<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0001" published="2004-02-17" seq="2004-0001" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868">oval:org.mitre.oval:def:868</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-017.html">Updated kernel packages available for Red Hat Enterprise Linux 3 Update 1</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9429">bid 9429</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14888">Linux kernel ptrace allows elevated privileges</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/337238">Red Hat Enterprise Linux kernel-2.4.21 does not perform adequate checking of eflags when in 32-bit ptrace emulation mode</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200402-06.xml">GLSA-200402-06</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2004-0002" published="2004-03-03" seq="2004-0002" severity="High" type="CVE"><desc><descript source="cve">The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html">cvs commit: src/sys/netinet ip_icmp.c tcp.h tcp_input.c tcp_subr.c tcp_usrreq.c tcp_var.h</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9572">bid 9572</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.0 Releng"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="5.1 Releng"/><vers num="5.1 p5 Release"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0003" published="2004-03-03" seq="2004-0003" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to &quot;R128 DRI limits checking.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Linuxcompatible.org" url="http://www.linuxcompatible.org/print25630.html">Updated Fedora Core 1 testing kernel</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-044.html">Updated kernel packages resolve minor security vulnerabilities</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_05_linux_kernel.html">SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:005)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1017.html">OVAL1017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval834.html">OVAL834</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-126.shtml">O-126</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-145.shtml">O-145</ref><ref source="BID" url="http://www.securityfocus.com/bid/9570">9570</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10782">10782</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10911">10911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10912">10912</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11202">11202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11361">11361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11369">11369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11370">11370</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11376">11376</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12075">12075</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15029">linux-r128-gain-priviliges(15029)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017">oval:org.mitre.oval:def:1017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834">oval:org.mitre.oval:def:834</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.22" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0004" published="2004-02-17" seq="2004-0004" severity="High" type="CVE"><desc><descript source="cve">The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer&apos;s certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate&apos;s chain is trusted by OpenCA&apos;s chain directory, allowing remote attackers to spoof requests from other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Openca.org" url="http://www.openca.org/news/CAN-2004-0004.txt">OpenCA Security Advisory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9435">bid 9435</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2">20040116 [OpenCA Advisory] Vulnerability in signature verification</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/336446">VU#336446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14847">openca-improper-signature-verification(14847)</ref><ref source="OSVDB" url="http://www.osvdb.org/3615">3615</ref></refs><vuln_soft><prod name="OpenCA" vendor="OpenCA"><vers num="0.9.1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0005" published="2004-03-03" seq="2004-0005" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">Advisory 01/2004: 12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-434">DSA-434-1 gaim -- several vulnerabilities</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190366">VU#190366</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/226974">VU#226974</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/404470">VU#404470</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/655974">VU#655974</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="GENTOO" url="http://www.linuxsecurity.com/content/view/105690/104/">GLSA-200401-04</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14942">gaim-mime-decoder-bo(14942)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14944">gaim-mime-decoder-oob(14944)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14935">gaim-yahoodecode-offbyone-bo(14935)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14938">gaim-sscanf-oob(14938)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref source="OSVDB" url="http://www.osvdb.org/3736">3736</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.75"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0006" published="2004-03-03" seq="2004-0006" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">Gentoo Linux Security Advisory</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval818.html">OVAL818</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/297198">VU#297198</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/371382">VU#371382</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/444158">VU#444158</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/503030">VU#503030</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527142">VU#527142</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/871838">VU#871838</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14947">gaim-http-proxy-bo(14947)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14940">gaim-login-name-bo(14940)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14941">gaim-login-value-bo(14941)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14945">gaim-urlparser-bo(14945)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14943">gaim-yahoopacketread-keyname-bo(14943)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14939">gaim-yahoowebpending-cookie-bo(14939)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818">oval:org.mitre.oval:def:818</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="OSVDB" url="http://www.osvdb.org/3731">3731</ref><ref source="OSVDB" url="http://www.osvdb.org/3732">3732</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.75" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0007" published="2004-03-03" seq="2004-0007" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-434">DSA-434-1 gaim -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">RHSA-2004:032</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref><ref source="CERT-VN" url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0007">VU#197142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval819.html">OVAL819</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="SUSE" url="http://www.securityfocus.com/advisories/6281">SuSE-SA:2004:004</ref><ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14946">gaim-extractinfo-bo(14946)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/197142">VU#197142</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819">oval:org.mitre.oval:def:819</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="OSVDB" url="http://www.osvdb.org/3733">3733</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.74" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0008" published="2004-03-03" seq="2004-0008" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval820.html">OVAL820</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14937">gaim-directim-bo(14937)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820">oval:org.mitre.oval:def:820</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="OSVDB" url="http://www.osvdb.org/3734">3734</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/779614">Gaim contains an integer overflow vulnerability when parsing DirectIM packets</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.74" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0009" published="2004-03-03" seq="2004-0009" severity="High" type="CVE"><desc><descript source="cve">Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the &quot;one-line DN&quot; of the target user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apache-ssl.org/advisory-20040206.txt">http://www.apache-ssl.org/advisory-20040206.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2">Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9590">bid 9590</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15065">Apache-SSL has a default password</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref><ref source="OSVDB" url="http://www.osvdb.org/3877">3877</ref></refs><vuln_soft><prod name="Apache-SSL" vendor="Apache-SSL"><vers num="1.3.28_1.52" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0010" published="2004-03-03" seq="2004-0010" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">Updated kernel packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9691">bid 9691</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15250">Linux Kernel ncp_lookup allows elevated privileges</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-479">DSA-479-1 linux-kernel-2.4.18-alpha+i386+powerpc -- several vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html">RHSA-2004:188</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1035.html">OVAL1035</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval835.html">OVAL835</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="TURBO" url="http://www.securityfocus.com/advisories/6759">TLSA-2004-05</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035">oval:org.mitre.oval:def:1035</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835">oval:org.mitre.oval:def:835</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23"/><vers num="2.4.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0011" published="2004-01-20" seq="2004-0011" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-416">fsp -- buffer overflow, directory traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9377">Debian FSP Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14155">FSP boundary error buffer overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-048.shtml">O-048</ref></refs><vuln_soft><prod name="FSP" vendor="Debian"><vers num="2.81.b18" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0013" published="2004-02-03" seq="2004-0013" severity="Medium" type="CVE"><desc><descript source="cve">jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-414">jabber -- denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9376">bid 9376</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005">Updated jabber packages fix DoS vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14158">Jabber SSL connections denial of service</ref><ref source="OSVDB" url="http://www.osvdb.org/3345">3345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10559">10559</ref></refs><vuln_soft><prod name="Jabber Server" vendor="Jabber Software Foundation"><vers num="1.4.3"/><vers num="1.4.2a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0014" published="2004-01-20" seq="2004-0014" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340454803706&amp;w=2">New nd packages fix buffer overflows</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9365">bid 9365</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-412">nd -- buffer overflows</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14141">nd long string buffer overflow</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008616">1008616</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10549">10549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10550">10550</ref></refs><vuln_soft><prod name="nd" vendor="nd"><vers num="0.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0015" published="2004-02-03" seq="2004-0015" severity="High" type="CVE"><desc><descript source="cve">vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-418">vbox3 -- privilege leak</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9381">bid 9381</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14170">vbox3-gain-privileges(14170)</ref></refs><vuln_soft><prod name="vbox3" vendor="vbox3"><vers num="0.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0016" published="2004-02-03" seq="2004-0016" severity="High" type="CVE"><desc><descript source="cve">The calendar module for phpgroupware 0.9.14 does not enforce the &quot;save extension&quot; feature for holiday files, which allows remote attackers to create and execute PHP files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-419">phpgroupware -- missing filename sanitising, SQL injection</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9387">bid 9387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/13489">phpgroupware-calendar-file-include(13489)</ref><ref source="OSVDB" url="http://www.osvdb.org/6860">6860</ref></refs><vuln_soft><prod name="PhPGroupware" vendor="PhPGroupware"><vers num="0.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0017" published="2004-02-03" seq="2004-0017" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-419">phpgroupware -- missing filename sanitising, SQL injection</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9386">bid 9386</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008662">1008662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10591">10591</ref></refs><vuln_soft><prod name="PhPGroupware" vendor="PHPGroupWare"><vers num="0.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0028" published="2004-02-03" seq="2004-0028" severity="High" type="CVE"><desc><descript source="cve">jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-420">jitterbug -- improperly sanitised input</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9397">bid 9397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14207">jitterbug-execute-code(14207)</ref></refs><vuln_soft><prod name="Jitterbug" vendor="Samba"><vers num="1.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0029" published="2004-01-20" seq="2004-0029" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9366">bid 9366</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14153">Lotus Notes and Domino notes.ini file has insecure permissions</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</ref><ref source="" url="http://www.excluded.org/advisories/advisory05.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3424">3424</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008623">1008623</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10566">10566</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0030" published="2004-01-20" seq="2004-0030" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14159">PhpGedView $PGV_BASE_DIRECTORY PHP file include</ref><ref source="BID" url="http://www.securityfocus.com/bid/9368">9368</ref><ref source="OSVDB" url="http://www.osvdb.org/3343">3343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008632">1008632</ref></refs><vuln_soft><prod name="phpGedView" vendor="phpGedView"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0031" published="2004-01-20" seq="2004-0031" severity="High" type="CVE"><desc><descript source="cve">PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14161">PhpGedView allows administrative password modification</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref><ref source="OSVDB" url="http://www.osvdb.org/3403">3403</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0032" published="2004-01-20" seq="2004-0032" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14160">PhpGedView search.php cross-site scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/9369">9369</ref><ref source="OSVDB" url="http://www.osvdb.org/3402">3402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0033" published="2004-01-20" seq="2004-0033" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14162">PhpGedView admin.php information disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/9371">9371</ref><ref source="OSVDB" url="http://www.osvdb.org/3404">3404</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0034" published="2004-01-20" seq="2004-0034" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">Multiple Vulnerabilities in Phorum 3.4.5</ref><ref adv="1" source="Phorum.org" url="http://phorum.org/"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9361">bid 9361</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14145">Phorum common.php, profile.php, and login.php script cross-site scripting</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref><ref source="OSVDB" url="http://www.osvdb.org/3434">3434</ref><ref source="OSVDB" url="http://www.osvdb.org/3506">3506</ref><ref source="OSVDB" url="http://www.osvdb.org/3510">3510</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008633">1008633</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0035" published="2004-01-20" seq="2004-0035" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">Multiple Vulnerabilities in Phorum 3.4.5</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9363">bid 9363</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14146">Phorum register.php script SQL injection</ref><ref source="OSVDB" url="http://www.osvdb.org/3508">3508</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-06-08" name="CVE-2004-0036" published="2004-01-20" seq="2004-0036" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.vbulletin.com/forum/showthread.php?postid=588825">http://www.vbulletin.com/forum/showthread.php?postid=588825</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2">vBulletin Forum 2.3.xx calendar.php SQL Injection</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14144">vBulletin Forum 2.3.xx calendar.php script SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/9360">9360</ref><ref source="OSVDB" url="http://www.osvdb.org/3344">3344</ref></refs><vuln_soft><prod name="VBulletin" vendor="Jelsoft"><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-0037" published="2004-01-20" seq="2004-0037" severity="High" type="CVE"><desc><descript source="cve">FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2">FirstClass Client 7.1: Command Execution via Email Web Link</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9370">Open Text Corporation FirstClass Local File Reference Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14151">FirstClass Client executes code without displaying a warning dialog</ref><ref source="OSVDB" url="http://www.osvdb.org/3442">3442</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10556">10556</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008609">1008609</ref></refs><vuln_soft><prod name="OpenText FirstClass Desktop Client" vendor="OpenText"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0038" published="2004-06-14" seq="2004-0038" severity="High" type="CVE"><desc><descript source="cve">McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/173">20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability</ref><ref adv="1" source="NAI" url="http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt"></ref><ref adv="1" patch="1" source="osvdb" url="http://www.osvdb.org/5626"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14166">epolicy-execute-commands(14166)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10200">bugtraq id 10200</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num="2.5 SP1"/><vers num="2.5"/><vers num="2.5.1"/><vers num="3.0 SP2a"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-03" name="CVE-2004-0039" published="2004-03-03" seq="2004-0039" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/790771">HTTP Parsing Vulnerabilities in Check Point Firewall-1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14149">Check Point FireWall-1 format string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9581">bid 9581</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">Two checkpoint fw-1/vpn-1 vulns</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/162">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/security_server.html">http://www.checkpoint.com/techsupport/alerts/security_server.html</ref><ref source="MISC" url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">http://www.us-cert.gov/cas/techalerts/TA04-036A.