendor="mod_auth_any"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0085" published="2003-03-31" seq="2003-0085" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792723017768&amp;w=2">Security Bugfix for Samba - Samba 2.2.8 Released</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-262">samba -- remote exploit</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2">GLSA: samba (200303-11)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7106">bid 7106</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval552.html">OVAL552</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/298233">VU#298233</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552">oval:org.mitre.oval:def:552</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded">20030401 Immunix Secured OS 7+ samba update</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8299">8299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8303">8303</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref></refs><vuln_soft><prod name="CIFS/9000 Server" vendor="HP"><vers num="A.01.09.01"/><vers num="A.01.09"/><vers num="A.01.08.01"/><vers num="A.01.08"/><vers num="A.01.07"/><vers num="A.01.06"/><vers num="A.01.05"/></prod><prod name="Samba" vendor="Samba"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.2"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0086" published="2003-03-31" seq="2003-0086" severity="Low" type="CVE"><desc><descript source="cve">The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-262">samba -- remote exploit</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2">GLSA: samba (200303-11)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7107">bid 7107</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval554.html">OVAL554</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554">oval:org.mitre.oval:def:554</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8299">8299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8303">8303</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.2"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0087" published="2003-03-03" seq="2003-0087" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/02.12.03.txt">Buffer Overflow in AIX libIM.a</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/6840">bid 6840</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2">20030212 libIM.a buffer overflow vulnerability</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only">IY40307</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only">IY40317</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only">IY40320</ref><ref source="BID" url="http://www.securityfocus.com/bid/6840">6840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11309">aix-aixterm-libim-bo(11309)</ref><ref source="OSVDB" url="http://www.osvdb.org/7996">7996</ref></refs><vuln_soft><prod name="libIM" vendor="National Language Support"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0088" published="2003-03-03" seq="2003-0088" severity="High" type="CVE"><desc><descript source="cve">TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref><ref adv="1" patch="1" source="Atstake.com" url="http://www.atstake.com/research/advisories/2003/a021403-1.txt">TruBlueEnvironment Privilege Escalation Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6859">bid 6859</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11332.php">Mac OS X TruBlueEnvironment privilege elevation</ref><ref source="BID" url="http://www.securityfocus.com/bid/6859">6859</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2 (Jaguar)"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0089" published="2003-12-15" seq="2003-0089" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106873965001431&amp;w=2">HP-UX Software Distributor Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/6030">Buffer overflow in Software Distributor (SD) for HP-UX</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8986">bid 8986</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/13623">HP-UX SD utilities buffer overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.00"/><vers num="11.11"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2003-0090" published="2003-12-15" reject="1" seq="2003-0090" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0091" published="2003-04-02" seq="2003-0091" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html">Solaris lpq Stack Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4383.html">OVAL4383</ref><ref source="" url="http://www.nsfocus.com/english/homepage/sa2003-02.htm"></ref><ref source="" url="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1">52443</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-068.shtml">N-068</ref><ref source="OSVDB" url="http://www.osvdb.org/8713">8713</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4383">oval:org.mitre.oval:def:4383</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316957/30/25250/threaded">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0092" published="2003-04-02" seq="2003-0092" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html">Solaris dtsession Heap Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1905.html">OVAL1905</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1905">oval:org.mitre.oval:def:1905</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316948/30/25250/threaded">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1">52388</ref><ref source="BID" url="http://www.securityfocus.com/bid/7240">7240</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0093" published="2003-03-03" seq="2003-0093" severity="Medium" type="CVE"><desc><descript source="cve">The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Red Hat" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585">tcpdump can crash a machine when it sees certain udp packets</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11324.php">tcpdump-radius-decoder-dos (11324)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-033.html">RHSA-2003:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11324">tcpdump-radius-decoder-dos(11324)</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.4a6"/><vers num="3.4"/><vers num="3.5"/><vers num="3.5.2"/><vers num="3.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0094" published="2003-03-03" seq="2003-0094" severity="Medium" type="CVE"><desc><descript source="cve">A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:016">util-linux</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6855">bid 6855</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11318">util-linux mcookie utility generates predictable cookies</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016">MDKSA-2003:016</ref><ref source="BID" url="http://www.securityfocus.com/bid/6855">6855</ref></refs><vuln_soft><prod name="util-linux" vendor="Andries Brouwer"><vers num="2.11u"/><vers num="2.11n"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0095" published="2003-03-03" seq="2003-0095" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Oracle.com" url="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf">Oracle unauthenticated remote system compromise (#NISR16022003a)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6849">bid 6849</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html">CERT Advisory CA-2003-05 Multiple Vulnerabilities in Oracle Servers</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2">Oracle unauthenticated remote system compromise (#NISR16022003a)</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11328.php">Oracle Database Server ORACLE.EXE username buffer overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953746">VU#953746</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref><ref source="BID" url="http://www.securityfocus.com/bid/6849">6849</ref><ref source="OSVDB" url="http://www.osvdb.org/6319">6319</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7.1"/><vers num="8.1.7"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="9.0"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0.2"/></prod><prod name="Oracle9i Release 2" vendor="Oracle"><vers num="9.2.2"/><vers num="9.2.1"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0096" published="2003-03-03" seq="2003-0096" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="bid 6847" url="http://online.securityfocus.com/bid/6847">bid 6847</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6848">bid 6848</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6850">bid 6850</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11327.php">Oracle Database Server TO_TIMESTAMP_TZ() buffer overflow</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/840666">Oracle9i Database contains remotely exploitable buffer overflow in &quot;TO_TIMESTAMP_TZ&quot; function</ref><ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</ref><ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/743954">VU#743954</ref><ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/663786">VU#663786</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html">CA-2003-05</ref><ref source="XF" url="http://www.iss.net/security_center/static/11325.php">oracle-bfilename-directory-bo(11325)</ref><ref source="XF" url="http://www.iss.net/security_center/static/11326.php">oracle-tzoffset-bo(11326)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref><ref source="" url="http://www.nextgenss.com/advisories/ora-bfilebo.txt"></ref><ref source="" url="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt"></ref><ref source="" url="http://www.nextgenss.com/advisories/ora-tzofstbo.txt"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref><ref source="BID" url="http://www.securityfocus.com/bid/6847">6847</ref><ref source="BID" url="http://www.securityfocus.com/bid/6848">6848</ref><ref source="BID" url="http://www.securityfocus.com/bid/6850">6850</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7.1"/><vers num="8.1.7"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="9.0"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0.2"/></prod><prod name="Oracle9i Release 2" vendor="Oracle"><vers num="9.2.2"/><vers num="9.2.1"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0097" published="2003-03-03" seq="2003-0097" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.slackware.com/changelog/current.php?cpu=i386">http://www.slackware.com/changelog/current.php?cpu=i386</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2">CGI vulnerability in PHP version 4.3.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6875">bid 6875</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2">GLSA: mod_php php</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11343.php">PHP could allow access to the CGI SAPI</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2">GLSA-200302-09.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/6875">6875</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0098" published="2003-03-03" seq="2003-0098" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:018">apcupsd</ref><ref adv="1" source="Source Forge" url="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6">Diff for /apcupsd/apcupsd/src/apcnisd.c between version 1.5 and 1.6</ref><ref adv="1" patch="1" source="Security Tracker" url="http://securitytracker.com/alerts/2003/Feb/1006108.html">Apcupsd Format String Flaw May Let Remote Users Gain Root Access</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-277">DSA-277-1 apcupsd -- buffer overflows, format string</ref><ref source="MISC" url="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137900">http://sourceforge.net/project/shownotes.php?release_id=137900</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/7200">7200</ref><ref source="XF" url="http://www.iss.net/security_center/static/11334.php">apcupsd-logevent-format-string(11334)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006108">1006108</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref><ref source="BID" url="http://www.securityfocus.com/bid/6828">6828</ref></refs><vuln_soft><prod name="Apcupsd" vendor="APC"><vers num="3.8.5" prev="1"/><vers num="3.10.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0099" published="2003-03-03" seq="2003-0099" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:018">apcupsd</ref><ref adv="1" source="Source Forge" url="http://sourceforge.net/project/shownotes.php?release_id=137900">Apcupsd UPS control software: Release Notes</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6828">bid 6828</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-277">DSA-277-1 apcupsd -- buffer overflows, format string</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11491.php">Apcupsd vsprintf() multiple buffer overflows</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137892">http://sourceforge.net/project/shownotes.php?release_id=137892</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref><ref source="BID" url="http://www.securityfocus.com/bid/7200">7200</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006108">1006108</ref></refs><vuln_soft><prod name="Apcupsd" vendor="APC"><vers num="3.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0100" published="2003-03-03" seq="2003-0100" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2">Cisco IOS OSPF exploit</ref><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2">Re: Cisco IOS OSPF exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6895">bid 6895</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11373.php">Cisco IOS OSPF neighbor buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/6895">6895</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.1 IA"/><vers num="11.1 CT"/><vers num="11.1 CC"/><vers num="11.1 CA"/><vers num="11.1 AA"/><vers num="11.1 (36)CC4"/><vers num="11.1 (36)CC2"/><vers num="11.1 (36)CA2"/><vers num="11.1 (28a)IA"/><vers num="11.1 (28a)CT"/><vers num="11.1 (24b)"/><vers num="11.1 (24a)"/><vers num="11.1 (20)AA4"/><vers num="11.1"/><vers num="11.1.7 CA"/><vers num="11.1.7 AA"/><vers num="11.1.9 IA"/><vers num="11.1.13 IA"/><vers num="11.1.13 CA"/><vers num="11.1.13 AA"/><vers num="11.1.13"/><vers num="11.1.15 IA"/><vers num="11.1.15 CA"/><vers num="11.1.15 AA"/><vers num="11.1.16 IA"/><vers num="11.1.16 AA"/><vers num="11.1.17 CT"/><vers num="11.1.17 CC"/><vers num="11.2 XA"/><vers num="11.2 WA4"/><vers num="11.2 WA3"/><vers num="11.2 SA"/><vers num="11.2 P"/><vers num="11.2 GS"/><vers num="11.2 F"/><vers num="11.2 BC"/><vers num="11.2 (9)XA"/><vers num="11.2 (8.9)SA6"/><vers num="11.2 (4)XAf"/><vers num="11.2 (4)XA"/><vers num="11.2 (4)"/><vers num="11.2 (26b)"/><vers num="11.2 (26a)"/><vers num="11.2 (26)P2"/><vers num="11.2 (23a)BC1"/><vers num="11.2 (19a)GS6"/><vers num="11.2 (19)GS0.2"/><vers num="11.2 (17)"/><vers num="11.2 (11b)T2"/><vers num="11.2"/><vers num="11.2.4 F1"/><vers num="11.2.4 F"/><vers num="11.2.8 SA5"/><vers num="11.2.8 SA3"/><vers num="11.2.8 SA1"/><vers num="11.2.8 P"/><vers num="11.2.9 XA"/><vers num="11.2.9 P"/><vers num="11.2.10 BC"/><vers num="11.3 XA"/><vers num="11.3 WA4"/><vers num="11.3 T"/><vers num="11.3 NA"/><vers num="11.3 MA"/><vers num="11.3 HA"/><vers num="11.3 DB"/><vers num="11.3 DA"/><vers num="11.3 AA"/><vers num="11.3 (8)DB2"/><vers num="11.3 (7)DB1"/><vers num="11.3 (2)XA"/><vers num="11.3 (11c)"/><vers num="11.3 (11b)T2"/><vers num="11.3 (11b)"/><vers num="11.3"/><vers num="11.3.1 T"/><vers num="11.3.1 ED"/><vers num="11.3.11 b"/><vers num="12.0 XW"/><vers num="12.0 XV"/><vers num="12.0 XU"/><vers num="12.0 XS"/><vers num="12.0 XR"/><vers num="12.0 XQ"/><vers num="12.0 XP"/><vers num="12.0 XN"/><vers num="12.0 XM"/><vers num="12.0 XL"/><vers num="12.0 XK"/><vers num="12.0 XJ"/><vers num="12.0 XI"/><vers num="12.0 XH"/><vers num="12.0 XG"/><vers num="12.0 XF"/><vers num="12.0 XE"/><vers num="12.0 XD"/><vers num="12.0 XC"/><vers num="12.0 XB"/><vers num="12.0 XA"/><vers num="12.0 WX"/><vers num="12.0 WT"/><vers num="12.0 WC"/><vers num="12.0 W5"/><vers num="12.0 T"/><vers num="12.0 SX"/><vers num="12.0 ST"/><vers num="12.0 SP"/><vers num="12.0 SL"/><vers num="12.0 SC"/><vers num="12.0 S"/><vers num="12.0 DC"/><vers num="12.0 DB"/><vers num="12.0 DA"/><vers num="12.0 (9a)"/><vers num="12.0 (9)S8"/><vers num="12.0 (9)S"/><vers num="12.0 (9)"/><vers num="12.0 (8a)"/><vers num="12.0 (8.3)SC"/><vers num="12.0 (8.0.2)S"/><vers num="12.0 (8)S1"/><vers num="12.0 (8)"/><vers num="12.0 (7a)"/><vers num="12.0 (7.4)S"/><vers num="12.0 (7)XV"/><vers num="12.0 (7)XK3"/><vers num="12.0 (7)XK"/><vers num="12.0 (7)XF1"/><vers num="12.0 (7)XF"/><vers num="12.0 (7)XE2"/><vers num="12.0 (7)XE"/><vers num="12.0 (7)WX5(15a)"/><vers num="12.0 (7)T2"/><vers num="12.0 (7)T"/><vers num="12.0 (7)SC"/><vers num="12.0 (7)S1"/><vers num="12.0 (7)DC1"/><vers num="12.0 (7)DB2"/><vers num="12.0 (6b)"/><vers num="12.0 (5.4)WC1"/><vers num="12.0 (5.3)WC1"/><vers num="12.0 (5.2)XU"/><vers num="12.0 (5.1)XP"/><vers num="12.0 (5)YB4"/><vers num="12.0 (5)XU"/><vers num="12.0 (5)XS"/><vers num="12.0 (5)XN1"/><vers num="12.0 (5)XN"/><vers num="12.0 (5)XK2"/><vers num="12.0 (5)XK"/><vers num="12.0 (5)XE"/><vers num="12.0 (5)WX"/><vers num="12.0 (5)WC3b"/><vers num="12.0 (5)WC3"/><vers num="12.0 (5)WC2b"/><vers num="12.0 (5)WC2"/><vers num="12.0 (5)WC 2900XL-LRE"/><vers num="12.0 (5)T1"/><vers num="12.0 (5)T"/><vers num="12.0 (4)XM1"/><vers num="12.0 (4)XM"/><vers num="12.0 (4)XE1"/><vers num="12.0 (4)XE"/><vers num="12.0 (3d)"/><vers num="12.0 (3)"/><vers num="12.0 (2b)"/><vers num="12.0 (2)XE"/><vers num="12.0 (18b)"/><vers num="12.0 (18)W5(22b)"/><vers num="12.0 (18)ST1"/><vers num="12.0 (18)S5"/><vers num="12.0 (18)S"/><vers num="12.0 (17a)"/><vers num="12.0 (17)ST5"/><vers num="12.0 (17)ST1"/><vers num="12.0 (17)SL6"/><vers num="12.0 (17)SL2"/><vers num="12.0 (17)S4"/><vers num="12.0 (17)S"/><vers num="12.0 (17)"/><vers num="12.0 (16a)"/><vers num="12.0 (16.06)S"/><vers num="12.0 (16)W5(21)"/><vers num="12.0 (16)ST1"/><vers num="12.0 (16)SC3"/><vers num="12.0 (16)S8"/><vers num="12.0 (15a)"/><vers num="12.0 (15)S6"/><vers num="12.0 (15)S3"/><vers num="12.0 (14a)"/><vers num="12.0 (14)W5(20)"/><vers num="12.0 (14)ST3"/><vers num="12.0 (14)ST"/><vers num="12.0 (14)S7"/><vers num="12.0 (13a)"/><vers num="12.0 (13)WT6(1)"/><vers num="12.0 (13)W5(19c)"/><vers num="12.0 (13)S6"/><vers num="12.0 (12a)"/><vers num="12.0 (12)S3"/><vers num="12.0 (11a)"/><vers num="12.0 (11)ST4"/><vers num="12.0 (11)S6"/><vers num="12.0 (10a)"/><vers num="12.0 (10)W5(18g)"/><vers num="12.0 (10)W5(18f)"/><vers num="12.0 (10)W5"/><vers num="12.0 (10)S7"/><vers num="12.0"/><vers num="12.0.1 XE"/><vers num="12.0.1 XB"/><vers num="12.0.1 XA3"/><vers num="12.0.1 W"/><vers num="12.0.1"/><vers num="12.0.2 XG"/><vers num="12.0.2 XF"/><vers num="12.0.2 XD"/><vers num="12.0.2 XC"/><vers num="12.0.2"/><vers num="12.0.3 T2"/><vers num="12.0.4 T"/><vers num="12.0.4 S"/><vers num="12.0.7 (T)"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2003-0101" published="2003-03-03" seq="2003-0101" severity="High" type="CVE"><desc><descript source="cve">miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2">Webmin/Usermin Session ID Spoofing Vulnerability </ref><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2">Webmin version 1.070 released - fixes security hole</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6915">bid 6915</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11390.php">Webmin and Usermin session ID spoofing root access</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:025">MDKSA-2003:025</ref><ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/62_e.html">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-319">DSA-319</ref><ref source="ENGARDE" url="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html">ESA-20030225-006</ref><ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html">HPSBUX0303-250</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I">20030602-01-I</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-058.shtml">N-058</ref><ref source="BID" url="http://www.securityfocus.com/bid/6915">6915</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2">20030224 GLSA:  usermin (200302-14)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2">20030224 