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-072.shtml">O-072</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-03" name="CVE-2004-0040" published="2004-03-03" seq="2004-0040" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/873334">Check Point ISAKMP vulnerable to buffer overflow via Certificate Request</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14150">Check Point VPN-1 IKE buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9582">bid 9582</ref><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2"> Two checkpoint fw-1/vpn-1 vulns</ref><ref source="MISC" url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">http://www.us-cert.gov/cas/techalerts/TA04-036A.html</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/163">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-073.shtml">O-073</ref><ref source="OSVDB" url="http://www.osvdb.org/3821">3821</ref><ref source="OSVDB" url="http://www.osvdb.org/4432">4432</ref></refs><vuln_soft><prod name="VPN-1" vendor="Checkpoint"><vers num="4.1 SP5a"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/></prod><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1 SP5a"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0041" published="2004-02-03" seq="2004-0041" severity="High" type="CVE"><desc><descript source="cve">The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-421">mod-auth-shadow -- password expiration</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9404">bid 9404</ref><ref source="OSVDB" url="http://www.osvdb.org/3454">3454</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008675">1008675</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10612">10612</ref></refs><vuln_soft><prod name="mod_auth_shadow" vendor="mod_auth_shadow"><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0042" published="2004-02-03" seq="2004-0042" severity="Medium" type="CVE"><desc><descript source="cve">vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="Securitytracker.com" url="http://www.securitytracker.com/alerts/2004/Jan/1008628.html">vsftpd Discloses Whether Usernames are Valid or Not</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008628">1008628</ref></refs><vuln_soft><prod name="vsftpd" vendor="Beasts"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0043" published="2004-02-03" seq="2004-0043" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9383">9383</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/3437">3437</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008651">1008651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10573">10573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14171">yahoo-messenger-filename-bo(14171)</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="5.6.0.1351" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0044" published="2004-02-03" seq="2004-0044" severity="High" type="CVE"><desc><descript source="cve">Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when &quot;Allow Only Cisco CallManager Users&quot; is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml">Cisco Personal Assistant User Password Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9384">9384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14172">ciscopersonalassistant-config-file-access(14172)</ref><ref source="OSVDB" url="http://www.osvdb.org/3430">3430</ref></refs><vuln_soft><prod name="Personal Assistant" vendor="Cisco"><vers num="1.4(1)"/><vers num="1.4(2)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0045" published="2004-02-03" seq="2004-0045" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html">Buffer overflow in control message handling</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html">OpenPKG Security Advisory (inn)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9382">bid 9382</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791">SSA:2004-014-02</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759020">VU#759020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10578">10578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14190">inn-artpost-control-message-bo(14190)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0046" published="2004-02-03" seq="2004-0046" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating &apos;&quot;&apos; (double quote) character.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2">SnapStream PVS LITE Cross Site Scripting Vulnerabillity</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9375">bid 9375</ref><ref source="OSVDB" url="http://www.osvdb.org/3440">3440</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008646">1008646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10575">10575</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14164">snapstream-quotation-xss(14164)</ref></refs><vuln_soft><prod name="SnapStream PVS" vendor="SnapStream"><vers num="Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0047" published="2004-03-03" seq="2004-0047" severity="Medium" type="CVE"><desc><descript source="cve">Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-430">trr19 -- missing privilege release</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9520">bid 9520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14975">trr19-gain-privileges(14975)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10744/">10744</ref><ref source="OSVDB" url="http://www.osvdb.org/3747">3747</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008875">1008875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10745">10745</ref></refs><vuln_soft><prod name="TRR19" vendor="Yamamoto Hirotaka"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0049" published="2004-02-17" seq="2004-0049" severity="Medium" type="CVE"><desc><descript source="cve">Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Real.com" url="http://service.real.com/help/faq/security/040112_dos/">Potential Server/Proxy Denial-of-Service Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9421">bid 9421</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/security/security022604.html">http://service.real.com/help/faq/security/security022604.html</ref><ref source="VULNWATCH" url="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357834">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref></refs><vuln_soft><prod name="Helix Universal Server" vendor="RealNetworks"><vers num="9.0.2.881" prev="1"/></prod><prod name="Helix Universal Mobile Server" vendor="RealNetworks"><vers num="10.1.1.120" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0050" published="2004-06-14" seq="2004-0050" severity="Medium" type="CVE"><desc><descript source="cve">Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377388114888&amp;w=2">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" source="Bugtraq" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/020952.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16066">ultraseek-error-path-disclosure(16066)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref></refs><vuln_soft><prod name="Ultraseek" vendor="Verity"><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0051" published="2004-10-20" seq="2004-0051" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517788100063&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17337">mime-contenttransfer-filter-bypass(17337)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0052" published="2004-10-20" seq="2004-0052" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517669115891&amp;w=2">Multiple vendor MIME separator issue</ref><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17334">mime-separator-filtering-bypass(17334)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0053" published="2004-10-20" seq="2004-0053" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109520704408739&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17331">mime-rfc2047-filtering-bypass(17331)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0054" published="2004-02-17" seq="2004-0054" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml">Vulnerabilities in H.323 Message Processing</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008685">1008685</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.3T"/><vers num="12.0"/><vers num="12.0S"/><vers num="12.0T"/><vers num="12.1"/><vers num="12.1T"/><vers num="12.1E"/><vers num="12.2"/><vers num="12.2S"/><vers num="12.2T"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0055" published="2004-02-17" seq="2004-0055" severity="Medium" type="CVE"><desc><descript source="cve">The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7090">bid 7090</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/955526">tcpdump contains vulnerability in RADIUS decoding function print_attr_string() in print-radius.c</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">Updated tcpdump packages fix various vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-425">DSA-425</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval850.html">OVAL850</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval853.html">OVAL853</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850">oval:org.mitre.oval:def:850</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853">oval:org.mitre.oval:def:853</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832">CLSA-2003:832</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008735">1008735</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.5.2"/><vers num="3.6.2"/><vers num="3.7"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0056" published="2004-02-17" seq="2004-0056" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008687">1008687</ref></refs><vuln_soft><prod name="Business Communications Manager" vendor="Nortel Networks"><vers num=""/></prod><prod name="Succession 1000 IP Trunk and IP Peer Network" vendor="Nortel Networks"><vers num=""/></prod><prod name="802.11 Wireless IP Gateway" vendor="Nortel Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0057" published="2004-02-17" seq="2004-0057" severity="Medium" type="CVE"><desc><descript source="cve">The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid &quot;len&quot; or &quot;loc&quot; values to be used in a loop, a different vulnerability than CVE-2003-0989.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">multiple vulnerabilities in tcpdump 3.8.1</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-007.html">Updated tcpdump packages fix various vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9423">bid 9423</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-425">DSA-425-1 tcpdump -- multiple vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval851.html">OVAL851</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval854.html">OVAL854</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/174086">VU#174086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10636">10636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14837">tcpdump-rawprint-isakmp-dos(14837)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851">oval:org.mitre.oval:def:851</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854">oval:org.mitre.oval:def:854</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008716">1008716</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0058" published="2004-02-17" seq="2004-0058" severity="Low" type="CVE"><desc><descript source="cve">Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</ref><ref source="OSVDB" url="http://www.osvdb.org/3496">3496</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008702">1008702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10620">10620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14214">antivir-tmpfile-insecure(14214)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.9.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0059" published="2004-02-17" seq="2004-0059" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0060" published="2004-02-17" seq="2004-0060" severity="Medium" type="CVE"><desc><descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0061" published="2004-02-17" seq="2004-0061" severity="High" type="CVE"><desc><descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0062" published="2004-02-17" seq="2004-0062" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to &quot;cause negative totals&quot; via an order with a large quantity.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2">FishCart Integer Overflow / Rounding Error</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9426">bid 9426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008731">1008731</ref></refs><vuln_soft><prod name="FishCart" vendor="FishNet"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0063" published="2004-02-17" seq="2004-0063" severity="High" type="CVE"><desc><descript source="cve">The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ncipher.com" url="http://www.ncipher.com/support/advisories/advisory8_payshield.html">payShield library may verify bad requests</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2">20040114 nCipher Advisory #8: payShield library may verify bad requests</ref><ref source="BID" url="http://www.securityfocus.com/bid/9422">9422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14832">payshield-incorrect-request-verification(14832)</ref><ref source="OSVDB" url="http://www.osvdb.org/3537">3537</ref></refs><vuln_soft><prod name="PayShield SPP library" vendor="nCipher"><vers num="1.3.12"/><vers num="1.5.18"/><vers num="1.6.18"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0064" published="2004-02-17" seq="2004-0064" severity="Low" type="CVE"><desc><descript source="cve">The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9411">bid 9411</ref><ref source="OSVDB" url="http://www.osvdb.org/3460">3460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10623">10623</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008703">1008703</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0065" published="2004-02-17" seq="2004-0065" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/11910">11910</ref><ref source="BID" url="http://www.securityfocus.com/bid/11925">11925</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0066" published="2004-02-17" seq="2004-0066" severity="Medium" type="CVE"><desc><descript source="cve">phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/3464">3464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14215">phpgedview-path-disclosure(14215)</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0067" published="2004-02-17" seq="2004-0067" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded">20070827 PhpGedView login page multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/11868">11868</ref><ref source="BID" url="http://www.securityfocus.com/bid/11880">11880</ref><ref source="BID" url="http://www.securityfocus.com/bid/11882">11882</ref><ref source="BID" url="http://www.securityfocus.com/bid/11888">11888</ref><ref source="BID" url="http://www.securityfocus.com/bid/11890">11890</ref><ref source="BID" url="http://www.securityfocus.com/bid/11891">11891</ref><ref source="BID" url="http://www.securityfocus.com/bid/11894">11894</ref><ref source="BID" url="http://www.securityfocus.com/bid/11903">11903</ref><ref source="BID" url="http://www.securityfocus.com/bid/11904">11904</ref><ref source="BID" url="http://www.securityfocus.com/bid/11905">11905</ref><ref source="BID" url="http://www.securityfocus.com/bid/11906">11906</ref><ref source="BID" url="http://www.securityfocus.com/bid/11907">11907</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2995">ADV-2007-2995</ref><ref source="OSVDB" url="http://www.osvdb.org/3473">3473</ref><ref source="OSVDB" url="http://www.osvdb.org/3474">3474</ref><ref source="OSVDB" url="http://www.osvdb.org/3475">3475</ref><ref source="OSVDB" url="http://www.osvdb.org/3476">3476</ref><ref source="OSVDB" url="http://www.osvdb.org/3477">3477</ref><ref source="OSVDB" url="http://www.osvdb.org/3478">3478</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018613">1018613</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26628">26628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36285">phpgedview-login-xss(36285)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14212">phpgedview-multiple-xss(14212)</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0068" published="2004-02-17" seq="2004-0068" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2">PhpDig 1.6.x: remote command execution</ref><ref patch="1" source="Phpdig.net" url="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9424">bid 9424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14826">phpdig-config-file-include(14826)</ref></refs><vuln_soft><prod name="PhpDig" vendor="PhpDig.net"><vers num="1.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0069" published="2004-02-17" seq="2004-0069" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2">Windows FTP Server Format String Vulnerability</ref><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2">exploit for HD Soft Windows FTP Server 1.6</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9385">bid 9385</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008658">1008658</ref></refs><vuln_soft><prod name="Windows FTP Server" vendor="HD Soft"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0070" published="2004-02-17" seq="2004-0070" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2">Remote Code Execution in ezContents</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9396">bid 9396</ref><ref source="CONFIRM" url="http://www.ezcontents.org/forum/viewtopic.php?t=361">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14199">ezcontents-php-file-include(14199)</ref><ref source="OSVDB" url="http://www.osvdb.org/6878">6878</ref></refs><vuln_soft><prod name="ezContents" vendor="VisualShapers"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0071" published="2004-02-17" seq="2004-0071" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2">PHP Manpage lookup directory transversal / file disclosing</ref><ref source="BID" url="http://www.securityfocus.com/bid/9395">9395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14203">manpagelookup-directory-traversal(14203)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008689">1008689</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0072" published="2004-02-17" seq="2004-0072" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., &quot;%5c%2e%2e&quot;) sequences in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2">Directory Traversal in Accipiter Direct Server 6.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14198">Accipiter Direct Server dot dot directory traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9389">bid 9389</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref><ref source="OSVDB" url="http://www.osvdb.org/3433">3433</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10600">10600</ref></refs><vuln_soft><prod name="Accipiter Direct Server" vendor="Accipiter"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0073" published="2004-02-17" seq="2004-0073" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9338">bid 9338</ref><ref source="OSVDB" url="http://www.osvdb.org/3318">3318</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008584">1008584</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10535">10535</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14136">easydynamicpages-php-file-include(14136)</ref><ref source="OSVDB" url="http://www.osvdb.org/3408">3408</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2">20040102 include() vuln in EasyDynamicPages v.2.0</ref></refs><vuln_soft><prod name="EasyDynamicPages" vendor="Stoitsov"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0074" published="2004-02-17" seq="2004-0074" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9352">bid 9352</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9341">bid 9341</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14906">xsok long -xsokdir buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14910">xsok-lang-bo(14910)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2">20040102 xsok local games exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2">20040103 xsok local games exploit (2)</ref></refs><vuln_soft><prod name="xsok" vendor="Michael Bischoff"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0075" published="2004-03-15" seq="2004-0075" severity="Low" type="CVE"><desc><descript source="cve">The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">Updated kernel packages resolve security vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15246">Linux kernel Vicam USB driver denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9690">bid 9690</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836">oval:org.mitre.oval:def:836</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0076" published="2004-08-18" reject="1" seq="2004-0076" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was removed from consideration by its Candidate Numbering Authority.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0077" published="2004-03-03" seq="2004-0077" severity="High" type="CVE"><desc><descript source="cve">The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2">Second critical mremap() bug found in all Linux, kernel,s</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-439">linux-kernel-2.4.16-arm -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15244">Linux kernel do_mremap allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9686">bid 9686</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200403-02.xml">Linux kernel do_mremap local privilege escalation vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html">20040218 Second critical mremap() bug found in all Linux kernels</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-438">DSA-438</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-440">DSA-440</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-441">DSA-441</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-444">DSA-444</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-450">DSA-450</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-453">DSA-453</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-454">DSA-454</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-456">DSA-456</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-466">DSA-466</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-470">DSA-470</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-514">DSA-514</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-475">DSA-475</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-066.html">RHSA-2004:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">RHSA-2004:069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2">2004-0007</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2">2004-0008</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/981222">VU#981222</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="OSVDB" url="http://www.osvdb.org/3986">3986</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825">oval:org.mitre.oval:def:825</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837">oval:org.mitre.oval:def:837</ref></refs><vuln_soft><prod name="Netwosix Linux" vendor="Netwosix"><vers num="1.0"/></prod><prod name="kernel_BOOT" vendor="Red Hat"><vers edition="i386" num="2.4.20.8"/></prod><prod name="kernel_doc" vendor="Red Hat"><vers edition="i386" num="2.4.20.8"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.2"/></prod><prod name="kernel" vendor="Red Hat"><vers edition="Athlon" num="2.4.20.8"/><vers edition="i386" num="2.4.20.8"/><vers edition="i686" num="2.4.20.8"/><vers edition="athlon smp" num="2.4.20.8"/><vers edition="i686 smp" num="2.4.20.8"/></prod><prod name="kernel_bigmem" vendor="Red Hat"><vers edition="i686" num="2.4.20.8"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/></prod><prod name="kernel_source" vendor="Red Hat"><vers edition="i386 src" num="2.4.20.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0078" published="2004-03-03" seq="2004-0078" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://bugs.debian.org/126336">http://bugs.debian.org/126336</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-050.html">Updated mutt packages fix remotely-triggerable crash</ref><ref adv="1" patch="1" source="Mandrakesecure.net" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:010">mutt</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-051.html">Updated mutt packages fix remotely-triggerable crash</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9641">bid 9641</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15134">Mutt index menu buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2">20040211 Mutt-1.4.2 fixes buffer overflow.</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt">CSSA-2004-013.0</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010">MDKSA-2004:010</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2">20040215 LNSA-#2004-0001: mutt remote crash</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</ref><ref source="OSVDB" url="http://www.osvdb.org/3918">3918</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811">oval:org.mitre.oval:def:811</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838">oval:org.mitre.oval:def:838</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="1.2.1"/><vers num="1.2.5.1"/><vers num="1.2.5.5"/><vers num="1.2.5.4"/><vers num="1.2.5.12 OL"/><vers num="1.2.5.12"/><vers num="1.2.5"/><vers num="1.3.12.1"/><vers num="1.3.12"/><vers num="1.3.16"/><vers num="1.3.17"/><vers num="1.3.22"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.4.0"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0079" published="2004-11-23" seq="2004-0079" severity="Medium" type="CVE"><desc><descript source="cve">The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">Multiple Vulnerabilities in OpenSSL</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15505">OpenSSL do_change_cipher_spec function denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20040317.txt">http://www.openssl.org/news/secadv_20040317.txt</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-465">DSA-465</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html">ESA-20040317-003</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc">FreeBSD-SA-04:05</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">NetBSD-SA2004-005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html">SuSE-SA:2004:007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/288574">VU#288574</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2621.html">OVAL2621</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval870.html">OVAL870</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval975.html">OVAL975</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-095.shtml">FEDORA-2004-095</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-139.html">RHSA-2004:139</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-101.shtml">O-101</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-830.html">RHSA-2005:830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17401">17401</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html">FEDORA-2005-1042</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-829.html">RHSA-2005:829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17381">17381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17398">17398</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2">SSRT4717</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961">SSA:2004-077</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18247">18247</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621">oval:org.mitre.oval:def:2621</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870">oval:org.mitre.oval:def:870</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975">oval:org.mitre.oval:def:975</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="StoneGate VPN Client" vendor="Stonesoft"><vers num="1.7"/><vers num="1.7.2"/><vers num="2.0"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0080" published="2004-03-03" seq="2004-0080" severity="Medium" type="CVE"><desc><descript source="cve">The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-056.html">Updated util-linux packages fix information leak</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9558">bid 9558</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-06.xml">GLSA-200404-06</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2">20040331 OpenLinux: util-linux could leak sensitive data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2">20040408 LNSA-#2004-0010: login may leak sensitive data</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/801526">VU#801526</ref><ref source="OSVDB" url="http://www.osvdb.org/3796">3796</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10773">10773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15016">utillinux-information-leak(15016)</ref></refs><vuln_soft><prod name="util-linux" vendor="Andries Brouwer"><vers num="2.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0081" published="2004-11-23" seq="2004-0081" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/465542">OpenSSL does not properly handle unknown message types</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15509">OpenSSL unknown TLS message types denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107955049331965&amp;w=2">20040317 Re: New OpenSSL releases fix denial of service attacks [17  March 2004]</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html">ESA-20040317-003</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-465">DSA-465</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-119.html">RHSA-2004:119</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc">20040304-01-U</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">TA04-078A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval871.html">OVAL871</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval902.html">OVAL902</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-095.shtml">FEDORA-2004-095</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-139.html">RHSA-2004:139</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871">oval:org.mitre.oval:def:871</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902">oval:org.mitre.oval:def:902</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="StoneGate VPN Client" vendor="Stonesoft"><vers num="1.7"/><vers num="1.7.2"/><vers num="2.0"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0082" published="2004-03-03" seq="2004-0082" severity="High" type="CVE"><desc><descript source="cve">The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</ref><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-064.html">Updated samba packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9637">bid 9637</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15132">Samba mksmbpasswd.sh could allow an attacker to gain access to user&apos;s account</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-078.shtml">O-078</ref><ref source="OSVDB" url="http://www.osvdb.org/3919">3919</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827">oval:org.mitre.oval:def:827</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0083" published="2004-03-03" seq="2004-0083" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Xfree86" url="http://www.xfree86.org/cvs/changes">Recent Changes to XFree86</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9636">bid 9636</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2">XFree86FontInformationFileBufferOverflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15130">XFree86 font.alias file buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-02.xml">XFree86 Font Information File Buffer Overflow</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=72">http://www.idefense.com/application/poi/display?id=72</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval806.html">OVAL806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval830.html">OVAL830</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820006">VU#820006</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2">20040211 XFree86 vulnerability exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806">oval:org.mitre.oval:def:806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830">oval:org.mitre.oval:def:830</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0084" published="2004-03-03" seq="2004-0084" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9652">bid 9652</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15200">XFree86 CopyISOLatin1Lowered buffer overflow</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=73">http://www.idefense.com/application/poi/display?id=73</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval807.html">OVAL807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval831.html">OVAL831</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/667502">VU#667502</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807">oval:org.mitre.oval:def:807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831">oval:org.mitre.oval:def:831</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0085" published="2004-03-03" seq="2004-0085" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14992">Mac OS X mail undisclosed security issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/9504">bid 9504</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.1.5"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0086" published="2004-03-03" seq="2004-0086" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0087" published="2004-03-03" seq="2004-0087" severity="Low" type="CVE"><desc><descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14997">macosx-configd-file-manipulation(14997)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="OSVDB" url="http://www.osvdb.org/6819">6819</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0088" published="2004-03-03" seq="2004-0088" severity="Low" type="CVE"><desc><descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="OSVDB" url="http://www.osvdb.org/6820">6820</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0089" published="2004-03-03" seq="2004-0089" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9509">bid 9509</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a012704-1.txt">A012704-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/902374">VU#902374</ref><ref source="OSVDB" url="http://www.osvdb.org/6821">6821</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14968">macosx-trublue-environmentvariable-bo(14968)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0090" published="2004-12-31" seq="2004-0090" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not &quot;shutdown properly,&quot; which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3791&amp;cid=1">ESB-2004.0072</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10723/">10723</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0091" published="2004-02-17" seq="2004-0091" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying &quot;There is no hidden field called &apos;reg_site&apos;, nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2">vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2">vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2"> RE: vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2">:    Re: vBulletin Security Vulnerability</ref><ref source="MISC" url="http://securitytracker.com/alerts/2004/Jan/1008780.html">http://securitytracker.com/alerts/2004/Jan/1008780.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008780">1008780</ref></refs><vuln_soft><prod name="Vbulletin" vendor="Jelsoft"><vers num="3.0 beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0092" published="2004-03-03" seq="2004-0092" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0093" published="2004-03-15" seq="2004-0093" severity="High" type="CVE"><desc><descript source="cve">XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-443">xfree86 -- several vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9701">bid 9701</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15272">XFree86 GLX array index denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0094" published="2004-03-15" seq="2004-0094" severity="High" type="CVE"><desc><descript source="cve">Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-443">xfree86 -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15273">XFree86 GLX integer signedness denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref><ref source="BID" url="http://www.securityfocus.com/bid/9701">9701</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0095" published="2004-02-17" seq="2004-0095" severity="Medium" type="CVE"><desc><descript source="cve">McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9476">bid 9476</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14989">epolicy-contentlength-post-dos(14989)</ref><ref source="OSVDB" url="http://www.osvdb.org/3744">3744</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0096" published="2004-03-03" seq="2004-0096" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ModPython.org" url="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html">Mod_python 2.7.10</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-03.xml">GLSA-200401-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-058.html">RHSA-2004:058</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-063.html">RHSA-2004:063</ref></refs><vuln_soft><prod name="mod_python" vendor="Apache Software Foundation"><vers num="2.7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0097" published="2004-03-03" seq="2004-0097" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-047.html">Updated PWLib packages fix protocol security issues</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15202">PWLib message denial of service</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-448">DSA-448-1 pwlib -- several vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval803.html">OVAL803</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval826.html">OVAL826</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803">oval:org.mitre.oval:def:803</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826">oval:org.mitre.oval:def:826</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref></refs><vuln_soft><prod name="PWLib" vendor="OpenH323 Project"><vers num="1.6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0099" published="2004-03-03" seq="2004-0099" severity="Medium" type="CVE"><desc><descript source="cve">mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc">mksnap_ffs clears file system options</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9533">bid 