Webmin 1.050 - 1.060 remote exploit</ref><ref source="" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025">MDKSA-2003:025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8115">8115</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8163">8163</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006160">1006160</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="0.4"/><vers num="0.5"/><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/><vers num="0.9"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="0.94"/><vers num="0.95"/><vers num="0.96"/><vers num="0.97"/><vers num="0.98"/><vers num="0.99"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.0.60"/><vers num="1.0.50"/></prod><prod name="Guardian Digital WebTool" vendor="EnGarde"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0102" published="2003-03-18" seq="2003-0102" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/03.04.03.txt">Locally Exploitable Buffer Overflow in file(1)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7008">bid 7008</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7009">bid 7009</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104680706201721&amp;w=2">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-260">DSA-260</ref><ref source="IMMUNIX" url="http://lwn.net/Alerts/34908/">IMNX-2003-7+-012-01</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030">MDKSA-2003:030</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc">NetBSD-SA2003-003</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_017_file.html">SuSE-SA:2003:017</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-086.html">RHSA-2003:086</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-087.html">RHSA-2003:087</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/611865">VU#611865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11469">file-afctr-read-bo(11469)</ref></refs><vuln_soft><prod name="file" vendor="file"><vers num="3.28"/><vers num="3.30"/><vers num="3.32"/><vers num="3.33"/><vers num="3.34"/><vers num="3.35"/><vers num="3.36"/><vers num="3.37"/><vers num="3.39"/><vers num="3.40"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5"/><vers num="1.5.1"/><vers num="1.5.2"/><vers num="1.5.3"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0103" published="2003-03-07" seq="2003-0103" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/6952">bid 6952</ref><ref source="XF" url="http://www.iss.net/security_center/static/11421.php">nokia-6210-vcard-dos(11421)</ref></refs><vuln_soft><prod name="6210 Handset" vendor="Nokia"><vers num="5.27"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0104" published="2003-03-18" seq="2003-0104" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999">PeopleSoft PeopleTools  Remote Command Execution Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/10962.php">peoplesoft-schedulertransfer-create-files(10962)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7053">bid 7053</ref></refs><vuln_soft><prod name="PeopleTools" vendor="PeopleSoft"><vers num="8.10"/><vers num="8.11"/><vers num="8.12"/><vers num="8.13"/><vers num="8.14"/><vers num="8.15"/><vers num="8.16"/><vers num="8.17"/><vers num="8.18"/><vers num="8.40"/><vers num="8.41"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0105" published="2004-09-28" seq="2003-0105" severity="Medium" type="CVE"><desc><descript source="cve">ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="corsaire" url="http://www.corsaire.com/advisories/c030224-001.txt">Port80 Software ServerMask inconsistencies</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16947">ServerMask header field obtain information</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215441332682&amp;w=2">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</ref></refs><vuln_soft><prod name="ServerMask" vendor="Port80 Software"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0106" published="2003-04-02" seq="2003-0106" severity="High" type="CVE"><desc><descript source="cve">The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869513822233&amp;w=2">Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref><ref adv="1" patch="1" source="Symantec" url="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754">How to protect against directory traversal and URL overflow attacks</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7196">bid 7196</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104868285106289&amp;w=2">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref></refs><vuln_soft><prod name="Enterprise Firewall" vendor="Symantec"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2003-0107" published="2003-03-07" seq="2003-0107" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://online.securityfocus.com/archive/1/312869">buffer overrun in zlib 1.1.4</ref><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2">oc zlib sploit just for fun :)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/6913">bid 6913</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11381.php">zlib gzprintf() buffer overflow</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2">20030224 Re: buffer overrun in zlib 1.1.4</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt">CSSA-2003-011.0</ref><ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619">CLSA-2003:619</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2">GLSA-200303-25</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033">MDKSA-2003:033</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc">NetBSD-SA2003-004</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-079.html">RHSA-2003:079</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-081.html">RHSA-2003:081</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405">57405</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/142121">VU#142121</ref><ref source="BID" url="http://www.securityfocus.com/bid/6913">6913</ref><ref source="OSVDB" url="http://www.osvdb.org/6599">6599</ref></refs><vuln_soft><prod name="zlib" vendor="GNU"><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0108" published="2003-03-07" seq="2003-0108" severity="Medium" type="CVE"><desc><descript source="cve">isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6974">bid 6974</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/02.27.03.txt">TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsing</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-255">tcpdump -- infinite loop</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11434.php">tcpdump ISAKMP parsing denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629">CLA-2003:629</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-085.html">RHSA-2003:085</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html">SuSE-SA:2003:0015</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.5.2"/><vers num="3.6.2"/><vers num="3.7"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0109" published="2003-03-31" seq="2003-0109" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029">Microsoft IIS WebDAV Remote Compromise Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-007.asp">Unchecked Buffer In Windows Component Could Cause Web Server Compromise (815021)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-09.html">CERT Advisory CA-2003-09 Buffer Overflow in Core Microsoft Windows DLL</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11533.php">Microsoft IIS WebDAV long request buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7116">bid 7116</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q815021">Q815021</ref><ref source="MISC" url="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval109.html">OVAL109</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/117394">VU#117394</ref><ref source="" url="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826476427372&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104826785731151&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861839130254&amp;w=2">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869293619064&amp;w=2">20030326 WebDAV exploit: using wide character decoder scheme</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887148323552&amp;w=2">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105768156625699&amp;w=2">20030708 WDAV exploit without netcat and with pretty magic number</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:109">oval:org.mitre.oval:def:109</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2003-0110" published="2003-05-05" seq="2003-0110" severity="Medium" type="CVE"><desc><descript source="cve">The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/advisory/04.09.03.txt">Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-012.asp">Flaw In Winsock Proxy Service And ISA Firewall Service Can Cause Denial Of Service (331066)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7314">bid 7314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval406.html">OVAL406</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994487012027&amp;w=2">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000 </ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:406">oval:org.mitre.oval:def:406</ref></refs><vuln_soft><prod name="proxy server" vendor="Microsoft"><vers num="2.0 SP1"/><vers num="2.0"/></prod><prod name="ISA Server" vendor="Microsoft"><vers num="2000 SP1"/><vers num="2000 FP1"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0111" published="2003-05-05" seq="2003-0111" severity="High" type="CVE"><desc><descript source="cve">The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka &quot;Flaw in Microsoft VM Could Enable System Compromise.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-011.asp">Flaw in Microsoft VM Could Enable System Compromise (816093)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/447569">Microsoft Windows Virtual Machine (VM) ByteCode Verifier fails to properly check Java applets for malicious code</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6221">bid 6221</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11751.php">msvm-bytecode-improper-validation(11751)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval136.html">OVAL136</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136">oval:org.mitre.oval:def:136</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/></prod><prod name="Virtual Machine" vendor="Microsoft"><vers num="3802"/><vers num="3805"/><vers num="3809"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0112" published="2003-05-12" seq="2003-0112" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft.com" url="http://www.microsoft.com/technet/security/bulletin/MS03-013.asp">Buffer Overrun in Windows Kernel Message Handling could Lead to Elevated Privileges (811493)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7370">bid 7370</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/446338">VU#446338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1264.html">OVAL1264</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval142.html">OVAL142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval262.html">OVAL262</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval779.html">OVAL779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11803">win-kernel-lpcrequestwaitreplyport-bo(11803)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2022.html">OVAL2022</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2265.html">OVAL2265</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3145.html">OVAL3145</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1264">oval:org.mitre.oval:def:1264</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:142">oval:org.mitre.oval:def:142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:262">oval:org.mitre.oval:def:262</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:779">oval:org.mitre.oval:def:779</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2022">oval:org.mitre.oval:def:2022</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2265">oval:org.mitre.oval:def:2265</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3145">oval:org.mitre.oval:def:3145</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0113" published="2003-05-12" seq="2003-0113" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105138417416900&amp;w=2">Buffer overflow in Internet Explorer&apos;s HTTP parsing code</ref><ref adv="1" patch="1" source="Microsoft.com" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp">Cumulative Patch for Internet Explorer (813489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7419">bid 7419</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval926.html">OVAL926</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/169753">VU#169753</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718285107246&amp;w=2">20030701 URLMON.DLL buffer overflow - technical details</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:926">oval:org.mitre.oval:def:926</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0114" published="2003-05-12" seq="2003-0114" severity="Medium" type="CVE"><desc><descript source="cve">The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104429340817718&amp;w=2"> internet explorer local file reading</ref><ref adv="1" patch="1" source="Microsoft.com" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp">Cumulative Patch for Internet Explorer (813489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6749">bid 6749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval963.html">OVAL963</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:963">oval:org.mitre.oval:def:963</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0115" published="2003-05-12" seq="2003-0115" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the &quot;Third Party Plugin Rendering&quot; vulnerability, a different vulnerability than CVE-2003-0233.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp">Cumulative Patch for Internet Explorer (813489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7491">bid 7491</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11848.php">Microsoft Internet Explorer improper rendering of third party file types could allow code execution</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0116" published="2003-05-12" seq="2003-0116" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka &quot;Modal Dialog script execution.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft.com" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp">Cumulative Patch for Internet Explorer (813489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6306">bid 6306</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/301945">20021203 Poisonous Style for Dialog window turns the zone off.</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/244729">VU#244729</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0117" published="2003-05-12" seq="2003-0117" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp">Cumulative Patch for BizTalk Server (815206)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7469">bid 7469</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216866132289&amp;w=2">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</ref></refs><vuln_soft><prod name="BizTalk Server" vendor="Microsoft"><vers edition="Developer" num="2002"/><vers edition="Enterprise" num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0118" published="2003-05-12" seq="2003-0118" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp">Cumulative Patch for BizTalk Server (815206)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7470">bid 7470</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216839231951&amp;w=2">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</ref></refs><vuln_soft><prod name="BizTalk Server" vendor="Microsoft"><vers edition="Developer" num="2000 SP2"/><vers edition="Developer" num="2000 SP1a"/><vers edition="Developer" num="2000"/><vers edition="Enterprise" num="2000 SP2"/><vers edition="Enterprise" num="2000 SP1a"/><vers edition="Enterprise" num="2000"/><vers edition="Standard" num="2000 SP2"/><vers edition="Standard" num="2000 SP1a"/><vers edition="Standard" num="2000"/><vers edition="Developer" num="2002"/><vers edition="Enterprise" num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0119" published="2004-02-03" seq="2003-0119" severity="High" type="CVE"><desc><descript source="cve">The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/624713">IBM AIX &quot;secldapclntd&quot; daemon authentication vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7264">bid 7264</ref><ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument">MSS-OAR-E01-2003:0245.1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8221">8221</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0120" published="2003-03-07" seq="2003-0120" severity="Low" type="CVE"><desc><descript source="cve">adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-256">mhc -- insecure temporary file</ref><ref source="BID" url="http://www.securityfocus.com/bid/6978">6978</ref><ref source="XF" url="http://www.iss.net/security_center/static/11439.php">mhc-adb2mhc-insecure-tmp(11439)</ref></refs><vuln_soft><prod name="mhc-utils" vendor="mhc-utils"><vers num="0.25 snap2001-06-25"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0121" published="2003-03-18" seq="2003-0121" severity="High" type="CVE"><desc><descript source="cve">Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2">Clearswift MAILsweeper MIME attachment evasion issue</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7044">bid 7044</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316311">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref></refs><vuln_soft><prod name="MailSweeper" vendor="Clearswift"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0122" published="2003-03-18" seq="2003-0122" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2">Buffer Overflow in Lotus Notes Protocol Authentication</ref><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101">Buffer Overflow During Notes Authentication to Domino Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7037">bid 7037</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0010.html">http://www.rapid7.com/advisories/R7-0010.html</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433489">VU#433489</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11526">lotus-nrpc-bo(11526)</ref></refs><vuln_soft><prod name="Lotus Notes Client" vendor="IBM"><vers num="R5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.9a"/><vers num="5.0.10"/><vers num="5.0.11"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="4.6.1"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4a"/><vers edition="Solaris" num="5.0.4"/><vers edition="French" num="5.0.5"/><vers num="5.0.5"/><vers num="5.0.6a"/><vers num="5.0.6"/><vers num="5.0.7a"/><vers edition="Solaris" num="5.0.7"/><vers num="5.0.8a"/><vers edition="French" num="5.0.8"/><vers num="5.0.8"/><vers num="5.0.9a"/><vers num="5.0.9"/><vers num="5.0.10"/><vers num="5.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0123" published="2003-03-18" seq="2003-0123" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2">Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</ref><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060">Web Retriever Buffer Overflow May Cause Denial of Service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7038">bid 7038</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0011.html">http://www.rapid7.com/advisories/R7-0011.html</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/411489">VU#411489</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11525">lotus-web-retriever-bo(11525)</ref></refs><vuln_soft><prod name="Lotus Notes Client" vendor="IBM"><vers num="R5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.9a"/><vers num="5.0.10"/><vers num="5.0.11"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="4.6.1"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4a"/><vers edition="Solaris" num="5.0.4"/><vers edition="French" num="5.0.5"/><vers num="5.0.5"/><vers num="5.0.6a"/><vers num="5.0.6"/><vers num="5.0.7a"/><vers edition="Solaris" num="5.0.7"/><vers num="5.0.8a"/><vers edition="French" num="5.0.8"/><vers num="5.0.8"/><vers num="5.0.9a"/><vers num="5.0.9"/><vers num="5.0.10"/><vers num="5.