9533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15005">freebsd-mksnapffs-bypass-security(15005)</ref><ref source="OSVDB" url="http://www.osvdb.org/3790">3790</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.1 Release"/><vers num="5.2 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-0103" published="2004-03-03" seq="2004-0103" severity="Medium" type="CVE"><desc><descript source="cve">crawl before 4.0.0 beta23 does not properly &quot;apply a size check&quot; when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-432">crawl -- buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9566">9566</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10788/">10788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15032">crawl-long-environment-bo(15032)</ref></refs><vuln_soft><prod name="Crawl" vendor="Linley Henzell"><vers num="4.0.0 b23" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0104" published="2004-03-03" seq="2004-0104" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-073.html">Updated metamail packages fix vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9692">bid 9692</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15259">Metamail header format string attack</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15245">metamail-contenttype-format-string(15245)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/518518">VU#518518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7" prev="1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0105" published="2004-03-03" seq="2004-0105" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-073.html">Updated metamail packages fix vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15258">Metamail splitmail file Subject header buffer overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15247">metamail-printheader-nonascii-bo(15247)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/513062">VU#513062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref><ref source="BID" url="http://www.securityfocus.com/bid/9692">9692</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7" prev="1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0106" published="2004-03-03" seq="2004-0106" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Slackware.com" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">XFree86 security update</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9655">bid 9655</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15206">XFree86 improper handling of multiple font files</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval809.html">OVAL809</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval832.html">OVAL832</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809">oval:org.mitre.oval:def:809</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832">oval:org.mitre.oval:def:832</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0107" published="2004-04-15" seq="2004-0107" severity="Medium" type="CVE"><desc><descript source="cve">The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-053.html">Updated sysstat packages fix security vulnerabilities</ref><ref patch="1" source="SGI.com" url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc">SGI Advanced Linux Environment security update #14</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9838">bid 9838</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-093.html">RHSA-2004:093</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-097.shtml">O-097</ref><ref source="OSVDB" url="http://www.osvdb.org/6884">6884</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval849.html">OVAL849</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval862.html">OVAL862</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15428">sysstat-post-trigger-symlink(15428)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849">oval:org.mitre.oval:def:849</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862">oval:org.mitre.oval:def:862</ref></refs><vuln_soft><prod name="Sysstat" vendor="Sysstat"><vers num="4.0.7"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.1.6"/><vers num="4.1.7"/><vers num="5.0.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="sysstat" vendor="Red Hat"><vers edition="i386" num="4.0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0108" published="2004-04-15" seq="2004-0108" severity="Medium" type="CVE"><desc><descript source="cve">The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-053.html">Updated sysstat packages fix security vulnerabilities</ref><ref patch="1" source="SGI.com" url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc">SGI Advanced Linux Environment security update #14</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9844">bid 9844</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-460">DSA-460</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15437">sysstat-isag-symlink(15437)</ref></refs><vuln_soft><prod name="Sysstat" vendor="Sysstat"><vers num="4.0.7"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.1.6"/><vers num="4.1.7"/><vers num="5.0.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="sysstat" vendor="Red Hat"><vers edition="i386" num="4.0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0109" published="2004-06-01" seq="2004-0109" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc">20040405-01-U</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc">20040504-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval940.html">OVAL940</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-105.html">RHSA-2004:105</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-183.html">RHSA-2004:183</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html">SuSE-SA:2004:009</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="BID" url="http://www.securityfocus.com/bid/10141">10141</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11361">11361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11373">11373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11469">11469</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11470">11470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11486">11486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11494">11494</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11518">11518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11626">11626</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11861">11861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11986">11986</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12003">12003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15866">linux-iso9660-bo(15866)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940">oval:org.mitre.oval:def:940</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.5"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0110" published="2004-03-15" seq="2004-0110" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-090.html">Updated libxml2 packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9718">bid 9718</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15301">Libxml2 nanohttp buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2">[OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-455">DSA-455</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-01.xml">GLSA-200403-01</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-091.html">RHSA-2004:091</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15302">libxml2-nanoftp-bo(15302)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10958/">10958</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval833.html">OVAL833</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval875.html">OVAL875</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/493966">VU#493966</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-086.shtml">O-086</ref><ref source="" url="http://www.xmlsoft.org/news.html">http://www.xmlsoft.org/news.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2">20040306 TSLSA-2004-0010 - libxml2</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-650.html">RHSA-2004:650</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833">oval:org.mitre.oval:def:833</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875">oval:org.mitre.oval:def:875</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Libxml2" vendor="XMLSoft"><vers num="2.4.19"/><vers num="2.4.23"/><vers num="2.5.4"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/></prod><prod name="Libxml" vendor="XMLSoft"><vers num="1.8.17"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0111" published="2004-04-15" seq="2004-0111" severity="Medium" type="CVE"><desc><descript source="cve">gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mandrakesecure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:020"></ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-103.html">Updated gdk-pixbuf packages fix crash</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9842">bid 9842</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-464">DSA-464</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020">MDKSA-2004:020</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-102.html">RHSA-2004:102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15426">gdk-pixbuf-bitmap-dos(15426)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845">oval:org.mitre.oval:def:845</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846">oval:org.mitre.oval:def:846</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.18"/><vers num="0.20"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="gdk_pixbuf" vendor="Red Hat"><vers edition="i386" num="0.18.0.7"/><vers edition="i386 Dev" num="0.18.0.7"/><vers edition="i386 Gnome" num="0.18.0.7"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0112" published="2004-11-23" seq="2004-0112" severity="Medium" type="CVE"><desc><descript source="cve">The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">Multiple Vulnerabilities in OpenSSL</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15508">OpenSSL on a server configured with Kerberos ciphersuites denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20040317.txt">http://www.openssl.org/news/secadv_20040317.txt</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">NetBSD-SA2004-005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html">SuSE-SA:2004:007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2">SSRT4717</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/484726">VU#484726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1049.html">OVAL1049</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval928.html">OVAL928</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-101.shtml">O-101</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961">SSA:2004-077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049">oval:org.mitre.oval:def:1049</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928">oval:org.mitre.oval:def:928</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0113" published="2004-03-29" seq="2004-0113" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://nagoya.apache.org/bugzilla/show_bug.cgi?id=27106">http://nagoya.apache.org/bugzilla/show_bug.cgi?id=27106</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15419">Apache HTTP Server mod_ssl plain HTTP request denial of service</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638">cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</ref><ref adv="1" source="Apacheweek.com" url="http://www.apacheweek.com/features/security-20">Overview of security vulnerabilities in Apache httpd 2.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9826">bid 9826</ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106"></ref><ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839">CLSA-2004:839</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-04.xml">GLSA-200403-04</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043">MDKSA-2004:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-084.html">RHSA-2004:084</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-182.html">RHSA-2004:182</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref><ref source="OSVDB" url="http://www.osvdb.org/4182">4182</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876">oval:org.mitre.oval:def:876</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0114" published="2004-03-03" seq="2004-0114" severity="Medium" type="CVE"><desc><descript source="cve">The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment&apos;s reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.pine.nl/press/pine-cert-20040201.txt">http://www.pine.nl/press/pine-cert-20040201.txt</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc">shmat reference counting bug</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15061">Multiple vendor BSD platforms allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9586">bid 9586</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2"> [PINE-CERT-20040201] reference count overflow in shmat()</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc">NetBSD-SA2004-004</ref><ref source="" url="http://www.openbsd.org/errata33.html#sysvshm"></ref><ref source="OSVDB" url="http://www.osvdb.org/3836">3836</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.2" prev="1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.6" prev="1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0115" published="2004-03-03" seq="2004-0115" severity="Medium" type="CVE"><desc><descript source="cve">VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp">Vulnerability in Virtual PC for Mac Could Allow Privilege Elevation (835150)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9632">bid 9632</ref><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a021004-1.txt">Virtual PC Services Insecure Temporary File Creation</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-076.shtml">O-076</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15113">virtual-pc-gain-privileges(15113)</ref><ref source="OSVDB" url="http://www.osvdb.org/3893">3893</ref></refs><vuln_soft><prod name="Virtual PC" vendor="Microsoft"><vers edition="Mac2" num="6.0"/><vers edition="Mac1" num="6.0"/><vers edition="Mac" num="6.0"/><vers edition="Mac" num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0116" published="2004-06-01" seq="2004-0116" severity="Medium" type="CVE"><desc><descript source="cve">An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="eEye" url="http://www.eeye.com/html/Research/Advisories/AD20040413A.html">AD20040413A</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx">MS04-012</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/417052">VU#417052</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp">MS04-012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval955.html">OVAL955</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval957.html">OVAL957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval958.html">OVAL958</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-115.shtml">O-115</ref><ref source="BID" url="http://www.securityfocus.com/bid/10127">10127</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Apr/1009758.html">1009758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11065/">11065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15708">win-rpcss-rpcmessage-dos(15708)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955">oval:org.mitre.oval:def:955</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957">oval:org.mitre.oval:def:957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958">oval:org.mitre.oval:def:958</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0117" published="2004-06-01" seq="2004-0117" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/353956">VU#353956</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval907.html">OVAL907</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval946.html">OVAL946</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval964.html">OVAL964</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15710">win-h323-bo(15710)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907">oval:org.mitre.oval:def:907</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946">oval:org.mitre.oval:def:946</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964">oval:org.mitre.oval:def:964</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="NetMeeting" vendor="Microsoft"><vers num="3" prev="1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0118" published="2004-06-01" seq="2004-0118" severity="High" type="CVE"><desc><descript source="cve">The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-April/020070.html">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref><ref adv="1" patch="1" source="eEye" url="http://www.eeye.com/html/Research/Advisories/AD20040413E.html">AD20040413E</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/783748">VU#783748</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1512.html">OVAL1512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1718.html">OVAL1718</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10117">10117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15714">win-vdm-gain-privileges(15714)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512">oval:org.mitre.oval:def:1512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718">oval:org.mitre.oval:def:1718</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0119" published="2004-06-01" seq="2004-0119" severity="High" type="CVE"><desc><descript source="cve">The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/638548">VU#638548</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html">20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1808.html">OVAL1808</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1962.html">OVAL1962</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1997.html">OVAL1997</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10113">10113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15715">win-spp-bo(15715)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808">oval:org.mitre.oval:def:1808</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962">oval:org.mitre.oval:def:1962</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997">oval:org.mitre.oval:def:1997</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="IIS" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0120" published="2004-06-01" seq="2004-0120" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/150236">VU#150236</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval885.html">OVAL885</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval886.html">OVAL886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval892.html">OVAL892</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10115">10115</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15712">ssl-message-dos(15712)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885">oval:org.mitre.oval:def:885</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886">oval:org.mitre.oval:def:886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892">oval:org.mitre.oval:def:892</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-18" name="CVE-2004-0121" published="2004-04-15" seq="2004-0121" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=79&amp;type=vulnerabilities">Microsoft Outlook &quot;mailto:&quot; Parameter Passing Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp">Vulnerability in Microsoft Outlook Could Allow Code Execution (828040)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9827">bid 9827</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893704602842&amp;w=2">20040310 Outlook mailto: URL argument injection vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-070A.html">TA04-070A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/305206">VU#305206</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-096.shtml">O-096</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:843">oval:org.mitre.oval:def:843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15414">outlook-mailtourl-execute-code(15414)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15429">outlook-ms04009-patch(15429)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="XP SP2"/><vers num="XP SP1"/><vers num="XP"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0122" published="2004-04-15" seq="2004-0122" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-010.asp">Vulnerability in MSN Messenger Could Allow Information Disclosure (838512)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9828">bid 9828</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/688094">VU#688094</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:844">oval:org.mitre.oval:def:844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15427">msn-ms04010-patch(15427)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15415">msn-request-view-files(15415)</ref></refs><vuln_soft><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0123" published="2004-06-01" seq="2004-0123" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/255924">VU#255924</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1007.html">OVAL1007</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1076.html">OVAL1076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval924.html">OVAL924</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10118">10118</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15713">win-asn1-double-free(15713)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007">oval:org.mitre.oval:def:1007</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076">oval:org.mitre.oval:def:1076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924">oval:org.mitre.oval:def:924</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2004-0124" published="2004-06-01" seq="2004-0124" severity="Low" type="CVE"><desc><descript source="cve">The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx">MS04-012</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/212892">VU#212892</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp">MS04-012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1041.html">OVAL1041</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1062.html">OVAL1062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1066.html">OVAL1066</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1072.html">OVAL1072</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-115.shtml">O-115</ref><ref source="BID" url="http://www.securityfocus.com/bid/10121">10121</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11065/">11065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15711">win-objectidentifier-open-port(15711)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041">oval:org.mitre.oval:def:1041</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062">oval:org.mitre.oval:def:1062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066">oval:org.mitre.oval:def:1066</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072">oval:org.mitre.oval:def:1072</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0"/><vers num="Server 4.0"/><vers num="4.0"/><vers num="Terminal Server 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2004-0125" published="2004-08-06" seq="2004-0125" severity="High" type="CVE"><desc><descript source="cve">The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10485">FreeBSD jail() Process Unauthorized Routing Table Modification Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16342">FreeBSD jailed process routing table modification</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc">FreeBSD-SA-04:12</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.10 pre"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0126" published="2004-03-29" seq="2004-0126" severity="Medium" type="CVE"><desc><descript source="cve">The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn&apos;t have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD.org" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc">Jailed processes can attach to other jails</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9762">bid 9762</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15344">FreeBSD jail_attach allows elevated privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/4101">4101</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0127" published="2004-03-03" seq="2004-0127" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/352355">PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9529">bid 9529</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=3768">3768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15129">phpgedview-editconfig-directory-traversal(15129)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008892">1008892</ref></refs><vuln_soft><prod name="PhpGedView" vendor="PhpGedView"><vers num="2.52.3"/><vers num="2.60"/><vers num="2.61"/><vers num="2.61.1"/><vers num="2.65"/><vers num="2.65.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0128" published="2004-03-03" seq="2004-0128" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/352355">Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref><ref adv="1" source="SourceForge.net" url="http://sourceforge.net/project/shownotes.php?release_id=141517">PhpGedView v2.65.2</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9531">bid 9531</ref><ref source="OSVDB" url="http://www.osvdb.org/3769">3769</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14987">phpgedview-gedfilconf-file-include(14987)</ref></refs><vuln_soft><prod name="PhpGedView" vendor="PhpGedView"><vers num="2.52.3"/><vers num="2.60"/><vers num="2.61"/><vers num="2.61.1"/><vers num="2.65"/><vers num="2.65.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0129" published="2004-03-03" seq="2004-0129" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=350228">http://sourceforge.net/forum/forum.php?forum_id=350228</ref><ref source="CONFIRM" url="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2">Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-05.xml">phpMyAdmin &lt; 2.5.6-rc1: possible attack against export.php</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9564">bid 9564</ref><ref source="OSVDB" url="http://www.osvdb.org/3800">3800</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10769">10769</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15021">phpmyadmin-dotdot-directory-traversal(15021)</ref></refs><vuln_soft><prod name="PhpMyAdmin" vendor="PhpMyAdmin"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.2 rc3"/><vers num="2.2 rc2"/><vers num="2.2 rc1"/><vers num="2.2 pre1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.4.0"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.4"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0130" published="2004-03-03" seq="2004-0130" severity="Medium" type="CVE"><desc><descript source="cve">login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SecuriTeam.com" url="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html">PhpGedView Path Disclosure Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Jan/1008844.html">1008844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15128">phpgedview-loginphp-path-disclosure(15128)</ref><ref source="" url="http://www.netvigilance.com/advisory0001"></ref><ref source="OSVDB" url="http://www.osvdb.org/6886">6886</ref></refs><vuln_soft><prod name="phpGedView" vendor="phpGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0131" published="2004-03-03" seq="2004-0131" severity="Medium" type="CVE"><desc><descript source="cve">The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</ref><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/016721.html">GNU Radius Remote Denial of Service Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/277396">GNU Radius accounting service fails to properly handle exceptional Acct-Status-Type and Acct-Session-Id attributes</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9578">bid 9578</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15046">GNU Radius rad_print_request denial of service</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true">20040204 GNU Radius Remote Denial of Service Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3824">3824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10799">10799</ref></refs><vuln_soft><prod name="Radius" vendor="GNU"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0132" published="2004-03-03" seq="2004-0132" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2">PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9638">bid 9638</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15135">ezContents multiple .php PHP file inclusion</ref></refs><vuln_soft><prod name="ezContents" vendor="VisualShapers"><vers num="1.40"/><vers num="1.41"/><vers num="1.42"/><vers num="1.43"/><vers num="1.44"/><vers num="1.45b"/><vers num="1.45"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0.1"/><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0133" published="2004-06-01" seq="2004-0133" severity="Low" type="CVE"><desc><descript source="cve">The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc">20040405-01-U</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="BID" url="http://www.securityfocus.com/bid/10151">10151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15901">linux-xfs-info-disclosure(15901)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0134" published="2004-08-18" seq="2004-0134" severity="High" type="CVE"><desc><descript source="cve">cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10418">IRIX Checkpoint and Restart libcpr Library Loading Privilege Escalation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16259">SGI IRIX cpr allows elevated privileges</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc">20040507-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="4.0"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5B"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5 20"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22m"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0135" published="2004-08-06" seq="2004-0135" severity="High" type="CVE"><desc><descript source="cve">The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16413">SGI IRIX SGI_IOPROBE allows root privileges</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10548/">SGI IRIX SYSSGI() System Call Unprivileged User Kernel Memory Access Vulnerability</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7122">7122</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="4.0"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5B"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5 20"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22m"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0136" published="2004-08-06" seq="2004-0136" severity="Low" type="CVE"><desc><descript source="cve">The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a &quot;corrupted binary.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10547">SGI IRIX Undisclosed MapElf32Exec Local Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16416">SGI IRIX mapelf32exec denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">Updated kernel packages fix security vulnerabilities</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7123">7123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0137" published="2004-08-06" seq="2004-0137" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of &quot;page invalidation issues.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10549">SGI IRIX Undisclosed Init Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16417">SGI IRIX page denial of service</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7124">7124</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-31" name="CVE-2004-0138" published="2004-12-31" seq="2004-0138" severity="Medium" type="CVE"><desc><descript source="cve">The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="" url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes"></ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="BID" url="http://www.securityfocus.com/bid/18174">18174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">RHSA-2004:549</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43124">linux-kernel-elfloader-dos(43124)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.24"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0139" published="2005-01-10" seq="2004-0139" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which &quot;t_unbind changes t_bind&apos;s behavior,&quot; has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11276">SGI IRIX T_Bind/T_UnBind Undisclosed Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17547">SGI IRIX bsd.a kernel t_bind and t_unbind</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc">20040905-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12682">12682</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0143" published="2004-03-03" seq="2004-0143" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2">ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref><ref adv="1" patch="1" source="Pentest.co.uk" url="http://www.pentest.co.uk/documents/ptl-2004-01.html">Multiple vulnerabilities in Nokia phones</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9603">bid 9603</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15107">Nokia OBEX denial of service</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref></refs><vuln_soft><prod name="Nokia" vendor="Nokia"><vers num="6310i"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0148" published="2004-04-15" seq="2004-0148" severity="High" type="CVE"><desc><descript source="cve">wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-457">wu-ftpd -- several vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-096.html">Updated wu-ftpd package fixes security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9832">bid 9832</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2">SSRT4704</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1867">ADV-2006-1867</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147">oval:org.mitre.oval:def:1147</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636">oval:org.mitre.oval:def:1636</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637">oval:org.mitre.oval:def:1637</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648">oval:org.mitre.oval:def:648</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11055">11055</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20168">20168</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1">102356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15423">wuftpd-restrictedgid-gain-access(15423)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.1"/><vers edition="academ" num="2.4.2 Beta2"/><vers edition="academ" num="2.4.2 Beta18"/><vers num="2.4.2 VR17"/><vers num="2.4.2 VR16"/><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18 VR8"/><vers num="2.4.2 Beta18 VR7"/><vers num="2.4.2 Beta18 VR6"/><vers num="2.4.2 Beta18 VR5"/><vers num="2.4.2 Beta18 VR4"/><vers num="2.4.2 Beta18 VR15"/><vers num="2.4.2 Beta18 VR14"/><vers num="2.4.2 Beta18 VR13"/><vers num="2.4.2 Beta18 VR12"/><vers num="2.4.2 Beta18 VR11"/><vers num="2.4.2 Beta18 VR10"/><vers num="2.5.0"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0149" published="2004-05-04" seq="2004-0149" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-451">DSA-451-1 xboing -- buffer overflows</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9764">xboing Local Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15347">xboing buffer overflow</ref></refs><vuln_soft><prod name="xboing" vendor="xboing"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0150" published="2004-04-15" seq="2004-0150" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-458">python2.2 -- buffer overflow</ref><ref adv="1" patch="1" source="Mandrakesecure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:019">python</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9836">bid 9836</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml">GLSA-200409-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019">MDKSA-2004:019</ref><ref source="OSVDB" url="http://www.osvdb.org/4172">4172</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15409">python-getaddrinfo-bo(15409)</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.2"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0151" published="2004-04-15" seq="2004-0151" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-462">xitalk -- missing privilege release</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9851">bid 9851</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15456">xitalk allows attacker to gain elevated privileges</ref><ref source="MISC" url="http://shellcode.org/Advisories/XITALK.txt">http://shellcode.org/Advisories/XITALK.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11114/">11114</ref></refs><vuln_soft><prod name="xitalk" vendor="XInterceptTalk"><vers num="1.1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0152" published="2004-04-15" seq="2004-0152" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15601">emil email multiple buffer overflows</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2">New emil packages fix multiple vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-468">emil -- several vulnerabilities</ref></refs><vuln_soft><prod name="emil" vendor="emil"><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.0 Beta9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0153" published="2004-04-15" seq="2004-0153" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2">New emil packages fix multiple vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-468">emil -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15602">emil format string attack</ref></refs><vuln_soft><prod name="emil" vendor="emil"><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.0 Beta9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0154" published="2004-06-14" seq="2004-0154" severity="Medium" type="CVE"><desc><descript source="cve">rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-072.html">RHSA-2004:072</ref><ref adv="1" patch="1" source="Trustix" url="http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt">2004-0009</ref><ref adv="1" source="Red Hat" url="http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15418">nfs-utils-dns-dos(15418)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9813">bugtraq id 9813</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval861.html">OVAL861</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861">oval:org.mitre.oval:def:861</ref></refs><vuln_soft><prod name="nfs-utils" vendor="nfs"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0155" published="2004-06-01" seq="2004-0155" severity="High" type="CVE"><desc><descript source="cve">The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136746911000&amp;w=2">20040407 CAN-2004-0155: The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:027">MDKSA-2004:027</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-165.html">RHSA-2004:165</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml">GLSA-200406-17</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:027">MDKSA-2004:027</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069">MDKSA-2004:069</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt">SCOSA-2005.10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval945.html">OVAL945</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/552398">VU#552398</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11328">11328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945">oval:org.mitre.oval:def:945</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:027">MDKSA-2004:027</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0156" published="2004-06-01" seq="2004-0156" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-485">DSA-485</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308904205272&amp;w=2">20040426 [ GLSA 200404-18 ] Multiple Vulnerabilities in ssmtp</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-18.xml">GLSA-200404-18</ref><ref source="BID" url="http://www.securityfocus.com/bid/10150">10150</ref><ref source="OSVDB" url="http://www.osvdb.org/5360">5360</ref><ref source="OSVDB" url="http://www.osvdb.org/5361">5361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009788">1009788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11378">11378</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11384">11384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11485">11485</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11571">11571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15872">ssmtp-die-logevent-format-string(15872)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403772130855&amp;w=2">20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)</ref></refs><vuln_soft><prod name="ssmtp" vendor="ssmtp"><vers num="2.49" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0157" published="2004-06-01" seq="2004-0157" severity="Medium" type="CVE"><desc><descript source="cve">x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-484">DSA-484</ref><ref source="" url="http://shellcode.org/Advisories/XONIX.