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2003-0124" published="2003-03-18" seq="2003-0124" severity="Medium" type="CVE"><desc><descript source="cve">man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value &quot;unsafe,&quot; which is then executed as a program via a system call if it is in the search path of the user who runs man.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2">Vulnerability in man &lt; 1.5l</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7066">bid 7066</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620">CLSA-2003:620</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2">GLSA-200303-13</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-133.html">RHSA-2003:133</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-134.html">RHSA-2003:134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11512">man-myxsprintf-code-execution(11512)</ref></refs><vuln_soft><prod name="man" vendor="Andries Brouwer"><vers num="1.5k"/><vers num="1.5j"/><vers num="1.5i2"/><vers num="1.5i"/><vers num="1.5h1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0125" published="2003-03-18" seq="2003-0125" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Kruse Security" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt">SOHO Routefinder 550 VPN, DoS and Buffer Overflow</ref><ref adv="1" source="Multi Tech" url="ftp://ftp.multitech.com/Routers/RF550VPN.TXT">SOHO Routefinder 550 VPN, DoS and Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/7067">7067</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11514">routefinder-vpn-options-bo(11514)</ref></refs><vuln_soft><prod name="RouteFinder 550 VPN" vendor="Multitech"><vers num="4.63" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0126" published="2003-03-18" seq="2003-0126" severity="High" type="CVE"><desc><descript source="cve">The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default &quot;admin&quot; account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Kruse Security" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt">SOHO Routefinder 550 VPN, DoS and Buffer Overflow</ref></refs><vuln_soft><prod name="RouteFinder 550 VPN" vendor="Multitech"><vers num="4.63" prev="1"/><vers num="4.64 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0127" published="2003-03-31" seq="2003-0127" severity="High" type="CVE"><desc><descript source="cve">The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2003-098.html">Updated 2.4 kernel fixes vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7112">bid 7112</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/628849">ptrace contains vulnerability allowing for local root compromise</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-088.html">RHSA-2003:088</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-270">DSA-270</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-276">DSA-276</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311">DSA-311</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:038">MDKSA-2003:038</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:039">MDKSA-2003:039</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt">CSSA-2003-020.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-145.html">RHSA-2003:145</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200303-17.xml">GLSA-200303-17</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval254.html">OVAL254</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html">20030317 Fwd: Ptrace hole / Linux 2.2.25</ref><ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:254">oval:org.mitre.oval:def:254</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-103.html">RHSA-2003:103</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038">MDKSA-2003:038</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039">MDKSA-2003:039</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0128" published="2003-03-24" seq="2003-0128" severity="Medium" type="CVE"><desc><descript source="cve">The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10">Multiple vulnerabilities in Ximian&apos;s Evolution Mail User Agent</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7117">bid 7117</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian &apos;s Evolution Mail User Agent</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval107.html">OVAL107</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2">20030321 GLSA:  evolution (200303-18)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:107">oval:org.mitre.oval:def:107</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0129" published="2003-03-24" seq="2003-0129" severity="Medium" type="CVE"><desc><descript source="cve">Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2">GLSA:  evolution (200303-18)</ref><ref adv="1" patch="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10">Multiple vulnerabilities in Ximian &apos;s Evolution Mail User Agent</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7118">bid 7118</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian &apos;s Evolution Mail User Agent</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval108.html">OVAL108</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:108">oval:org.mitre.oval:def:108</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0130" published="2003-03-24" seq="2003-0130" severity="Medium" type="CVE"><desc><descript source="cve">The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2"> GLSA:  evolution (200303-18)</ref><ref adv="1" patch="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10">Multiple vulnerabilities in Ximian &apos;s Evolution Mail User Agent</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7119">bid 7119</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian &apos;s Evolution Mail User Agent</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval111.html">OVAL111</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:111">oval:org.mitre.oval:def:111</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0131" published="2003-03-24" seq="2003-0131" severity="High" type="CVE"><desc><descript source="cve">The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the &quot;Klima-Pokorny-Rosa attack.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811162730834&amp;w=2">Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</ref><ref adv="1" source="ePrint.iacr.org" url="http://eprint.iacr.org/2003/052/">Attacking RSA-based Sessions in SSL/TLS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7148">bid 7148</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11586"></ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/888801">SSL/TLS implementations disclose side channel information via PKCS #1 v1.5 version number extension</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:035">MDKSA-2003:035</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc">NetBSD-SA2003-007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030319.txt">http://www.openssl.org/news/secadv_20030319.txt</ref><ref source="IMMUNIX" url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html">IMNX-2003-7+-001-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_024_openssl.html">SuSE-SA:2003:024</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval461.html">OVAL461</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852637112330&amp;w=2">20030324 GLSA:  openssl (200303-20)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878215721135&amp;w=2">2003-0013</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461">oval:org.mitre.oval:def:461</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded">20030327 Immunix Secured OS 7+ openssl update</ref><ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml">GLSA-200303-20</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html">OpenPKG-SA-2003.026</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035">MDKSA-2003:035</ref><ref source="SUSE" url="http://www.suse.de/de/security/2003_024_openssl.html">SuSE-SA:2003:024</ref></refs><vuln_soft><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.6b"/><vers num="0.9.6a"/><vers num="0.9.6"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0132" published="2003-04-11" seq="2003-0132" severity="Medium" type="CVE"><desc><descript source="cve">A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2">Apache 2.0.45 Released</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7254">bid 7254</ref><ref source="MISC" url="http://www.idefense.com/advisory/04.08.03.txt">http://www.idefense.com/advisory/04.08.03.txt</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval156.html">OVAL156</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206537">VU#206537</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104982175321731&amp;w=2">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994309010974&amp;w=2">20030408 Exploit Code Released for Apache 2.x Memory Leak</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994239010517&amp;w=2">20030409 GLSA:  apache (200304-01)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001663120995&amp;w=2">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013378320711&amp;w=2">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156">oval:org.mitre.oval:def:156</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0133" published="2003-05-05" seq="2003-0133" severity="Medium" type="CVE"><desc><descript source="cve">GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-126.html">Updated gtkhtml packages fix vulnerability</ref><ref adv="1" patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:046">gtkhtml</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7350">bid 7350</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:046">MDKSA-2003:046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval138.html">OVAL138</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737">CLA-2003:737</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138">oval:org.mitre.oval:def:138</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046">MDKSA-2003:046</ref></refs><vuln_soft><prod name="GtkHTML" vendor="GNOME"><vers num="1.1.9"/><vers num="1.1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0134" published="2003-04-11" seq="2003-0134" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2">Apache 2.0.45 Released</ref><ref patch="1" source="Apache" url="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0135" published="2003-04-11" seq="2003-0135" severity="High" type="CVE"><desc><descript source="cve">vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-084.html">Updated vsftpd packages re-enable tcp_wrappers support</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7253">bid 7253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval634.html">OVAL634</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:634">oval:org.mitre.oval:def:634</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0136" published="2003-05-05" seq="2003-0136" severity="Low" type="CVE"><desc><descript source="cve">psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-285">lprng -- insecure temporary file</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7334">bid 7334</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-142.html">Updated LPRng packages fix psbanner vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval423.html">OVAL423</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:423">oval:org.mitre.oval:def:423</ref></refs><vuln_soft><prod name="LPRng" vendor="AStArt Technologies"><vers num="3.7.4"/><vers num="3.8.9"/><vers num="3.8.10.1"/><vers num="3.8.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0137" published="2003-03-18" seq="2003-0137" severity="Medium" type="CVE"><desc><descript source="cve">SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2003/a031303-2.txt">Nokia SGSN (DX200 Based Network Element) SNMP issue</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7081">bid 7081</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8301">8301</ref></refs><vuln_soft><prod name="SGSN DX200" vendor="Nokia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0138" published="2003-03-24" seq="2003-0138" severity="High" type="CVE"><desc><descript source="cve">Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-266">DSA-266-1 krb5 -- several vulnerabilities</ref><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt">Cryptographic weaknesses in Kerberos v4 protocol</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/623217">Cryptographic weakness in Kerberos Version 4 protocol</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-269">DSA-269</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval248.html">OVAL248</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:248">oval:org.mitre.oval:def:248</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref><ref source="BID" url="http://www.securityfocus.com/bid/7113">7113</ref></refs><vuln_soft><prod name="Kerberos 4" vendor="MIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0139" published="2003-03-24" seq="2003-0139" severity="High" type="CVE"><desc><descript source="cve">Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and &quot;ticket splicing.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2">MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt">Cryptographic weaknesses in Kerberos v4 protocol</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/442569">MIT Kerberos vulnerable to ticket splicing when using Kerberos4 triple DES service tickets</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval250.html">OVAL250</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:250">oval:org.mitre.oval:def:250</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317130/30/25250/threaded">20030330 GLSA: openafs (200303-26)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref></refs><vuln_soft><prod name="Kerberos 4" vendor="MIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0140" published="2003-03-24" seq="2003-0140" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104818814931378&amp;w=2">Vulnerability in Mutt Mail User Agent</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/315679">mutt-1.4.1 fixes a buffer overflow.</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7120">bid 7120</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11583">Mutt long folder name buffer overflow</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-268">DSA-268</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_020_mutt.html">SuSE-SA:2003:020</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:041">MDKSA-2003:041</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-109.html">RHSA-2003:109</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2.html">OVAL2</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval434.html">OVAL434</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10"></ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626">CLA-2003:626</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630">CLA-2003:630</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104817995421439&amp;w=2">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852190605988&amp;w=2">20030322 GLSA:  mutt (200303-19)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105171507629573&amp;w=2">20030430 GLSA:  balsa (200304-10)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2">oval:org.mitre.oval:def:2</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434">oval:org.mitre.oval:def:434</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml">GLSA-200303-19</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041">MDKSA-2003:041</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="1.3.12"/><vers num="1.3.16"/><vers num="1.3.17"/><vers num="1.3.22"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.27"/><vers num="1.4.0"/><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2003-0141" published="2003-04-02" seq="2003-0141" severity="Medium" type="CVE"><desc><descript source="cve">The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CoreSecurity.com" url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10">RealPlayer PNG deflate heap corruption vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7177">BID 7177</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887465427579&amp;w=2">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref><ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/705761">VU#705761</ref></refs><vuln_soft><prod name="RealOne Player" vendor="RealNetworks"><vers num="9.0.0.297"/><vers num="9.0.0.288"/><vers num="6.0.11.853"/><vers num="6.0.11.841"/><vers num="6.0.11.830"/><vers num="6.0.11.818"/><vers num="2.0"/><vers edition="Gold" num="6.0.10.505"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers num="8.0"/></prod><prod name="RealOne Enterprise Desktop" vendor="RealNetworks"><vers num="6.0.11.774"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0142" published="2003-08-18" seq="2003-0142" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the &quot;Certified plug-ins only&quot; option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/328224">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/689835">VU#689835</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2003-0143" published="2003-03-18" seq="2003-0143" severity="High" type="CVE"><desc><descript source="cve">The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739841223916&amp;w=2">QPopper 4.0.x buffer overflow vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-259">qpopper -- mail user privilege escalation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7058">bid 7058</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11516">Qpopper pop_msg () long macroname buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104748775900481&amp;w=2">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792541215354&amp;w=2">GLSA-200303-12</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html">SuSE-SA:2003:018</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104768137314397&amp;w=2">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0144" published="2003-03-31" seq="2003-0144" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2003_014_lprold.html">lprold</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7025">bid 7025</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11473">OpenBSD lprm buffer overflow</ref><ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-267">DSA-267</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-275">DSA-275</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:059">MDKSA-2003:059</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P">20030406-02-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_014_lprold.html">SuSE-SA:2003:0014</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104690434504429&amp;w=2">20030305 potential buffer overflow in lprm (fwd)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104714441925019&amp;w=2">20030308 OpenBSD lprm(1) exploit</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059">MDKSA-2003:059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8293">8293</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/></prod><prod name="lprold" vendor="lprold"><vers num="3.0.48"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/><vers num="2.8"/><vers num="2.9"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/></prod><prod name="lpr" vendor="BSD"><vers num="2000-05-07"/><vers num="0.48"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2003-0145" published="2003-03-31" seq="2003-0145" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in tcpdump before 3.7.2 related to an inability to &quot;Handle unknown RADIUS attributes properly,&quot; allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TcpDump" url="http://www.tcpdump.org/tcpdump-changes.txt"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-151.html">RHSA-2003:151</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11857">tcpdump-radius-attribute-dos(11857)</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.5.2"/><vers num="3.6.2"/><vers num="3.7"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0146" published="2003-03-31" seq="2003-0146" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via &quot;maths overflow errors&quot; such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104644687816522&amp;w=2">NetPBM, multiple vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-263">netpbm-free -- math overflow errors</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-060.html">RHSA-2003:060</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/630433">VU#630433</ref><ref source="BID" url="http://www.securityfocus.com/bid/6979">6979</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11463">netpbm-multiple-bo(11463)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656">CLSA-2003:656</ref></refs><vuln_soft><prod name="NetPBM" vendor="NetPBM"><vers num="9.