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10149">10149</ref><ref source="OSVDB" url="http://www.osvdb.org/5358">5358</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009789">1009789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11382">11382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15873">xonix-privilege-dropping(15873)</ref></refs><vuln_soft><prod name="xonix" vendor="xonix"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0158" published="2004-03-29" seq="2004-0158" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in lbreakout2 allows local users to gain &apos;games&apos; group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2">lbreakout2 &lt; 2.4beta-2 local exploit</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-445"> lbreakout2 -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9712">bid 9712</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15229">LBreakout2 HOME environment variable buffer overflow</ref><ref source="CONFIRM" url="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</ref></refs><vuln_soft><prod name="LBreakout2" vendor="Lgames"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0159" published="2004-03-15" seq="2004-0159" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an &quot;ls&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2">New hsftp packages fix format string vulnerability</ref><ref adv="1" patch="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017737.html">New hsftp packages fix format string vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9715">bid 9715</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15276">hsftp format string attack</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/4029">4029</ref></refs><vuln_soft><prod name="hsftp" vendor="Samhain Labs"><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.9"/><vers num="1.10"/><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0160" published="2004-03-29" seq="2004-0160" severity="High" type="CVE"><desc><descript source="cve">Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-446">synaesthesia -- insecure file creation</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15279">Synaesthesia configuration file symlink attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9713">bid 9713</ref></refs><vuln_soft><prod name="Synaesthesia" vendor="Synaesthesia"><vers num="2.1.0"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0161" published="2004-10-20" seq="2004-0161" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524928232568&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/9274">mime-tools-parameter-encoding(9274)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0162" published="2004-10-20" seq="2004-0162" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517563513776&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17332">mime-rfc822-filtering-bypass(17332)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-0163" published="2004-09-28" seq="2004-0163" severity="Medium" type="CVE"><desc><descript source="cve">Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="corsaire" url="http://www.corsaire.com/advisories/c031120-002.txt">Sygate Secure Enterprise replay issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16945">Sygate Secure Enterprise replay denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215685731675&amp;w=2">20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue</ref></refs><vuln_soft><prod name="Secure Enterprise" vendor="Sygate Technologies"><vers num="3.5MR3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0164" published="2004-03-03" seq="2004-0164" severity="Medium" type="CVE"><desc><descript source="cve">KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2">Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14117">OpenBSD ISAKMP daemon Invalid SPI could allow an attacker to delete IPsec SAs</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc">NetBSD-SA2004-001</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14118">openbsd-isakmp-initialcontact-delete-sa(14118)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9417">9417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval947.html">OVAL947</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref><ref source="BID" url="http://www.securityfocus.com/bid/9416">9416</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947">oval:org.mitre.oval:def:947</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num="all versions"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0165" published="2004-03-15" seq="2004-0165" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref adv="1" patch="1" source="Atstake.com" url="http://www.atstake.com/research/advisories/2004/a022304-1.txt">Mac OS X pppd Format String Vulnerability</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15297">Mac OS X ppp daemon format string attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9730">bid 9730</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/841742">Apple Mac OS X Point-to-Point Protocol daemon (pppd) contains format string vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="OSVDB" url="http://www.osvdb.org/6822">6822</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0166" published="2004-03-15" seq="2004-0166" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to &quot;the display of URLs in the status bar.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14993">Mac OS X Safari Web browser undisclosed security issue</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/194238">Apple Mac OS X Safari fails to properly display URLs in the status bar</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14993">macosx-safari-unknown(14993)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0167" published="2004-03-15" seq="2004-0167" severity="High" type="CVE"><desc><descript source="cve">DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15300">Mac OS X unknown issue in DiskArbitration implementation</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/578886">VU#578886</ref><ref source="BID" url="http://www.securityfocus.com/bid/9731">9731</ref><ref source="OSVDB" url="http://www.osvdb.org/6824">6824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15300">macos-diskarbitration-unknown(15300)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0168" published="2004-03-15" seq="2004-0168" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to &quot;notification logging.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15299">Mac OS X unknown issue in CoreFoundation notification logging</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15299">macos-corefoundation-unknown(15299)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959/">10959</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0169" published="2004-03-15" seq="2004-0169" severity="Medium" type="CVE"><desc><descript source="cve">QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15291">Darwin Streaming Server DESCRIBE request denial of service</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765514003396&amp;w=2">Darwin Streaming Server Remote Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9735">bid 9735</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/460350">Apple Quicktime/Darwin Streaming Server fails to properly parse DESCRIBE requests</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/6826">6826</ref><ref source="OSVDB" url="http://www.osvdb.org/6837">6837</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.3"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0171" published="2004-03-15" seq="2004-0171" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15369">FreeBSD memory buffers (mbufs) denial of service</ref><ref adv="1" patch="1" source="iDefense.com" url="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities">FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9792">bid 9792</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc">FreeBSD-SA-04:04</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395670">VU#395670</ref><ref source="OSVDB" url="http://www.osvdb.org/4124">4124</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.6.2"/><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0172" published="2004-03-15" seq="2004-0172" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2003-October/011610.html">ltrace bug</ref><ref adv="1" source="SecurityTracker.com" url="http://www.securitytracker.com/alerts/2003/Oct/1007896.html">ltrace Heap Overflow May Let Local Users Execute Arbitrary Code With Root Privileges</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/13389">ltrace search_for_command buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/8790">bid 8790</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html">20031008 ltrace bug</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html">20031008 ltrace bug</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1007896">1007896</ref></refs><vuln_soft><prod name="ltrace" vendor="Juan Cespedes"><vers num="0.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0173" published="2004-04-15" seq="2004-0173" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing &quot;..%5C&quot; (dot dot encoded backslash) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apacheweek.com/issues/04-03-12">http://www.apacheweek.com/issues/04-03-12</ref><ref source="CONFIRM" url="http://nagoya.apache.org/bugzilla/show_bug.cgi?id=26152">http://nagoya.apache.org/bugzilla/show_bug.cgi?id=26152</ref><ref adv="1" patch="1" source="Netsys" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017740.html">Apache for cygwin directory traversal vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9733">bid 9733</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15293">Apache for Cygwin dot dot directory traversal</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/10962">10962</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="0.8.11"/><vers num="0.8.14"/><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.5"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0174" published="2004-05-04" seq="2004-0174" severity="Medium" type="CVE"><desc><descript source="cve">Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a &quot;short-lived connection on a rarely-accessed listening socket.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107973894328806&amp;w=2">[ANNOUNCE] Apache HTTP Server 2.0.49 Released</ref><ref adv="1" patch="1" source="The aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066914830552&amp;w=2">TSLSA-2004-0017 - apache</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15540">Apache HTTP Server socket starvation denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">Stronghold 4: New release fixes Apache, mod_ssl, and PHP issues</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1982.html">OVAL1982</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/132110">VU#132110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11170">11170</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref><ref source="BID" url="http://www.securityfocus.com/bid/9921">9921</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009495.html">1009495</ref><ref source="" url="http://www.apache.org/dist/httpd/CHANGES_1.3"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100110.html">OVAL100110</ref><ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110">oval:org.mitre.oval:def:100110</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982">oval:org.mitre.oval:def:1982</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.49" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0175" published="2004-08-18" seq="2004-0175" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9986">OpenSSH SCP Client File Corruption Vulnerability</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_09_kernel.html">[suse-security-announce] SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:009)</ref><ref adv="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831">Vulnerabilidade no comando scp</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147</ref><ref source="CONFIRM" url="http://www.juniper.net/support/security/alerts/adv59739.txt">http://www.juniper.net/support/security/alerts/adv59739.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831">CLSA-2004:831</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html">SuSE-SA:2004:009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-106.html">RHSA-2005:106</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16323">openssh-scp-file-overwrite(16323)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-074.html">RHSA-2005:074</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-165.html">RHSA-2005:165</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-481.html">RHSA-2005:481</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-495.html">RHSA-2005:495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt">SCOSA-2006.11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19243">19243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="OSVDB" url="http://www.osvdb.org/9550">
9550</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.0 p1"/><vers num="3.0"/><vers num="3.0.1 p1"/><vers num="3.0.1"/><vers num="3.0.2 p1"/><vers num="3.0.2"/><vers num="3.1 p1"/><vers num="3.1"/><vers num="3.2"/><vers num="3.2.2 p1"/><vers num="3.2.3 p1"/><vers num="3.3 p1"/><vers num="3.3"/><vers num="3.4 p1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0176" published="2004-05-04" seq="2004-0176" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108007072215742&amp;w=2">Advisory 03/2004: Multiple (13) Ethereal remote overflows</ref><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2">LNSA-#2004-0007: Multiple security problems in Ethereal</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15569">Ethereal multiple dissectors buffer overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-511">DSA-511-1 ethereal -- buffer overflows</ref><ref source="MISC" url="http://security.e-matters.de/advisories/032004.html">http://security.e-matters.de/advisories/032004.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00013.html">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-07.xml">GLSA-200403-07</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-136.html">RHSA-2004:136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-137.html">RHSA-2004:137</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval878.html">OVAL878</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval887.html">OVAL887</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/119876">VU#119876</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/125156">VU#125156</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433596">VU#433596</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/591820">VU#591820</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/644886">VU#644886</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/659140">VU#659140</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/740188">VU#740188</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/864884">VU#864884</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/931588">VU#931588</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11185">11185</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835">CLA-2004:835</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878">oval:org.mitre.oval:def:878</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887">oval:org.mitre.oval:def:887</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref source="OSVDB" url="http://www.osvdb.org/6893">6893</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0177" published="2004-06-01" seq="2004-0177" severity="Medium" type="CVE"><desc><descript source="cve">The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ">http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-126.shtml">O-126</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="BID" url="http://www.securityfocus.com/bid/10152">10152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15867">linux-ext3-info-disclosure(15867)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0178" published="2004-06-01" seq="2004-0178" severity="Low" type="CVE"><desc><descript source="cve">The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">RHSA-2004:413</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-437.html">RHSA-2004:437</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA">http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-193.shtml">O-193</ref><ref source="BID" url="http://www.securityfocus.com/bid/9985">9985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15868">linux-sound-blaster-dos(15868)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0179" published="2004-06-01" seq="2004-0179" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-487">DSA-487</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-157.html">RHSA-2004:157</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1552">FEDORA-2004-1552</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-158.html">RHSA-2004:158</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-159.html">RHSA-2004:159</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-160.html">RHSA-2004:160</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-01.xml">GLSA-200405-01</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-04.xml">GLSA-200405-04</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1065.html">OVAL1065</ref><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html">SuSE-SA:2004:008</ref><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html">SuSE-SA:2004:009</ref><ref adv="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:032">MDKSA-2004:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/10136">10136</ref><ref source="OSVDB" url="http://www.osvdb.org/5365">5365</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11363">11363</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108214147022626&amp;w=2">20040416 void.at - neon format string bugs</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213873203477&amp;w=2">20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065">oval:org.mitre.oval:def:1065</ref></refs><vuln_soft><prod name="Cadaver WebDAV Client" vendor="Cadaver"><vers num="0.22.1"/><vers num="0.22.0"/><vers num="0.21.0"/><vers num="0.20.5"/><vers num="0.20.4"/><vers num="0.20.3"/><vers num="0.20.2"/><vers num="0.20.1"/><vers num="0.20.0"/></prod><prod name="Subversion" vendor="Subversion"><vers num=""/></prod><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.2"/></prod><prod name="Neon Client Library" vendor="Neon"><vers num="0.24.4"/><vers num="0.24.3"/><vers num="0.24.2"/><vers num="0.24.1"/><vers num="0.24"/><vers num="0.23.8"/><vers num="0.23.7"/><vers num="0.23.6"/><vers num="0.23.5"/><vers num="0.23.4"/><vers num="0.23.3"/><vers num="0.23.2"/><vers num="0.23.1"/><vers num="0.23"/><vers num="0.19.