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0147" published="2003-03-31" seq="2003-0147" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server&apos;s private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms (&quot;Karatsuba&quot; and normal).</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766550528628&amp;w=2">Vulnerability in OpenSSL</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html">OpenSSL Private Key Disclosure</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792570615648&amp;w=2">Timing Attack on OpenSSL</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/997481">Cryptographic libraries and applications do not adequately defend against timing attacks</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7101">bid 7101</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030317.txt">http://www.openssl.org/news/secadv_20030317.txt</ref><ref source="MISC" url="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035">MDKSA-2003:035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval466.html">OVAL466</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861762028637&amp;w=2">GLSA-200303-24</ref><ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104829040921835&amp;w=2">GLSA-200303-15</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104819602408063&amp;w=2">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:466">oval:org.mitre.oval:def:466</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded">20030327 Immunix Secured OS 7+ openssl update</ref><ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml">GLSA-200303-23</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html">OpenPKG-SA-2003.019</ref></refs><vuln_soft><prod name="Stunnel" vendor="Stunnel"><vers num="3.20"/><vers num="3.10"/><vers num="3.7"/><vers num="3.8"/><vers num="3.9"/><vers num="3.11"/><vers num="3.12"/><vers num="3.13"/><vers num="3.14"/><vers num="3.15"/><vers num="3.16"/><vers num="3.17"/><vers num="3.18"/><vers num="3.19"/><vers num="3.21"/><vers num="3.22"/><vers num="4.04"/><vers num="4.03"/><vers num="4.02"/><vers num="4.01"/><vers num="4.0"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="1.1"/><vers num="1.2"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.6b"/><vers num="0.9.6a"/><vers num="0.9.6"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0148" published="2003-08-27" seq="2003-0148" severity="High" type="CVE"><desc><descript source="cve">The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Atstake.com" url="http://www.atstake.com/research/advisories/2003/a073103-1.txt">ePolicy Orchestrator Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="Nai.com" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp">Network Associates Security Bulletin 07/31/03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8319">bid 8319</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num="2.0"/><vers num="2.5 SP1"/><vers num="2.5"/><vers num="2.5.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0149" published="2003-08-27" seq="2003-0149" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Atstake.com" url="http://www.atstake.com/research/advisories/2003/a073103-1.txt">ePolicy Orchestrator Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="Nai.com" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp">Network Associates Security Bulletin 07/31/03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8316">bid 8316</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num="2.0"/><vers num="2.5 SP1"/><vers num="2.5"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-30" name="CVE-2003-0150" published="2003-03-24" seq="2003-0150" severity="High" type="CVE"><desc><descript source="cve">MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the &quot;SELECT * INFO OUTFILE&quot; operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2">MySQL_user_can_be_changed_to_root?</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7052">bid 7052</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2">OpenPKG Security Advisory (mysql)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2">20030308 MySQL_user_can_be_changed_to_root?</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739810523433&amp;w=2">20030310 Re: MySQL user can be changed to root</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-303">DSA-303</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html">ESA-20030324-012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-094.html">RHSA-2003:094</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:057">MDKSA-2003:057</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285012750&amp;w=2">20030318 GLSA:  mysql (200303-14)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203897">VU#203897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11510">mysql-datadir-root-privileges(11510)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval442.html">OVAL442</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:442">oval:org.mitre.oval:def:442</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057">MDKSA-2003:057</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.52"/><vers num="3.23.53a"/><vers num="3.23.53"/><vers num="3.23.54a"/><vers num="3.23.54"/><vers num="3.23.55"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0151" published="2003-03-24" seq="2003-0151" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792477914620&amp;w=2">Remote Administration of BEA WebLogic Server and Express</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792544515384&amp;w=2">Multiple vulnerabilities in BEA WebLogic Server</ref><ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-011-en.txt">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</ref><ref source="BID" url="http://www.securityfocus.com/bid/7122">7122</ref><ref source="BID" url="http://www.securityfocus.com/bid/7124">7124</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0152" published="2003-04-02" seq="2003-0152" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-265">bonsai -- several</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7162">bid 7162</ref></refs><vuln_soft><prod name="Bonsai" vendor="Mozilla"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0153" published="2003-04-02" seq="2003-0153" severity="Medium" type="CVE"><desc><descript source="cve">bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2">Bonsai XSS and Physical Path Revealing Vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-265">bonsai -- several</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/5517">bid 5517</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=187230">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/9921">bonsai-path-disclosure(9921)</ref><ref source="BID" url="http://www.securityfocus.com/bid/5517">5517</ref></refs><vuln_soft><prod name="Bonsai" vendor="Mozilla"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0154" published="2003-04-02" seq="2003-0154" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2">Bonsai XSS and Physical Path Revealing Vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-265">bonsai -- several</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/5516">bid 5516</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=163573">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</ref><ref source="MISC" url="http://bugzilla.mozilla.org/show_bug.cgi?id=146244">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</ref><ref source="XF" url="http://www.iss.net/security_center/static/9920.php">bonsai-error-message-xss(9920)</ref><ref source="" url="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view"></ref><ref source="" url="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view"></ref></refs><vuln_soft><prod name="Bonsai" vendor="Mozilla"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0155" published="2003-04-02" seq="2003-0155" severity="Medium" type="CVE"><desc><descript source="cve">bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-265">bonsai -- several</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7163">bid 7163</ref></refs><vuln_soft><prod name="Bonsai" vendor="Mozilla"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0156" published="2003-03-24" seq="2003-0156" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739747222492&amp;w=2">Cross-Referencing Linux vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-264">lxr -- missing filename sanitizing</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7062">bid 7062</ref></refs><vuln_soft><prod name="LXR" vendor="Cross Referencer"><vers num="0.3"/><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-2003-0157" published="2003-03-24" reject="1" seq="2003-0157" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry modified="2005-10-31" name="CVE-2003-0158" published="2003-03-24" reject="1" seq="2003-0158" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0159" published="2003-04-02" seq="2003-0159" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Ethereal" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html">SOCKS string format vulnerability in Ethereal 0.9.9</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2003_019_ethereal.html">ethereal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7050">bid 7050</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval55.html">OVAL55</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104741640924709&amp;w=2">20030309 GLSA:  ethereal (200303-10)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:55">oval:org.mitre.oval:def:55</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.18"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0160" published="2003-04-02" seq="2003-0160" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client&apos;s web browser.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="Source Forge" url="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988">SquirrelMail 1.2.11 has been released</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-112.html">RHSA-2003:112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval614.html">OVAL614</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:614">oval:org.mitre.oval:def:614</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.2.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0161" published="2003-04-02" seq="2003-0161" severity="High" type="CVE"><desc><descript source="cve">The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special &quot;NOCHAR&quot; control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104897487512238&amp;w=2">Sendmail: -1 gone wild</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-12.html">CERT Advisory CA-2003-12 Buffer Overflow in Sendmail</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7230">bid 7230</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-120.html">Updated sendmail packages fix vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html">20030329 Sendmail: -1 gone wild</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/897604">VU#897604</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc">FreeBSD-SA-03:07</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-121.html">RHSA-2003:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt">SCOSA-2004.11</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P">20030401-01-P</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt">CSSA-2003-016.0</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-278">DSA-278</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-290">DSA-290</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104896621106790&amp;w=2">20030329 sendmail 8.12.9 available</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614">CLA-2003:614</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914999806315&amp;w=2">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321997">20030520 [Fwd: 127 Research and Development: 127 Day!]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316961/30/25250/threaded">20030331 GLSA: sendmail (200303-27)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded">20030401 Immunix Secured OS 7+ openssl update</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml">GLSA-200303-27</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1">52620</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1">52700</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail"><vers num="8.9.0"/><vers num="8.9.1"/><vers num="8.9.2"/><vers num="8.9.3"/><vers num="8.10"/><vers num="8.10.1"/><vers num="8.10.2"/><vers num="8.11"/><vers num="8.11.1"/><vers num="8.11.2"/><vers num="8.11.3"/><vers num="8.11.4"/><vers num="8.11.5"/><vers num="8.11.6"/><vers num="8.12 beta7"/><vers num="8.12 Beta5"/><vers num="8.12 Beta16"/><vers num="8.12 Beta12"/><vers num="8.12 Beta10"/><vers num="8.12.0"/><vers num="8.12.1"/><vers num="8.12.2"/><vers num="8.12.3"/><vers num="8.12.4"/><vers num="8.12.5"/><vers num="8.12.6"/><vers num="8.12.7"/><vers num="8.12.8"/><vers num="2.6"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/></prod><prod name="Sendmail Switch" vendor="Sendmail"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.1.5"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/></prod><prod name="Tru64" vendor="Compaq"><vers num="4.0g PK3_BL17"/><vers num="4.0g"/><vers num="4.0f PK7_BL18"/><vers num="4.0f PK6_BL17"/><vers num="4.0f"/><vers num="4.0d PK9_BL17"/><vers num="4.0d"/><vers num="4.0b"/><vers num="5.0f"/><vers num="5.0a PK3_BL17"/><vers num="5.0a"/><vers num="5.0 PK4_BL18"/><vers num="5.0 PK4_BL17"/><vers num="5.0"/><vers num="5.1b PK1_BL1"/><vers num="5.1b"/><vers num="5.1a PK3_BL3"/><vers num="5.1a PK2_BL2"/><vers num="5.1a PK1_BL1"/><vers num="5.1a"/><vers num="5.1 PK6_BL20"/><vers num="5.1 PK5_BL19"/><vers num="5.1 PK4_BL18"/><vers num="5.1 PK3_BL17"/><vers num="5.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.01"/><vers num="10.0"/><vers num="10.1"/><vers num="10.8"/><vers num="10.9"/><vers num="10.10"/><vers num="10.16"/><vers num="10.20 SIS"/><vers num="10.20 Series 800"/><vers num="10.20 Series 700"/><vers num="10.20"/><vers num="10.26"/><vers num="10.30"/><vers num="10.34"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/><vers num="10.24"/><vers num="11.0.4"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.4"/><vers num="2.4"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0162" published="2003-04-02" seq="2003-0162" severity="High" type="CVE"><desc><descript source="cve">Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11431">Ecartis password reset</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673407728323&amp;w=2">Ecardis Password Reseting Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6971">bid 6971</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-271">DSA-271</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636153214262&amp;w=2">20030227 Ecardis Password Reseting Vulnerability</ref></refs><vuln_soft><prod name="Ecartis" vendor="Ecartis"><vers num="1.0.0 snapshot 2002-10-13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0163" published="2003-05-05" seq="2003-0163" severity="Medium" type="CVE"><desc><descript source="cve">decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Rapid7.com" url="http://www.rapid7.com/advisories/R7-0013.html">Heap Corruption in Gaim-Encryption Plugin</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7182">bid 7182</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013281120352&amp;w=2">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</ref></refs><vuln_soft><prod name="Gaim-Encryption" vendor="Gaim-Encryption"><vers num="1.13"/><vers num="1.14"/><vers num="1.15"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0165" published="2003-04-02" seq="2003-0165" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-128.html">Updated Eye of GNOME packages fix vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7121">bid 7121</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887189724146&amp;w=2">20030328 CORE-2003-0304-03: Vulnerability in GNOME&apos;s Eye of Gnome</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html">20030328 Vulnerability in GNOME&apos;s Eye of Gnome</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:048">MDKSA-2003:048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval52.html">OVAL52</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/363001">VU#363001</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:52">oval:org.mitre.oval:def:52</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048">MDKSA-2003:048</ref></refs><vuln_soft><prod name="eog" vendor="GNOME"><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0166" published="2003-04-02" seq="2003-0166" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869828526885&amp;w=2">nteger overflow in PHP memory allocator</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7197">bid 7197</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7198">bid 7198</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7199">bid 7199</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878100719467&amp;w=2">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691">CLSA-2003:691</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.1.0.0"/><vers num="4.1.0.1"/><vers num="4.1.0.2"/><vers num="4.2.0.0"/><vers num="4.2.0.1"/><vers num="4.2.0.2"/><vers num="4.2.0.3"/><vers num="4.3"/><vers num="4.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0167" published="2003-04-02" seq="2003-0167" severity="High" type="CVE"><desc><descript source="cve">Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-274">mutt -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7229">bid 7229</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-300">DSA-300</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="1.3.12.1"/><vers num="1.3.12"/><vers num="1.3.16"/><vers num="1.3.17"/><vers num="1.3.22"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.27"/><vers num="1.3.28"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0168" published="2003-04-02" seq="2003-0168" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis.com" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html">[VulnWatch] iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref><ref source="MISC" url="http://www.idefense.com/advisory/03.31.03.txt">http://www.idefense.com/advisory/03.31.03.txt</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00027.html">http://lists.apple.com/mhonarc/security-announce/msg00027.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/112553">VU#112553</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded">20030401 Fwd: QuickTime 6.1 for Windows is available</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317148/30/25220/threaded">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref><ref source="BID" url="http://www.securityfocus.com/bid/7247">7247</ref><ref source="OSVDB" url="http://www.osvdb.org/10561">10561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11671">quicktime-url-bo(11671)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="5.0"/><vers num="6.