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0180" published="2004-06-01" seq="2004-0180" severity="Low" type="CVE"><desc><descript source="cve">The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-486">DSA-486</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc">FreeBSD-SA-04:07</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:028">MDKSA-2004:028</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-153.html">RHSA-2004:153</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-154.html">RHSA-2004:154</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:028">MDKSA-2004:028</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1042.html">OVAL1042</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-13.xml">GLSA-200404-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11368">11368</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11371">11371</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11374">11374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11375">11375</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11377">11377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11380">11380</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11391">11391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11400">11400</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11405">11405</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11548">11548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15864">cvs-rcs-create-files(15864)</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2">FEDORA-2004-1620</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181">SSA:2004-108-02</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042">oval:org.mitre.oval:def:1042</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:028">MDKSA-2004:028</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0181" published="2004-06-01" seq="2004-0181" severity="Low" type="CVE"><desc><descript source="cve">The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="Linux Security" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="BID" url="http://www.securityfocus.com/bid/10143">10143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15902">linux-jfs-info-disclosure(15902)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0182" published="2004-06-01" seq="2004-0182" severity="Medium" type="CVE"><desc><descript source="cve">Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-156.html">RHSA-2004:156</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.0.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0183" published="2004-05-04" seq="2004-0183" severity="Medium" type="CVE"><desc><descript source="cve">TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI&apos;s, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-478">DSA-478-1 tcpdump -- denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0017.html">http://www.rapid7.com/advisories/R7-0017.html</ref><ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt">http://www.tcpdump.org/tcpdump-changes.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1468">FEDORA-2004-1468</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-219.html">RHSA-2004:219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15680">tcpdump-isakmp-delete-bo(15680)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10003">10003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval972.html">OVAL972</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240790">VU#240790</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009593">1009593</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11258">11258</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11320">11320</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0015">2004-0015</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972">oval:org.mitre.oval:def:972</ref></refs><vuln_soft><prod name="TCPDUMP" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0184" published="2004-05-04" seq="2004-0184" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-478">DSA-478-1 tcpdump -- denial of service</ref><ref adv="1" source="rapid7" url="http://www.rapid7.com/advisories/R7-0017.html">Rapid7 Advisory R7-0017</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15602">emil format string attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref><ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt">http://www.tcpdump.org/tcpdump-changes.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1468">FEDORA-2004-1468</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-219.html">RHSA-2004:219</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/492558">VU#492558</ref><ref source="BID" url="http://www.securityfocus.com/bid/10004">10004</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval976.html">OVAL976</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15679">tcpdump-isakmp-integer-underflow(15679)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009593">1009593</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11258">11258</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0015">2004-0015</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976">oval:org.mitre.oval:def:976</ref></refs><vuln_soft><prod name="TCPDUMP" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0185" published="2004-03-15" seq="2004-0185" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</ref><ref adv="1" patch="1" source="Securiteam.com" url="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html">Wu-FTPd SKEY Stack Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/13518">WU-FTPD SKEY authentication buffer overflow</ref><ref patch="1" source="Ftpd.org" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-457">DSA-457-1 wu-ftpd -- several vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-096.html">Updated wu-ftpd package fixes security issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/8893">8893</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0186" published="2004-03-15" seq="2004-0186" severity="High" type="CVE"><desc><descript source="cve">smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2">Samba 3.x + kernel 2.6.x local root vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15131">Samba smbmnt allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9619">bid 9619</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-463">DSA-463-1 samba -- privilege escalation</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3916">3916</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0"/><vers num="3.0.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0187" published="2004-03-15" reject="1" seq="2004-0187" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0188" published="2004-03-15" seq="2004-0188" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2">Calife heap corrupt / potential local root exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9756">bid 9756</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15335">Calife long password buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-461">DSA-461-1 calife -- buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9776">9776</ref></refs><vuln_soft><prod name="Calife" vendor="Calife"><vers num="2.8.4 c"/><vers num="2.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0189" published="2004-03-15" seq="2004-0189" severity="High" type="CVE"><desc><descript source="cve">The &quot;%xx&quot; URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL (&quot;%00&quot;) characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Squid-cache.org" url="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt"> Squid Proxy Cache Security Update Advisory SQUID-2004:1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9778">bid 9778</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15366">Squid url_regex ACL bypass</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838">CLA-2004:838</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-474">DSA-474</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-11.xml">GLSA-200403-11</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025">MDKSA-2004:025</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-133.html">RHSA-2004:133</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-134.html">RHSA-2004:134</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt">SCOSA-2005.16</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</ref><ref source="OSVDB" url="http://www.osvdb.org/5916">5916</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877">oval:org.mitre.oval:def:877</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941">oval:org.mitre.oval:def:941</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.0 PATCH2"/><vers num="2.1 PATCH2"/><vers num="2.3 STABLE5"/><vers num="2.4 STABLE7"/><vers num="2.4"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0190" published="2004-03-15" seq="2004-0190" severity="High" type="CVE"><desc><descript source="cve">Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator&apos;s local system or in a proxy, which allows attackers to steal the password and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017414.html">Symantec, Firewall/VPN Appliance, model 200 leak of security</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9784">bid 9784</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15212">Symantec Firewall/VPN caches administrative password in plain text</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2"> Symantec FireWall/VPN Appliance model 200 leak of security</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref><ref source="OSVDB" url="http://www.osvdb.org/4117">4117</ref></refs><vuln_soft><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="100"/><vers num="200"/><vers num="200R"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2004-0191" published="2004-03-15" seq="2004-0191" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Grou" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2">Sandblad #13: Cross-domain exploit on zombie document with event</ref><ref adv="1" source="Mozilla.org" url="http://bugzilla.mozilla.org/show_bug.cgi?id=227417">Cross-domain exploit on zombie document with event handlers</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9747">bid 9747</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15322">Mozilla event handler cross-site scripting</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-110.html">RHSA-2004:110</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-112.html">RHSA-2004:112</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2">SSRT4722</ref><ref source="OSVDB" url="http://www.osvdb.org/4062">4062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874">oval:org.mitre.oval:def:874</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937">oval:org.mitre.oval:def:937</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="0.8"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.35"/><vers num="0.9.48"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0192" published="2004-03-15" seq="2004-0192" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2">Symantec Gateway Security Management Service Cross Site Scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9755">bid 9755</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15330">Symantec Gateway Security error page cross-site scripting</ref></refs><vuln_soft><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0193" published="2004-03-15" seq="2004-0193" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Eeye.com" url="http://www.eeye.com/html/Research/Upcoming/20040213.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/165">Vulnerability in SMB Parsing in ISS Products</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/150326">Internet Security Systems&apos; BlackICE and RealSecure contain a heap overflow in the processing of SMB packets</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040226.html">AD20040226</ref><ref source="BID" url="http://www.securityfocus.com/bid/9752">9752</ref><ref source="OSVDB" url="http://www.osvdb.org/4072">4072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10988">10988</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15207">pam-smb-protocol-bo(15207)</ref></refs><vuln_soft><prod name="Proventia" vendor="Internet Security Systems"><vers num="A Series XPU 20.15"/><vers num="G Series XPU 22.3"/><vers num="M Series XPU 1.3"/></prod><prod name="RealSecure Guard" vendor="Internet Security Systems"><vers num="3.6ecb"/></prod><prod name="RealSecure Server Sensor" vendor="Internet Security Systems"><vers num="7.0 XPU20.16"/></prod><prod name="RealSecure Desktop" vendor="Internet Security Systems"><vers num="3.6eca"/><vers num="7.0ebg"/><vers num="7.0epk"/><vers num="3.6ecf"/></prod><prod name="BlackICE Server Protection" vendor="Internet Security Systems"><vers num="3.6cbz"/></prod><prod name="RealSecure Sentry" vendor="Internet Security Systems"><vers num="3.6ecf"/></prod><prod name="RealSecure Network" vendor="Internet Security Systems"><vers num="7.0 XPU20.15"/></prod><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6cbd"/></prod><prod name="BlackICE Agent Server" vendor="Internet Security Systems"><vers num="3.6eca"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0194" published="2004-03-29" seq="2004-0194" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15384">Adobe Acrobat Reader XFDF buffer overflow</ref><ref adv="1" patch="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/adobexfdf.txt">Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9802">bid 9802</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/4135">4135</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0197" published="2004-06-01" seq="2004-0197" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-014.mspx">MS04-014</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-014.asp">MS04-014</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval968.html">OVAL968</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/740716">VU#740716</ref><ref source="BID" url="http://www.securityfocus.com/bid/10112">10112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15703">msjet-query-execute-code(15703)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968">oval:org.mitre.oval:def:968</ref></refs><vuln_soft><prod name="Jet" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0199" published="2004-06-14" seq="2004-0199" severity="Medium" type="CVE"><desc><descript source="cve">Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10321">bugtraq id 10321</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16095">win-hcp-code-execution(16095)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/484814">VU#484814</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx">MS04-015</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437759930820&amp;w=2">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref><ref source="MISC" url="http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt">http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1008.html">OVAL1008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1032.html">OVAL1032</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108430407801825&amp;w=2">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008">oval:org.mitre.oval:def:1008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032">oval:org.mitre.oval:def:1032</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2004-0200" published="2004-09-28" seq="2004-0200" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IBM" url="http://www.microsoft.com/technet/security/bulletin/ms04-028.asp">Microsoft Security Bulletin MS04-028</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16304">Microsoft Windows JPEG buffer overflow</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-260A.html">TA04-260A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/297462">VU#297462</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1105.html">OVAL1105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1721.html">OVAL1721</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2706.html">OVAL2706</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3038.html">OVAL3038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3082.html">OVAL3082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3320.html">OVAL3320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3810.html">OVAL3810</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3881.html">OVAL3881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4003.html">OVAL4003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4216.html">OVAL4216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4307.html">OVAL4307</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524346729948&amp;w=2">20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105">oval:org.mitre.oval:def:1105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721">oval:org.mitre.oval:def:1721</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706">oval:org.mitre.oval:def:2706</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038">oval:org.mitre.oval:def:3038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082">oval:org.mitre.oval:def:3082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320">oval:org.mitre.oval:def:3320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810">oval:org.mitre.oval:def:3810</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881">oval:org.mitre.oval:def:3881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003">oval:org.mitre.oval:def:4003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216">oval:org.mitre.oval:def:4216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307">oval:org.mitre.oval:def:4307</ref></refs><vuln_soft><prod name="OneNote" vendor="Microsoft"><vers num="2003"/></prod><prod name="Visual J#" vendor="Microsoft"><vers edition=".NET Standard" num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers edition="Student_Teacher" num="2003"/><vers num="XP SP3"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Producer" vendor="Microsoft"><vers edition="Office_PowerPoints" num="gold"/></prod><prod name="Picture It" vendor="Microsoft"><vers num="2002"/><vers num="7.0"/><vers num="9"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Gold" num="2002"/><vers edition="Gold" num="2003"/></prod><prod name="Word" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Project" vendor="Microsoft"><vers num="2002 SP1"/><vers num="2003"/></prod><prod name="InfoPath" vendor="Microsoft"><vers num="2003"/></prod><prod name="Digital Image Suite" vendor="Microsoft"><vers num="9"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Visual C#" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name=".NET Framework" vendor="Microsoft"><vers edition="SDK" num="1.0 SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="Tablet PC" num="SP1"/><vers edition="SP1" num="64-bit"/><vers num="64-bit Version 2003"/></prod><prod name="Visual C++" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name="Digital Image Pro" vendor="Microsoft"><vers num="7.0"/><vers num="9"/></prod><prod name="Visio" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2003"/></prod><prod name="PowerPoint" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Greetings" vendor="Microsoft"><vers num="2002"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0201" published="2004-08-06" seq="2004-0201" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16586">Microsoft