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0169" published="2003-04-11" seq="2003-0169" severity="Medium" type="CVE"><desc><descript source="cve">hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html">Malformed request causes denial of service in HP Instant TopTools</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7246">bid 7246</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914959705949&amp;w=2">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref></refs><vuln_soft><prod name="Instant TopTools" vendor="HP"><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0170" published="2004-03-29" seq="2003-0170" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424">NATIVE GSSAPI FTPD INCORRECTLY AUTHENTICATES USER</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7346">bid 7346</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11823">Aix ftpd (File Transfer Protocol Daemon) Kerberos 5 authentication allows unauthorized access</ref><ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1">MSS-OAR-E01-2003.0469.1</ref><ref source="OSVDB" url="http://www.osvdb.org/4878">4878</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0171" published="2003-05-05" seq="2003-0171" severity="High" type="CVE"><desc><descript source="cve">DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2003/a041003-1.txt">MacOS X DirectoryService Privilege Escalation and DoS Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7322">bid 7322</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.0"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.0"/><vers num="10.0.1"/><vers num="10.0.2"/><vers num="10.0.3"/><vers num="10.0.4"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0172" published="2003-04-02" seq="2003-0172" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878149020152&amp;w=2">PHP for Win32: buffer overflow in openlog() function</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7210">bid 7210</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316583">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/385238">20041222 PHP v4.3.x exploit for Windows.</ref><ref source="OSVDB" url="http://www.osvdb.org/2113">2113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11637">php-openlog-stack-bo(11637)</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0173" published="2003-05-05" seq="2003-0173" severity="High" type="CVE"><desc><descript source="cve">xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sgi" url="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P">xfsdump creates files insecurely</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/7321">bid 7321</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-283">xfsdump -- insecure file creation</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:047">MDKSA-2003:047</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/111673">VU#111673</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047">MDKSA-2003:047</ref></refs><vuln_soft><prod name="xfsdump" vendor="xfsdump"><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0174" published="2003-05-12" seq="2003-0174" severity="High" type="CVE"><desc><descript source="cve">The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sgi.com" url="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P">Vulnerability in nsd LDAP Implementation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7442">bid 7442</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-084.shtml">N-084</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11860">irix-ldap-authentication-bypass(11860)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.19"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0175" published="2004-02-03" seq="2003-0175" severity="Low" type="CVE"><desc><descript source="cve">SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/142228">SGI IRIX vulnerable to DoS when user space program calls the PIOCSWATCH ioctl() function</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/12241">SGI IRIX PIOCSWATCH ioctl() denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7868">bid 7868</ref><ref adv="1" patch="1" source="Sgi.com" url="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008770">1008770</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0176" published="2003-08-18" seq="2003-0176" severity="Medium" type="CVE"><desc><descript source="cve">The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P">20030701-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.5"/><vers num="6.5.6"/><vers num="6.5.7"/><vers num="6.5.8"/><vers num="6.5.9"/><vers num="6.5.10"/><vers num="6.5.11"/><vers num="6.5.12"/><vers num="6.5.13"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.20m"/><vers num="6.5.20f"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0177" published="2003-08-18" seq="2003-0177" severity="Medium" type="CVE"><desc><descript source="cve">SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow &quot;-&quot; entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P">20030701-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.5"/><vers num="6.5.6"/><vers num="6.5.7"/><vers num="6.5.8"/><vers num="6.5.9"/><vers num="6.5.10"/><vers num="6.5.11"/><vers num="6.5.12"/><vers num="6.5.13"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.20m"/><vers num="6.5.20f"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0178" published="2003-04-02" seq="2003-0178" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431461&amp;w=2">Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/772817">Lotus Domino Web Server vulnerable to buffer overflow via non-existent </ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6871">bid 6871</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11337">Lotus Domino Host: header redirect buffer overflow</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206361">VU#206361</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/542873">VU#542873</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11336">lotus-domino-inotes-bo(11336)</ref><ref source="BID" url="http://www.securityfocus.com/bid/6870">6870</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777531350&amp;w=2">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431463&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777331345&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref></refs><vuln_soft><prod name="Lotus Domino Web Server" vendor="IBM"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0179" published="2003-04-02" seq="2003-0179" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550124032513&amp;w=2">Lotus iNotes Client ActiveX Control Buffer Overrun</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/571297">Lotus Notes and Domino COM Object Control Handler contains buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6872">bid 6872</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</ref><ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104543">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11339">lotus-notes-activex-bo(11339)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778131373&amp;w=2">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref></refs><vuln_soft><prod name="Lotus Notes Client" vendor="IBM"><vers num="6.0"/></prod><prod name="Lotus Domino Web Server" vendor="IBM"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0180" published="2003-04-02" seq="2003-0180" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Nextgenss.com" url="http://www.nextgenss.com/advisories/lotus-60dos.txt">LOTUS DOMINO Denial Of Service Attacks 1 &amp; 2</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CERT Advisory CA-2003-11 Multiple Vulnerabilities in Lotus Notes and Domino</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/355169">Lotus Domino Web Server vulnerable to denial of service via incomplete POST request</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-60dos.txt">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref><ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11360">lotus-incomplete-post-dos(11360)</ref><ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref></refs><vuln_soft><prod name="Lotus Domino Web Server" vendor="IBM"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2003-0181" published="2003-04-02" seq="2003-0181" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a &quot;Fictionary Value Field POST request&quot; as demonstrated using the s_Validation form with a long, unknown parameter name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Nextgenss.com" url="http://www.nextgenss.com/advisories/lotus-60dos.txt">LOTUS DOMINO Denial Of Service Attacks 1 &amp; 2</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CERT Advisory CA-2003-11 Multiple Vulnerabilities in Lotus Notes and Domino</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref><ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11361">lotus-invalid-field-dos(11361)</ref><ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref></refs><vuln_soft><prod name="Lotus Domino Web Server" vendor="IBM"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0187" published="2003-08-27" seq="2003-0187" severity="Medium" type="CVE"><desc><descript source="cve">The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20&apos;s support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986028426824&amp;w=2">Netfilter Security Advisory: Conntrack list_del() DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8331">bid 8331</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval260.html">OVAL260</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:260">oval:org.mitre.oval:def:260</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0188" published="2003-06-09" seq="2003-0188" severity="High" type="CVE"><desc><descript source="cve">lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-169.html">RHSA-2003:169</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-304">DSA-304</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-167.html">RHSA-2003:167</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-35.txt">TLSA-2003-35</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval430.html">OVAL430</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:430">oval:org.mitre.oval:def:430</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/><vers edition="i386" num="9.0"/></prod><prod name="Iv" vendor="Red Hat"><vers edition="i386" num="4.49.4.1"/><vers edition="i386" num="4.49.4.3"/><vers edition="i386" num="4.49.4.7"/><vers edition="i386" num="4.49.4.9"/></prod><prod name="lv" vendor="lv"><vers num="4.49.1"/><vers num="4.49.2"/><vers num="4.49.3"/><vers num="4.49.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0189" published="2003-06-09" seq="2003-0189" severity="Medium" type="CVE"><desc><descript source="cve">The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><design/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apache" url="http://www.apache.org/dist/httpd/Announcement2.html"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-186.html">RHSA-2003:186</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/479268">VU#479268</ref><ref source="BID" url="http://www.securityfocus.com/bid/7725">7725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8881">8881</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12091">apache-aprpasswordvalidate-dos(12091)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661">CLA-2003:661</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2003-0190" published="2003-05-12" seq="2003-0190" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2">OpenSSH/PAM timing attack allows remote users identification</ref><ref adv="1" source="NetSys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2003-April/009493.html">OpenSSH/PAM timing attack allows remote users identification</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7467">bid 7467</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2">20030430 OpenSSH/PAM timing attack allows remote users identification</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html">20030430 OpenSSH/PAM timing attack allows remote users identification</ref><ref source="MISC" url="http://lab.mediaservice.net/advisory/2003-01-openssh.txt">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-222.html">RHSA-2003:222</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-224.html">RHSA-2003:224</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018677302607&amp;w=2">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-31.txt">TLSA-2003-31</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval445.html">OVAL445</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:445">oval:org.mitre.oval:def:445</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.4 p1"/><vers num="3.6.1 p1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0192" published="2003-08-18" seq="2003-0192" severity="Medium" type="CVE"><desc><descript source="cve">Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle &quot;certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one,&quot; which could cause Apache to use the weak ciphersuite.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8134">BID: 8134</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-240.html">Updated httpd packages fix Apache security vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt">SCOSA-2004.6</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval169.html">OVAL169</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:169">oval:org.mitre.oval:def:169</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0193" published="2004-08-18" seq="2003-0193" severity="Low" type="CVE"><desc><descript source="cve">msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names (&quot;word$$.html&quot;).</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-575">DSA-575</ref><ref source="BID" url="http://www.securityfocus.com/bid/11560">11560</ref><ref source="OSVDB" url="http://www.osvdb.org/11193">11193</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13021/">13021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13022/">13022</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16335">catdoc-xlsview-symlink(16335)</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525"></ref></refs><vuln_soft><prod name="catdoc" vendor="catdoc"><vers num="0.91" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0194" published="2003-06-09" seq="2003-0194" severity="Medium" type="CVE"><desc><descript source="cve">tcpdump does not properly drop privileges to the pcap user when starting up.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-174.html">RHSA-2003:174</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-151.html">RHSA-2003:151</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/><vers edition="i386" num="9.0"/></prod><prod name="tcpdump" vendor="Red Hat"><vers edition="i386" num="3.4.39"/><vers edition="i386" num="3.6.2.12"/><vers edition="i386" num="3.6.2.9"/><vers edition="IA64" num="3.6.2.9"/><vers edition="i386" num="3.6.3.3"/><vers edition="i386" num="3.7.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0195" published="2003-06-16" seq="2003-0195" severity="Medium" type="CVE"><desc><descript source="cve">CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat Linux" url="http://www.redhat.com/support/errata/RHSA-2003-171.html">Updated CUPS packages fix denial of service attack</ref><ref source="" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:062"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-317">DSA-317-1 cupsys -- denial of service</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:062">MDKSA-2003:062</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_028.html">SuSE-SA:2003:028</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-33.txt">TLSA-2003-33</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6.html">OVAL6</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427288724449&amp;w=2">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678">CLSA-2003:678</ref><ref source="BID" url="http://www.securityfocus.com/bid/7637">7637</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6">oval:org.mitre.oval:def:6</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062">MDKSA-2003:062</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="8.1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0196" published="2003-05-05" seq="2003-0196" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-280">samba -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7295">bid 7295</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104973186901597&amp;w=2">OpenPKG Security Advisory (samba)</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-137.html">New samba packages fix security vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval564.html">OVAL564</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:564">oval:org.mitre.oval:def:564</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref></refs><vuln_soft><prod name="CIFS/9000 Server" vendor="HP"><vers num="A.01.09.02"/><vers num="A.01.09.01"/><vers num="A.01.09"/><vers num="A.01.08.01"/><vers num="A.01.08"/><vers num="A.01.07"/><vers num="A.01.06"/><vers num="A.01.05"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod><prod name="Samba" vendor="Samba"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.2"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/><vers num="2.2.8"/></prod><prod name="Tru64" vendor="Compaq"><vers num="4.0g PK3_BL17"/><vers num="4.0g"/><vers num="4.0f PK7_BL18"/><vers num="4.0f PK6_BL17"/><vers num="4.0f"/><vers num="4.0d PK9_BL17"/><vers num="4.0d"/><vers num="4.0b"/><vers num="5.0f"/><vers num="5.0a PK3_BL17"/><vers num="5.0a"/><vers num="5.0 PK4_BL18"/><vers num="5.0 PK4_BL17"/><vers num="5.0"/><vers num="5.1b PK1_BL1"/><vers num="5.1b"/><vers num="5.1a PK3_BL3"/><vers num="5.1a PK2_BL2"/><vers num="5.1a PK1_BL1"/><vers num="5.1a"/><vers num="5.1 PK6_BL20"/><vers num="5.1 PK5_BL19"/><vers num="5.1 PK4_BL18"/><vers num="5.1 PK3_BL17"/><vers num="5.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.01"/><vers num="10.20"/><vers num="10.24"/><vers num="11.04"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/></prod><prod name="Samba-TNG" vendor="Samba-TNG"><vers num="0.3"/><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2003-0197" published="2003-04-11" seq="2003-0197" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Secnetops.com" url="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt">Interbase ISC_LOCK_ENV overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7266">bid 7266</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104940730819887&amp;w=2">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="1.0.2"/></prod><prod name="Interbase" vendor="Borland Software"><vers num="6.0"/><vers num="6.4"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0198" published="2003-05-05" seq="2003-0198" severity="Medium" type="CVE"><desc><descript source="cve">Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7324">bid 7324</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.0"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.0"/><vers num="10.0.1"/><vers num="10.0.2"/><vers num="10.0.3"/><vers num="10.0.4"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0201" published="2003-05-05" seq="2003-0201" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104972664226781&amp;w=2">Buffer Overflow in Samba allows remote root compromise</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-280">samba -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7294">bid 7294</ref><ref source="MISC" url="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_025_samba.html">SuSE-SA:2003:025</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-137.html">RHSA-2003:137</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P">20030403-01-P</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval567.html">OVAL567</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2163.html">OVAL2163</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/267873">VU#267873</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624">CLA-2003:624</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994564212488&amp;w=2">20030409 GLSA:  samba (200304-02)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104981682014565&amp;w=2">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:567">oval:org.mitre.oval:def:567</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2163">oval:org.mitre.oval:def:2163</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref></refs><vuln_soft><prod name="CIFS/9000 Server" vendor="HP"><vers num="A.01.09.02"/><vers num="A.01.09.01"/><vers num="A.01.09"/><vers num="A.01.08.01"/><vers num="A.01.08"/><vers num="A.01.07"/><vers num="A.01.06"/><vers num="A.01.05"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod><prod name="Samba" vendor="Samba"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.3a"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/><vers num="2.2.8"/></prod><prod name="Tru64" vendor="Compaq"><vers num="4.0g PK3_BL17"/><vers num="4.0g"/><vers num="4.0f PK7_BL18"/><vers num="4.0f PK6_BL17"/><vers num="4.0f"/><vers num="4.0d PK9_BL17"/><vers num="4.0d"/><vers num="4.0b"/><vers num="5.0f"/><vers num="5.0a PK3_BL17"/><vers num="5.0a"/><vers num="5.0 PK4_BL18"/><vers num="5.0 PK4_BL17"/><vers num="5.0"/><vers num="5.1b PK1_BL1"/><vers num="5.1b"/><vers num="5.1a PK3_BL3"/><vers num="5.1a PK2_BL2"/><vers num="5.1a PK1_BL1"/><vers num="5.1a"/><vers num="5.1 PK6_BL20"/><vers num="5.1 PK5_BL19"/><vers num="5.1 PK4_BL18"/><vers num="5.1 PK3_BL17"/><vers num="5.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.01"/><vers num="10.20"/><vers num="10.24"/><vers num="11.04"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/></prod><prod name="Samba-TNG" vendor="Samba-TNG"><vers num="0.3"/><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0202" published="2004-04-15" seq="2003-0202" severity="Medium" type="CVE"><desc><descript source="cve">The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-279">metrics -- insecure temporary file creation</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11734">metrics tmpfile symlink attack</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7293">bid 7293</ref></refs><vuln_soft><prod name="Metrics" vendor="Brian Renaud"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0203" published="2003-04-11" seq="2003-0203" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2">moxftp arbitrary code execution poc/advisory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6921">bid 6921</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11399">moxftp FTP welcome banner buffer overflow</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-281">DSA-281</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2">20030223 moxftp arbitrary code execution poc/advisory</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8136">8136</ref><ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html">20030223 moxftp arbitrary code execution poc/advisory</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006156">1006156</ref></refs><vuln_soft><prod name="moxftp" vendor="moxftp"><vers num="2.2"/></prod><prod name="xftp" vendor="xftp"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0204" published="2003-05-05" seq="2003-0204" severity="High" type="CVE"><desc><descript source="cve">KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="KDE" url="http://www.kde.org/info/security/advisory-20030409-1.txt">PS/PDF file handling vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-284">kdegraphics -- insecure execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7318">bid 7318</ref><ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=56808">http://bugs.kde.org/show_bug.cgi?id=56808</ref><ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=53343">http://bugs.kde.org/show_bug.cgi?id=53343</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-293">DSA-293</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-296">DSA-296</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:049">MDKSA-2003:049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-002.html">RHSA-2003:002</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668">CLA-2003:668</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001557020141&amp;w=2">20030410 GLSA:  kde-3.x (200304-04)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012994719099&amp;w=2">20030411 GLSA:  kde-2.x (200304-05)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105034222521369&amp;w=2">20030414 GLSA:  kde-2.x (200304-05.1)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105017403010459&amp;w=2">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049">MDKSA-2003:049</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3a"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5a"/><vers num="3.0.5"/><vers num="3.1"/><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0205" published="2003-05-12" seq="2003-0205" severity="High" type="CVE"><desc><descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2">Security problems in gkrellm-newsticker</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7415">bid 7415</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-294">gkrellm-newsticker -- missing quoting, incomplete parser</ref></refs><vuln_soft><prod name="GKrellM Newsticker" vendor="GKrellM Newsticker"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0206" published="2003-05-12" seq="2003-0206" severity="Medium" type="CVE"><desc><descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2">Security problems in gkrellm-newsticker</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7414">bid 7414</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-294">gkrellm-newsticker -- missing quoting, incomplete parser</ref></refs><vuln_soft><prod name="GKrellM Newsticker" vendor="GKrellM Newsticker"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0207" published="2003-05-05" seq="2003-0207" severity="Low" type="CVE"><desc><descript source="cve">ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-286">gs-common -- insecure temporary file</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7337">bid 7337</ref></refs><vuln_soft><prod name="gs-common" vendor="gs-common"><vers num="0.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0208" published="2003-05-05" seq="2003-0208" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Securiteam.org" url="http://www.securiteam.com/securitynews/5XP0B0U9PE.html">Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref><ref adv="1" patch="1" source="Macromedia" url="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm">Privacy and Macromedia Flash Ad Tracking</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105033712615013&amp;w=2">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref></refs><vuln_soft><prod name="Flash" vendor="Macromedia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2003-0209" published="2003-05-05" seq="2003-0209" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/139129">Heap overflow in Snort </ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7178">bid 7178</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105043563016235&amp;w=2">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111217731583&amp;w=2">20030423 Snort &lt;=1.9.1 exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103586927007&amp;w=2">20030422 GLSA:  snort (200304-05)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2">20030428 GLSA:  snort (200304-06)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref><ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172790914107&amp;w=2">ESA-20030430-013</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:052">MDKSA-2003:052</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052">MDKSA-2003:052</ref></refs><vuln_soft><prod name="SmoothWall" vendor="SmoothWall"><vers num="2.0 Beta 4"/></prod><prod name="Snort" vendor="Sourcefire"><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5"/><vers num="1.8.6"/><vers num="1.8.7"/><vers num="1.9"/><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0210" published="2003-05-12" seq="2003-0210" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120066126196&amp;w=2">Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7413">bid 7413</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml">Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/697049">VU#697049</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105118056332344&amp;w=2">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref></refs><vuln_soft><prod name="Secure ACS" vendor="Cisco"><vers num="2.1"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="3.0.1"/><vers num="3.0"/><vers num="3.0.3"/><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0211" published="2003-05-05" seq="2003-0211" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Red Hat" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537">xinetd leaks memory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7382">bid 7382</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068673220605&amp;w=2">Xinetd 2.3.10 Memory Leaks</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-160.html">RHSA-2003:160</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:056">MDKSA-2003:056</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval657.html">OVAL657</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782">CLA-2003:782</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:657">oval:org.mitre.oval:def:657</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056">MDKSA-2003:056</ref></refs><vuln_soft><prod name="Xinetd" vendor="Xinetd"><vers num="2.3.0"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6"/><vers num="2.3.7"/><vers num="2.3.8"/><vers num="2.3.9"/><vers num="2.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0212" published="2003-05-12" seq="2003-0212" severity="High" type="CVE"><desc><descript source="cve">handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105059298502830&amp;w=2">Vulnerability in rinetd</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7377">bid 7377</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-289">rinetd -- incorrect memory resizing</ref></refs><vuln_soft><prod name="rinetd" vendor="rinetd"><vers num="0.61"/><vers num="0.52"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0213" published="2003-05-12" seq="2003-0213" severity="High" type="CVE"><desc><descript source="cve">ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/317995">PoPToP PPTP server remotely exploitable buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-295">pptpd -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7316">bid 7316</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068728421160&amp;w=2">Exploit for PoPToP PPTP server</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_029.html">SuSE-SA:2003:029</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/673993">VU#673993</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154539727967&amp;w=2">20030428 GLSA:  pptpd (200304-08)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319428">20030422 Re: Exploit for PoPToP PPTP server - Linux version</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=138437"></ref></refs><vuln_soft><prod name="PPTP Server" vendor="PoPToP"><vers num="1.0.1"/><vers num="1.1.2"/><vers num="1.1.3 2002-10-09"/><vers num="1.1.3"/><vers num="1.1.4b2"/><vers num="1.1.4b1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0214" published="2003-05-12" seq="2003-0214" severity="Medium" type="CVE"><desc><descript source="cve">run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-292">mime-support -- insecure temporary file creation</ref></refs><vuln_soft><prod name="mime-support" vendor="Debian"><vers num="3.9"/><vers num="3.10"/><vers num="3.11"/><vers num="3.12"/><vers num="3.13"/><vers num="3.14"/><vers num="3.15"/><vers num="3.16"/><vers num="3.17"/><vers num="3.18"/><vers num="3.19"/><vers num="3.20"/><vers num="3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0215" published="2003-05-12" seq="2003-0215" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120052725940&amp;w=2">SQL injection in BttlxeForum</ref><ref adv="1" source="Security Tracker" url="http://securitytracker.com/alerts/2003/Apr/1006632.html">bttlxeForum Input Validation Flaw in Login Process Lets Remote Users Gain Access Without Authenticating</ref><ref adv="1" patch="1" source="Battleaxe Software" url="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812">SQL injection attack allowing users to gain full control over the forum software</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7416">bid 7416</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006632">1006632</ref></refs><vuln_soft><prod name="bttlxeForum" vendor="Battleaxe Software"><vers num="2.0 beta 3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2003-0216" published="2003-05-12" seq="2003-0216" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml">Cisco Catalyst Enable Password Bypass Vulnerability</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml.">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443257">VU#443257</ref></refs><vuln_soft><prod name="Catalyst 6500" vendor="Cisco"><vers num="7.5 (1)"/></prod><prod name="Catalyst 4000" vendor="Cisco"><vers num="7.5 (1)"/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num="7.5 (1)"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0217" published="2003-06-16" seq="2003-0217" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283833617480&amp;w=2">XSS In Neoteris IVE Allows Session Hijacking</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7510">bid 7510</ref></refs><vuln_soft><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0218" published="2003-05-12" seq="2003-0218" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154473526898&amp;w=2">GLSA: monkeyd (200304-07.1)</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html">Monkey HTTPd Remote Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7202">bid 7202</ref><ref source="CONFIRM" url="http://monkeyd.sourceforge.net/Changelog.txt">http://monkeyd.sourceforge.net/Changelog.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105094204204166&amp;w=2">20030420 Monkey HTTPd Remote Buffer Overflow</ref></refs><vuln_soft><prod name="Monkey HTTP Daemon" vendor="Monkey"><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.6"/><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0219" published="2003-05-12" seq="2003-0219" severity="High" type="CVE"><desc><descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10"> Vulnerabilities in Kerio Personal Firewall</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641012">VU#641012</ref><ref source="BID" url="http://www.securityfocus.com/bid/7179">7179</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref></refs><vuln_soft><prod name="Personal Firewall 2" vendor="Kerio"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0220" published="2003-05-12" seq="2003-0220" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10">Vulnerabilities in Kerio Personal Firewall</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/454716">VU#454716</ref><ref source="BID" url="http://www.securityfocus.com/bid/7180">7180</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref></refs><vuln_soft><prod name="Personal Firewall 2" vendor="Kerio"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0221" published="2003-05-12" seq="2003-0221" severity="High" type="CVE"><desc><descript source="cve">The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="HP" url="http://www.ciac.org/ciac/bulletins/n-086.shtml">SSRT3471</ref><ref source="BID" url="http://www.securityfocus.com/bid/7452">7452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11892">tru64-dupatch-setld-symlink(11892)</ref></refs><vuln_soft><prod name="Tru64 UNIX" vendor="HP"><vers num="5.1B PK1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0222" published="2003-05-12" seq="2003-0222" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a &quot;CREATE DATABASE LINK&quot; query containing a connect string with a long USING parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Oracle" url="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf">Buffer Overflow in Oracle Net Services for Oracle Database Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7453">bid 7453</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105163376015735&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-085.shtml">N-085</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11885">oracle-database-link-bo(11885)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105162831008176&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.0x"/><vers num="8.0.6.3"/><vers num="8.0.6"/><vers num="8.1x"/><vers num="8.1.5"/><vers num="8.1.6"/><vers num="8.1.7.4"/><vers num="8.1.7.1"/><vers num="8.1.7"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="9.0"/><vers num="9.0.1.4"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0.2"/><vers num="9.2.0.2"/><vers num="9.2.0.1"/></prod><prod name="Oracle7" vendor="Oracle"><vers num="7.3.3"/><vers num="7.3.4"/></prod><prod name="Oracle9i Release 2" vendor="Oracle"><vers num="9.2.2"/><vers num="9.2.1"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.0.1"/><vers num="8.0.2"/><vers num="8.0.3"/><vers num="8.0.4"/><vers num="8.0.5.1"/><vers num="8.0.5"/><vers num="8.0.6"/><vers num="8.1.5"/><vers num="8.1.6"/><vers num="8.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2003-0223" published="2003-06-09" seq="2003-0223" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp">MS03-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval66.html">OVAL66</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:66">oval:org.mitre.oval:def:66</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0224" published="2003-06-09" seq="2003-0224" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka &quot;Server Side Include Web Pages Buffer Overrun.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp">MS03-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval483.html">OVAL483</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105431767100944&amp;w=2">20030530 NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:483">oval:org.mitre.oval:def:483</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0225" published="2003-06-09" seq="2003-0225" severity="Medium" type="CVE"><desc><descript source="cve">The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp">MS03-018</ref><ref source="MISC" url="http://www.aqtronix.com/Advisories/AQ-2003-01.txt">http://www.aqtronix.com/Advisories/AQ-2003-01.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval373.html">OVAL373</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105110606122772&amp;w=2">20030418 Microsoft Active Server Pages DoS</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:373">oval:org.mitre.oval:def:373</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0226" published="2003-06-09" seq="2003-0226" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html">20030528 Internet Information Services 5.0 Denial of service</ref><ref adv="1" patch="1" source="Spidynamics" url="http://www.spidynamics.com/iis_alert.html"></ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp">MS03-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval933.html">OVAL933</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421243732552&amp;w=2">20030528 Internet Information Services 5.0 Denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427362724860&amp;w=2">20030529 IIS WEBDAV Denial of Service attacks</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:933">oval:org.mitre.oval:def:933</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0227" published="2003-06-09" seq="2003-0227" severity="Medium" type="CVE"><desc><descript source="cve">The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-019.asp">MS03-019</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval936.html">OVAL936</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval966.html">OVAL966</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421176432011&amp;w=2">20030528 MS03-019: DoS or Code of Choice</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421127531558&amp;w=2">20030528 Re: Alert: MS03-019, Microsoft... wrong, again.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427615626177&amp;w=2">20030528 RE: Alert: MS03-019, Microsoft... wrong, again.</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:936">oval:org.mitre.oval:def:936</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:966">oval:org.mitre.oval:def:966</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0228" published="2003-05-27" seq="2003-0228" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232913516488&amp;w=2">Windows Media Player directory traversal vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-017.asp">Flaw in Windows Media Player Skins Downloading could allow Code Execution (817787)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7517">bid 7517</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval321.html">OVAL321</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/384932">VU#384932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11953">mediaplayer-skin-code-execution(11953)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233960728901&amp;w=2">20030507 Windows Media Player directory traversal vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240528419389&amp;w=2">20030508 why i love xs4all + mediaplayer thingie</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:321">oval:org.mitre.oval:def:321</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="XP"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2003-0230" published="2003-08-27" seq="2003-0230" severity="High" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the &quot;Named Pipe Hijacking&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8276">BID: 8276</ref><ref patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp">MS03-031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval235.html">OVAL235</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/556356">VU#556356</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:235">oval:org.mitre.oval:def:235</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="2000 SP3a"/><vers num="2000 SP3"/><vers num="2000 SP2"/><vers num="2000 SP1"/><vers num="2000"/><vers edition="Desktop Engine" num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2003-0231" published="2003-08-27" seq="2003-0231" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8274">BID: 8274</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a072303-2.txt">A072303-2</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp">MS03-031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval299.html">OVAL299</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/918652">VU#918652</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:299">oval:org.mitre.oval:def:299</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="2000 SP3a"/><vers num="2000 SP3"/><vers num="2000 SP2"/><vers num="2000 SP1"/><vers num="2000"/><vers edition="Desktop Engine" num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2003-0232" published="2003-08-27" seq="2003-0232" severity="High" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/8275">BID: 8275</ref><ref adv="1" patch="1" source="Atstake" url="http://www.atstake.com/research/advisories/2003/a072303-3.txt">A072303-3</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp">MS03-031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval303.html">OVAL303</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/584868">VU#584868</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:303">oval:org.mitre.oval:def:303</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="2000 SP3a"/><vers num="2000 SP3"/><vers num="2000 SP2"/><vers num="2000 SP1"/><vers num="2000"/><vers edition="Desktop Engine" num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2003-0233" published="2003-05-12" seq="2003-0233" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120164927952&amp;w=2">Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp">Cumulative Patch for Internet Explorer (813489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7420">bid 7420</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/11854.php">Microsoft Internet Explorer plug-in.ocx Load method buffer overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1094.html">OVAL1094</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1094">oval:org.mitre.oval:def:1094</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0235" published="2003-05-27" seq="2003-0235" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10">Multiple Vulnerabilities in Mirabilis ICQ Pro 2003a client</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7461">bid 7461</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11938">icq-pop3-format-string(11938)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/><vers num="2000.0A"/><vers num="2001b Build3659"/><vers num="2001b Build3638"/><vers num="2001b Build3636"/><vers num="2001a"/><vers num="2002a Build3727"/><vers num="2002a Build3722"/><vers num="2003a Build3800"/><vers num="2003a Build3799"/><vers num="2003a Build3777"/><vers num="99a 2.15Build1701"/><vers num="99a 2.21Build1800"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0236" published="2003-05-27" seq="2003-0236" severity="High" type="CVE"><desc><descript source="cve">Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10">Multiple Vulnerabilities in Mirabilis ICQ Pro 2003a client</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7462">bid 7462</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7463">bid 7463</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11939">icq-pop3-email-bo(11939)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/><vers num="2000.0A"/><vers num="2001b Build3659"/><vers num="2001b Build3638"/><vers num="2001b Build3636"/><vers num="2001a"/><vers num="2002a Build3727"/><vers num="2002a Build3722"/><vers num="2003a Build3800"/><vers num="2003a Build3799"/><vers num="2003a Build3777"/><vers num="99a 2.15Build1701"/><vers num="99a 2.21Build1800"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0237" published="2003-05-27" seq="2003-0237" severity="High" type="CVE"><desc><descript source="cve">The &quot;ICQ Features on Demand&quot; functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10">Multiple Vulnerabilities in Mirabilis ICQ Pro 2003a client</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7464">bid 7464</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11944">icq-features-no-auth(11944)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/><vers num="2000.0A"/><vers num="2001b Build3659"/><vers num="2001b Build3638"/><vers num="2001b Build3636"/><vers num="2001a"/><vers num="2002a Build3727"/><vers num="2002a Build3722"/><vers num="2003a Build3800"/><vers num="2003a Build3799"/><vers num="2003a Build3777"/><vers num="99a 2.15Build1701"/><vers num="99a 2.21Build1800"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0238" published="2003-05-27" seq="2003-0238" severity="Medium" type="CVE"><desc><descript source="cve">The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10">Multiple Vulnerabilities in Mirabilis ICQ Pro 2003a client</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7465">bid 7465</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11947">icq-table-tag-dos(11947)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/><vers num="2000.0A"/><vers num="2001b Build3659"/><vers num="2001b Build3638"/><vers num="2001b Build3636"/><vers num="2001a"/><vers num="2002a Build3727"/><vers num="2002a Build3722"/><vers num="2003a Build3800"/><vers num="2003a Build3799"/><vers num="2003a Build3777"/><vers num="99a 2.15Build1701"/><vers num="99a 2.21Build1800"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0239" published="2003-05-27" seq="2003-0239" severity="Medium" type="CVE"><desc><descript source="cve">icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Core Security" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10">Multiple Vulnerabilities in Mirabilis ICQ Pro 2003a client</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7466">bid 7466</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11948">icq-gif89a-header-dos(11948)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/><vers num="2000.0A"/><vers num="2001b Build3659"/><vers num="2001b Build3638"/><vers num="2001b Build3636"/><vers num="2001a"/><vers num="2002a Build3727"/><vers num="2002a Build3722"/><vers num="2003a Build3800"/><vers num="2003a Build3799"/><vers num="2003a Build3777"/><vers num="99a 2.15Build1701"/><vers num="99a 2.21Build1800"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0240" published="2003-06-09" seq="2003-0240" severity="High" type="CVE"><desc><descript source="cve">The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/799060">VU#799060</ref><ref source="BID" url="http://www.securityfocus.com/bid/7652">7652</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006854">1006854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8876">8876</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12104">axis-admin-authentication-bypass(12104)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406374731579&amp;w=2">20030527 CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10"></ref><ref source="OSVDB" url="http://www.osvdb.org/4804">4804</ref></refs><vuln_soft><prod name="AXIS 2110 Network Camera" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 2400 Video Server" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 2130 PTZ Network Camera" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 2460 Network DVR" vendor="Axis Communications"><vers num="3.00" prev="1"/></prod><prod name="AXIS 2420 Network Camera" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 2100 Network Camera" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 2120 Network Camera" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod><prod name="AXIS 250S Video Server" vendor="Axis Communications"><vers num="3.02" prev="1"/></prod><prod name="AXIS 2401 Video Server" vendor="Axis Communications"><vers num="2.32" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0241" published="2003-06-09" seq="2003-0241" severity="High" type="CVE"><desc><descript source="cve">FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0091.html">20030528 SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm)</ref><ref adv="1" patch="1" source="SECNAP" url="http://www.secnap.net/security/gm001.html"></ref></refs><vuln_soft><prod name="GoldMine" vendor="FrontRange"><vers num="5.70"/><vers num="6.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0242" published="2003-06-09" seq="2003-0242" severity="High" type="CVE"><desc><descript source="cve">IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869548">VU#869548</ref><ref source="BID" url="http://www.securityfocus.com/bid/7628">7628</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006796">1006796</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8798">8798</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12027">macos-ipsec-acl-bypass(12027)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0243" published="2003-05-27" seq="2003-0243" severity="High" type="CVE"><desc><descript source="cve">Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Tracker" url="http://securitytracker.com/alerts/2003/May/1006707.html">Happymall E-Commerce Input Validation Flaw Lets Remote Users Execute Arbitrary Commands</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7530">bid 7530</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7529">bid 7529</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0058.html">20030507 Happymall E-Commerce Remote Command Execution</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006707">1006707</ref></refs><vuln_soft><prod name="HappyMall" vendor="HappyCGI"><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0244" published="2003-05-27" seq="2003-0244" severity="Medium" type="CVE"><desc><descript source="cve">The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-145.html">Updated kernel fixes security vulnerabilities and updates drivers</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-311">DSA-311-1 linux-kernel-2.4.18 -- several vulnerabilitiesDate Reported:</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html">20030517 Algorithmic Complexity Attacks and the Linux Networking Code</ref><ref source="MISC" url="http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html">http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-147.html">RHSA-2003:147</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-172.html">RHSA-2003:172</ref><ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105595901923063&amp;w=2">20030618 [slackware-security]  2.4.21 kernels available (SSA:2003-168-01)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval261.html">OVAL261</ref><ref source="BID" url="http://www.securityfocus.com/bid/7601">7601</ref><ref source="SECUNIA" url="http://www.secunia.com/advisories/8786/">8786</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15382">data-algorithmic-complexity-dos(15382)</ref><ref source="" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=104956079213417"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:261">oval:org.mitre.oval:def:261</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0245" published="2003-06-09" seq="2003-0245" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Apache" url="http://www.apache.org/dist/httpd/Announcement2.html"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-186.html">RHSA-2003:186</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/757612">Apache Portable Runtime contains heap buffer overflow in apr_psprintf()</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/12090">Apache HTTP Server apr_psprintf code execution</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html">20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability</ref><ref source="MISC" url="http://www.idefense.com/advisory/05.30.03.txt">http://www.idefense.com/advisory/05.30.03.txt </ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:063">MDKSA-2003:063</ref><ref source="BID" url="http://www.securityfocus.com/bid/7723">7723</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661">CLA-2003:661</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:063">MDKSA-2003:063</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0246" published="2003-06-16" seq="2003-0246" severity="Low" type="CVE"><desc><descript source="cve">The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-172.html">RHSA-2003:172</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7600">bid 7600</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-311">DSA-311-1 linux-kernel-2.4.18 -- several vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-147.html">RHSA-2003:147</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html">20030520 Linux 2.4 kernel ioperm vuln</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval278.html">OVAL278</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:278">oval:org.mitre.oval:def:278</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.5 .0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="2.5.5"/><vers num="2.5.6"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0247" published="2003-06-16" seq="2003-0247" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service (&quot;kernel oops&quot;).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-187.html">Updated 2.4 kernel fixes vulnerabilities and driver bugs</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-311">DSA-311-1 linux-kernel-2.4.18 -- several vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-195.html">RHSA-2003:195</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval284.html">OVAL284</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:284">oval:org.mitre.oval:def:284</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0248" published="2003-06-16" seq="2003-0248" severity="High" type="CVE"><desc><descript source="cve">The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval292.html">OVAL292</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:292">oval:org.mitre.oval:def:292</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref><ref adv="1" patch="1" source="Red Hat Linux" url="http://www.redhat.com/support/errata/RHSA-2003-187.html">Updated 2.4 kernel fixes vulnerabilities and driver bugs</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-311">Debian Security Advisory DSA-311-1 linux-kernel-2.4.18 -- several</ref><ref adv="1" patch="1" source="Mandrakesoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:066">Updated kernel packages fix multiple vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-195.html">RHSA-2003:195</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2003-0249" published="2003-12-31" seq="2003-0249" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP treats unknown methods such as &quot;PoSt&quot; as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive.  NOTE: this issue has been disputed by the Apache security team, saying &quot;It is by design that PHP allows scripts to process any request method.  A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods.  It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=97">20030625 PHP/Apache .htaccess Authentication Bypass Vulnerability</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0251" published="2003-07-24" seq="2003-0251" severity="Medium" type="CVE"><desc><descript source="cve">ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-173.html">RHSA-2003:173</ref><ref source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:072">MDKSA-2003:072</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:072">MDKSA-2003:072</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55600&amp;zone_32=category%3Asecurity">55600</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-43.txt">TLSA-2003-43</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval667.html">OVAL667</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/440454/100/0/threaded">HPSBTU02132</ref><ref source="BID" url="http://www.securityfocus.com/bid/8031">8031</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2873">ADV-2006-2873</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016517">1016517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21112">21112</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-201.html">RHSA-2003:201</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:667">oval:org.mitre.oval:def:667</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:072">MDKSA-2003:072</ref></refs><vuln_soft><prod name="ypserv NIS server" vendor="NIS"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0252" published="2003-08-18" seq="2003-0252" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820223707191&amp;w=2">20030714 Linux nfs-utils xlog() off-by-one bug</ref><ref adv="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html">20030714 Linux nfs-utils xlog() off-by-one bug</ref><ref adv="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html">20030714 Reality of the rpc.mountd bug</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830921519513&amp;w=2">20030715 [slackware-security] nfs-utils packages replaced (SSA:2003-195-01b)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839032403325&amp;w=2">20030716 Immunix Secured OS 7+ nfs-utils update -- bugtraq</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt">http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-349">DSA-349</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-206.html">RHSA-2003:206</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-207.html">RHSA-2003:207</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.html">SuSE-SA:2003:031</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:076">MDKSA-2003:076</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-44.txt">TLSA-2003-44</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval443.html">OVAL443</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258564">VU#258564</ref><ref source="BID" url="http://www.securityfocus.com/bid/8179">8179</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1007187">1007187</ref><ref source="SECUNIA" url="http://secunia.com/advisories/9259">9259</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12600">nfs-utils-offbyone-bo(12600)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:443">oval:org.mitre.oval:def:443</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:076">MDKSA-2003:076</ref></refs><vuln_soft><prod name="nfs-utils" vendor="nfs"><vers num="0.2"/><vers num="0.2.1"/><vers num="0.3.1"/><vers num="0.3.3"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0253" published="2003-08-18" seq="2003-0253" severity="Medium" type="CVE"><desc><descript source="cve">The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-240.html">Updated httpd packages fix Apache security vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval173.html">OVAL173</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:173">oval:org.mitre.oval:def:173</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0254" published="2003-08-18" seq="2003-0254" severity="Medium" type="CVE"><desc><descript source="cve">Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-240.html">Updated httpd packages fix Apache security vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval183.html">OVAL183</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:183">oval:org.mitre.oval:def:183</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0255" published="2003-05-27" seq="2003-0255" severity="High" type="CVE"><desc><descript source="cve">The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105215110111174&amp;w=2">Key validity bug in GnuPG 1.2.1 and earlier</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-175.html">Updated gnupg packages fix validation bug</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-176.html">RHSA-2003:176</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:061">MDKSA-2003:061</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval135.html">OVAL135</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/397604">VU#397604</ref><ref source="BID" url="http://www.securityfocus.com/bid/7497">7497</ref><ref source="OSVDB" url="http://www.osvdb.org/4947">4947</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11930">gnupg-invalid-key-acceptance(11930)</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-34.txt">TLSA200334</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000694">CLA-2003:694</ref><ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301357425157&amp;w=2">ESA-20030515-016</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311804129104&amp;w=2">20030516 [OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362224514081&amp;w=2">20030522 [slackware-security]  GnuPG key validation fix (SSA:2003-141-04)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:135">oval:org.mitre.oval:def:135</ref><ref source="" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html"></ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html">20030515-016</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:061">MDKSA-2003:061</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="Gnu"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0256" published="2003-05-27" seq="2003-0256" severity="High" type="CVE"><desc><descript source="cve">The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mandrake Secure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:055">kopete</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7536">bid 7536</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:055">MDKSA-2003:055</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000665">CLA-2003:665</ref><ref source="" url="http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:055">MDKSA-2003:055</ref></refs><vuln_soft><prod name="kopete" vendor="KDE"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0257" published="2004-04-15" seq="2003-0257" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1">Printer commands format string vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/12000">IBM AIX print utilities format string attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7604">bid 7604</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0258" published="2003-05-27" seq="2003-0258" severity="High" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml">Cisco VPN 3000 Concentrator Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7516">bid 7516</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/727780">VU#727780</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11954">cisco-vpn-unauth-access(11954)</ref></refs><vuln_soft><prod name="VPN 3060 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3000 Concentrator" vendor="Cisco"><vers num="3.5 (Rel)"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.6"/><vers num="3.6.1"/><vers num="3.6.7D"/><vers num="4.0"/></prod><prod name="VPN 3005 Concentrator" vendor="Cisco"><vers num="3.6.3"/><vers num="3.6.5"/><vers num="3.6.7D"/><vers num="3.6.7C"/><vers num="3.6.7B"/><vers num="3.6.7A"/><vers num="3.6.7"/><vers num="4.0"/><vers num="4.0.1"/></prod><prod name="VPN 3002 Hardware Client" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3015 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3030 Concentator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3080 Concentrator" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0259" published="2003-05-27" seq="2003-0259" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml">Cisco, VPN 3000 Concentrator, Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7522">bid 7522</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/317348">VU#317348</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11955">cisco-vpn-ssh-dos(11955)</ref></refs><vuln_soft><prod name="VPN 3060 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3000 Concentrator" vendor="Cisco"><vers num="2.0"/><vers num="2.5.2(F)"/><vers num="2.5.2(D)"/><vers num="2.5.2(C)"/><vers num="2.5.2(B)"/><vers num="2.5.2(A)"/><vers num="3.0"/><vers num="3.0.3(B)"/><vers num="3.0.3(A)"/><vers num="3.0.4"/><vers num="3.1(Rel)"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.4"/><vers num="3.5(Rel)"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.6"/><vers num="3.6.1"/><vers num="3.6.7D"/><vers num="3.6.7"/></prod><prod name="VPN 3005 Concentrator" vendor="Cisco"><vers num="3.6.3"/><vers num="3.6.5"/><vers num="3.6.7D"/><vers num="3.6.7C"/><vers num="3.6.7B"/><vers num="3.6.7A"/><vers num="3.6.7"/></prod><prod name="VPN 3002 Hardware Client" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3015 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3030 Concentator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3080 Concentrator" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0260" published="2003-05-27" seq="2003-0260" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml">Cisco VPN 3000 Concentrator Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7523">bid 7523</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/221164">VU#221164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11956">cisco-vpn-icmp-dos(11956)</ref></refs><vuln_soft><prod name="VPN 3060 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3000 Concentrator" vendor="Cisco"><vers num="2.0"/><vers num="2.5.2(F)"/><vers num="2.5.2(D)"/><vers num="2.5.2(C)"/><vers num="2.5.2(B)"/><vers num="2.5.2(A)"/><vers num="3.0"/><vers num="3.0.3(B)"/><vers num="3.0.3(A)"/><vers num="3.0.4"/><vers num="3.1(Rel)"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.4"/><vers num="3.5(Rel)"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.6"/><vers num="3.6.1"/><vers num="3.6.7"/></prod><prod name="VPN 3005 Concentrator" vendor="Cisco"><vers num="3.6.3"/><vers num="3.6.5"/><vers num="3.6.7"/></prod><prod name="VPN 3002 Hardware Client" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3015 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3030 Concentator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3080 Concentrator" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0261" published="2003-05-27" seq="2003-0261" severity="Medium" type="CVE"><desc><descript source="cve">fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-302">fuzz -- privilege escalation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7521">bid 7521</ref></refs><vuln_soft><prod name="Fuzz" vendor="Fuzz"><vers num="0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0262" published="2003-05-27" seq="2003-0262" severity="High" type="CVE"><desc><descript source="cve">leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2003/dsa-299">leksbot -- improper setuid-root execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/7505">7505</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11945">kataxwr-gain-privileges(11945)</ref></refs><vuln_soft><prod name="Leksbot" vendor="Leksbot"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0263" published="2003-05-27" seq="2003-0263" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223471822836&amp;w=2">Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7506">bid 7506</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7508">bid 7508</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0052.html">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11951">ftgate-mailfrom-rcptto-bo(11951)</ref></refs><vuln_soft><prod name="FTGatePro" vendor="Floosietek"><vers num="1.22_1328"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2003-0264" published="2003-05-27" seq="2003-0264" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/slmail-vulns.txt">Multiple Buffer Overflows in SLMail</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232506011335&amp;w=2">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233360321895&amp;w=2">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref></refs><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="5.1.0.4420"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0265" published="2003-05-27" seq="2003-0265" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7421">bid 7421</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232424810097&amp;w=2">20030507 SAP database local root vulnerability during installation. (fwd)</ref></refs><vuln_soft><prod name="SAP DB" vendor="Sap"><vers num="7.3.29"/><vers num="7.4.3.7 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0266" published="2003-05-27" seq="2003-0266" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt">Multiple Vulnerabilities in SLWebMail</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref></refs><vuln_soft><prod name="SLWebMail" vendor="BVRP Software"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0267" published="2003-05-27" seq="2003-0267" severity="Medium" type="CVE"><desc><descript source="cve">ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7513">bid 7513</ref><ref adv="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt">Multiple Vulnerabilities in SLWebMail</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref></refs><vuln_soft><prod name="SLWebMail" vendor="BVRP Software"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0268" published="2003-05-27" seq="2003-0268" severity="Medium" type="CVE"><desc><descript source="cve">SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt">Multiple Vulnerabilities in SLWebMail</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref></refs><vuln_soft><prod name="SLWebMail" vendor="BVRP Software"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0269" published="2003-05-27" seq="2003-0269" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2003-May/009570.html">youbin local root exploit + advisory</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7503">bid 7503</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0053.html">20030506 youbin local root exploit + advisory</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004892.html">20030506 youbin local root exploit + advisory</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11949">youbin-home-bo(11949)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223947528794&amp;w=2">20030506 youbin local root exploit + advisory</ref></refs><vuln_soft><prod name="youbin" vendor="youbin"><vers num="2.5"/><vers num="3.0"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0270" published="2003-06-16" seq="2003-0270" severity="High" type="CVE"><desc><descript source="cve">The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2003/a051203-1.txt">A051203-1</ref><ref adv="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/7554">bid 7554</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1006742">1006742</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8773">8773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11980">airport-auth-credentials-disclosure(11980)</ref></refs><vuln_soft><prod name="AirPort Base Station" vendor="Apple"><vers num="802.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0271" published="2003-05-27" seq="2003-0271" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/316958">Personal FTP Server</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240469318622&amp;w=2">Remote Stack Overflow exploit for Personal FTPD</ref><ref source="MISC" url="http://security.nnov.ru/search/document.asp?docid=4309">http://security.nnov.ru/search/document.asp?docid=4309</ref></refs><vuln_soft><prod name="Personal FTP Server" vendor="Cooolsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0272" published="2003-05-27" seq="2003-0272" severity="High" type="CVE"><desc><descript source="cve">admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an &quot;adminok&quot; value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240907024660&amp;w=2">miniPortail (PHP) : Admin Access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7532">bid 7532</ref><ref source="MISC" url="http://www.frog-man.org/tutos/miniPortail.txt">http://www.frog-man.org/tutos/miniPortail.txt</ref></refs><vuln_soft><prod name="MiniPortal" vendor="MiniPortal"><vers num="1.9"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0273" published="2003-05-27" seq="2003-0273" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Fsck.com" url="http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html">w: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7509">bid 7509</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240947225275&amp;w=2">20030508 Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</ref></refs><vuln_soft><prod name="Request Tracker" vendor="Best Practical Solutions"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0274" published="2003-05-27" seq="2003-0274" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105241224228693&amp;w=2">ListProc mailing list ULISTPROC_UMASK overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7533">bid 7533</ref></refs><vuln_soft><prod name="ListProc" vendor="CREN"><vers num="8.2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0275" published="2003-06-16" seq="2003-0275" severity="Medium" type="CVE"><desc><descript source="cve">SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105249980809988&amp;w=2">20030509 II-Labs Advisory: Remote code execution in YaBBse 1.5.2 (php version)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2003-0276" published="2003-06-16" seq="2003-0276" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155818012718&amp;w=2">Pi3Web 2.0.1 DoS</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105275789410250&amp;w=2">Unix Version of the Pi3web DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/7555">7555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11889">pi3web-get-request-bo(11889)</ref></refs><vuln_soft><prod name="Pi3Web" vendor="Pi3"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0277" published="2003-06-16" seq="2003-0277" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/7559">7559</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11987">happymall-dotdot-directory-traversal(11987)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2">20030512 One more flaw in Happymall</ref></refs><vuln_soft><prod name="HappyMall" vendor="HappyCGI"><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0278" published="2003-06-16" seq="2003-0278" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2">One more flaw in Happymall</ref><ref source="BID" url="http://www.securityfocus.com/bid/7557">7557</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11988">happymall-normalhtml-xss(11988)</ref></refs><vuln_soft><prod name="Happymall" vendor="Happycgi.com"><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2003-0279" published="2003-06-16" seq="2003-0279" severity="Low" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/><race/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276019312980&amp;w=2">Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref><ref source="BID" url="http://www.securityfocus.com/bid/7558">7558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11984">phpnuke-web-sql-injection(11984)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref><ref source="BID" url="http://www.securityfocus.com/bid/7588">7588</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0280" published="2003-06-16" seq="2003-0280" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105258772101349&amp;w=2">Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/7547">7547</ref><ref source="BID" url="http://www.securityfocus.com/bid/7548">7548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11975">cmailserver-smtp-bo(11975)</ref></refs><vuln_soft><prod name="CMailServer" vendor="Youngzsoft"><vers num="4.0.2003.23.27"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0281" published="2003-06-16" seq="2003-0281" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259012802997&amp;w=2">Firebird Local exploit</ref><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2002/Jun/0212.html">20020617 Interbase 6.0 malloc() issues</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-18.xml">GLSA-200405-18</ref><ref source="BID" url="http://www.securityfocus.com/bid/7546">7546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8758">8758</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11977">firebird-interbase-bo(11977)</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2003-0282" published="2003-06-16" seq="2003-0282" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a &quot;..&quot; sequence.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259038503175&amp;w=2">unzip directory traversal revisited</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7550">Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2003-199.html">Updated unzip packages fix trojan vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-200.html">RHSA-2003:200</ref><ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01">IMNX-2003-7+-017-01</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:073">MDKSA-2003:073</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-344">DSA-344</ref><ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-42.txt">TLSA-2003-42</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt">CSSA-2003-031.0</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval619.html">OVAL619</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-111.shtml">N-111</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12004">unzip-dotdot-directory-traversal(12004)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000672">CLA-2003:672</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105786446329347&amp;w=2">20030710 [OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:619">oval:org.mitre.oval:def:619</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:073">MDKSA-2003:073</ref></refs><vuln_soft><prod name="OpenLinux Server" vendor="SCO"><vers num="3.1.1"/></prod><prod name="UnZip" vendor="Info-Zip"><vers num="5.50"/></prod><prod name="OpenLinux Workstation" vendor="SCO"><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2003-0283" published="2003-06-16" seq="2003-0283" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a &quot;&lt;&lt;&quot; before a tag name in the (1) subject, (2) author&apos;s name, or (3) author&apos;s e-mail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251421925394&amp;w=2">20030509 Re: A Phorum&apos;s bug...</ref><ref source="BID" url="http://www.securityfocus.com/bid/7545">7545</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11974">phorum-message-html-injection(11974)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251043821533&amp;w=2">20030509 A Phorum&apos;s bug...</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10