Windows HTML Help could allow execution of code</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/920060">Microsoft Windows HTML Help component fails to properly validate input data</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx">Vulnerability in HTML Help Could Allow Code Execution (840315)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10705">Microsoft Windows HTML Help Heap Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html">20040714 HtmlHelp - .CHM File Heap Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1503.html">OVAL1503</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1530.html">OVAL1530</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2155.html">OVAL2155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3179.html">OVAL3179</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503">oval:org.mitre.oval:def:1503</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530">oval:org.mitre.oval:def:1530</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155">oval:org.mitre.oval:def:2155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179">oval:org.mitre.oval:def:3179</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0202" published="2004-08-06" seq="2004-0202" severity="Medium" type="CVE"><desc><descript source="cve">IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-016.mspx">Microsoft Security Bulletin MS04-016</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10487">Microsoft DirectX DirectPlay Remote Malformed Packet Denial Of Service Vulnerability</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-016.asp">MS04-016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1027.html">OVAL1027</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2190.html">OVAL2190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2413.html">OVAL2413</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2516.html">OVAL2516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2705.html">OVAL2705</ref><ref source="OSVDB" url="http://www.osvdb.org/6742">6742</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11802">11802</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16306">ms-directx-directplay-dos(16306)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027">oval:org.mitre.oval:def:1027</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190">oval:org.mitre.oval:def:2190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413">oval:org.mitre.oval:def:2413</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516">oval:org.mitre.oval:def:2516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705">oval:org.mitre.oval:def:2705</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="DirectX" vendor="Microsoft"><vers num="7.0a"/><vers num="7.0"/><vers num="7.1"/><vers num="8.0a"/><vers num="8.0"/><vers num="8.1b"/><vers num="8.1a"/><vers num="8.1"/><vers num="8.2"/><vers num="9.0b"/><vers num="9.0a"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0203" published="2004-11-23" seq="2004-0203" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx">Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842436)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/948750">VU#948750</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2016.html">OVAL2016</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16583">exchange-owa-execute-code(16583)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016">oval:org.mitre.oval:def:2016</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5 SP4"/><vers num="5.5 SP3"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0204" published="2004-08-06" seq="2004-0204" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via &quot;..&quot; sequences in the dynamicimag argument to crystalimagehandler.aspx.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10260">Business Objects Crystal Reports Web Form Viewer Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16044">Crystal Reports file deletion</ref><ref source="CONFIRM" url="http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp">http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-017.asp">MS04-017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1157.html">OVAL1157</ref><ref source="OSVDB" url="http://www.osvdb.org/6748">6748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11800">11800</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2">20040502 Crystal Reports Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157">oval:org.mitre.oval:def:1157</ref></refs><vuln_soft><prod name="Crystal Enterprise" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="Crystal Enterprise RAS for UNIX" vendor="businessobjects"><vers num="8.5"/></prod><prod name="Crystal Reports" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Gold" num="2003"/></prod><prod name="Outlook" vendor="Microsoft"><vers edition="Business Contact Manager" num="2003"/></prod><prod name="Business Solutions CRM" vendor="Microsoft"><vers num="1.2"/></prod><prod name="Crystal Enterprise Java SDK" vendor="businessobjects"><vers num="8.5"/></prod><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="J Builder" vendor="Borland Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0205" published="2004-08-06" seq="2004-0205" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10706/">Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/717748">Microsoft Internet Information Server (IIS) 4.0 contains a buffer overflow in the redirect function</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16578">Microsoft Internet Information Server (IIS) redirect buffer overflow</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-021.asp">MS04-021</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-179.shtml">O-179</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2204.html">OVAL2204</ref><ref source="BID" url="http://www.securityfocus.com/bid/10706">10706</ref><ref source="OSVDB" url="http://www.osvdb.org/7799">7799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12061">12061</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204">oval:org.mitre.oval:def:2204</ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0206" published="2004-11-03" seq="2004-0206" severity="High" type="CVE"><desc><descript source="cve">Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-031.asp">Vulnerability in NetDDE Could Allow Remote Code Execution (841533</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/640488">Microsoft Windows contains an unchecked buffer in the NetDDE services</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16556">Microsoft Windows NetDDE buffer overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17657">Microsoft Internet Information Server MS04-031 patch is not installed</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1852.html">OVAL1852</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2394.html">OVAL2394</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3120.html">OVAL3120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3242.html">OVAL3242</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4592.html">OVAL4592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5074.html">OVAL5074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6788.html">OVAL6788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12803/">12803</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786703930674&amp;w=2">20041013 Microsoft Windows NetDDE Service Buffer Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852">oval:org.mitre.oval:def:1852</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394">oval:org.mitre.oval:def:2394</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120">oval:org.mitre.oval:def:3120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242">oval:org.mitre.oval:def:3242</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592">oval:org.mitre.oval:def:4592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074">oval:org.mitre.oval:def:5074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788">oval:org.mitre.oval:def:6788</ref><ref source="BID" url="http://www.securityfocus.com/bid/11372">11372</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0207" published="2004-11-03" seq="2004-0207" severity="Low" type="CVE"><desc><descript source="cve">&quot;Shatter&quot; style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16579">Microsoft Windows Window Management API allows elevated privileges</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/218526">Microsoft Windows contains vulnerability in Window Management API</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109777417922695&amp;w=2">20041013 SetWindowLong Shatter Attacks</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0208" published="2004-11-03" seq="2004-0208" severity="High" type="CVE"><desc><descript source="cve">The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16580">Microsoft Windows Virtual DOS Machine (VDM) allows elevated privileges</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/910998">Microsoft Windows kernel fails to properly handle invalid opcodes used in DOS emulation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1751.html">OVAL1751</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3161.html">OVAL3161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3953.html">OVAL3953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4316.html">OVAL4316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4762.html">OVAL4762</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109772135404427&amp;w=2">20041013 EEYE: Windows VDM #UD Local Privilege Escalation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751">oval:org.mitre.oval:def:1751</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161">oval:org.mitre.oval:def:3161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953">oval:org.mitre.oval:def:3953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316">oval:org.mitre.oval:def:4316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762">oval:org.mitre.oval:def:4762</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0209" published="2004-11-03" seq="2004-0209" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve &quot;an unchecked buffer.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829067325779&amp;w=2">[EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16581">Microsoft Windows Enhanced Metafile (EMF) buffer overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1872.html">OVAL1872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2114.html">OVAL2114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2428.html">OVAL2428</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/806278">VU#806278</ref><ref source="BID" url="http://www.securityfocus.com/bid/11375">11375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17658">win-ms04032-patch(17658)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872">oval:org.mitre.oval:def:1872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114">oval:org.mitre.oval:def:2114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428">oval:org.mitre.oval:def:2428</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0210" published="2004-08-06" seq="2004-0210" severity="High" type="CVE"><desc><descript source="cve">The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10710/">Microsoft Windows POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/647436">Microsoft Windows contains a buffer overflow in the POSIX subsystem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16590">Microsoft Windows POSIX buffer overflow allows local attacker to gain privileges</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-020.mspx">Vulnerability in POSIX Could Allow Code Execution (841872)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-020.asp">MS04-020</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2166.html">OVAL2166</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2847.html">OVAL2847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166">oval:org.mitre.oval:def:2166</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847">oval:org.mitre.oval:def:2847</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6 alpha"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Workstation 4.0 SP6a"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0211" published="2004-11-03" seq="2004-0211" severity="Low" type="CVE"><desc><descript source="cve">The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16582">Microsoft Windows Server 2003 kernel CPU denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/119262">Microsoft Windows kernel fails to reset values in CPU data structures</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4893.html">OVAL4893</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893">oval:org.mitre.oval:def:4893</ref></refs><vuln_soft><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0212" published="2004-08-06" seq="2004-0212" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10708">Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16591">Microsoft Windows Task Scheduler buffer overflow</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-022.mspx">Vulnerability in Task Scheduler Could Allow Code Execution (841873)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/mstaskjob.txt">http://www.ngssoftware.com/advisories/mstaskjob.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981403025596&amp;w=2">20040714 Unchecked buffer in mstask.dll</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-022.asp">MS04-022</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/228028">VU#228028</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1344.html">OVAL1344</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1781.html">OVAL1781</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1964.html">OVAL1964</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3428.html">OVAL3428</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12060">12060</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981273009250&amp;w=2">20040714 Microsoft Windows Task Scheduler &apos;.job&apos; Stack Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344">oval:org.mitre.oval:def:1344</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781">oval:org.mitre.oval:def:1781</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964">oval:org.mitre.oval:def:1964</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428">oval:org.mitre.oval:def:3428</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Server 4.0 SP6a"/><vers num="Workstation 4.0 SP6a"/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0213" published="2004-08-06" seq="2004-0213" severity="High" type="CVE"><desc><descript source="cve">Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a &quot;Shatter&quot; style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16592">Microsoft Windows Utility Manager gain privileges</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108975382413405&amp;w=2">Microsoft Window Utility Manager Local Elevation of Privileges</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-019.asp">Vulnerability in Utility Manager Could Allow Code Execution (842526)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10707/">Microsoft Windows Utility Manager Local Privilege Escalation Variant Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/868580">VU#868580</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2495.html">OVAL2495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495">oval:org.mitre.oval:def:2495</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0214" published="2004-11-03" seq="2004-0214" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="seclists.org" url="http://seclists.org/lists/bugtraq/2004/Apr/0322.html">Bugtraq: Microsoft&apos;s Explorer and Internet Explorer long share name buffer overflow.</ref><ref adv="1" source="seclists.org" url="http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html">FullDisclosure: Microsoft&apos;s Explorer and Internet Explorer long share name buffer overflow.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15956">Microsoft Windows long file share name buffer overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17662">Microsoft Windows MS04-037 patch is not installed</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;en-us;322857">322857</ref><ref source="BID" url="http://www.securityfocus.com/bid/10213">10213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1601.html">OVAL1601</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1749.html">OVAL1749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2638.html">OVAL2638</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4345.html">OVAL4345</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5307.html">OVAL5307</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11482/">11482</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx">MS04-037</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/616200">VU#616200</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011647">1011647</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html">http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html</ref><ref source="OSVDB" url="http://www.osvdb.org/5687">5687</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601">oval:org.mitre.oval:def:1601</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749">oval:org.mitre.oval:def:1749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638">oval:org.mitre.oval:def:2638</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345">oval:org.mitre.oval:def:4345</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307">oval:org.mitre.oval:def:5307</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2900"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0215" published="2004-08-06" seq="2004-0215" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10711">Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16585">Microsoft Outlook Express malformed email header denial of service</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-018.mspx">Cumulative Security Update for Outlook Express (823353)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/869640">Microsoft Outlook Express fails to properly validate malformed e-mail headers</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-018.asp">MS04-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1950.html">OVAL1950</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2137.html">OVAL2137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2657.html">OVAL2657</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3376.html">OVAL3376</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950">oval:org.mitre.oval:def:1950</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137">oval:org.mitre.oval:def:2137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657">oval:org.mitre.oval:def:2657</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376">oval:org.mitre.oval:def:3376</ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0216" published="2004-11-03" seq="2004-0216" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760693512754&amp;w=2">Microsoft Internet Explorer Install Engine Control Buffer Overflow</ref><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="www.us-cert.gov" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">Multiple Vulnerabilities in Microsoft Internet Explorer</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/637760">www.kb.cert.org</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17620">Microsoft Internet Explorer InstallEngineCtl SetCifFile buffer overflow</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/msinsengfull.txt">http://www.ngssoftware.com/advisories/msinsengfull.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5316.html">OVAL5316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5329.html">OVAL5329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6100.html">OVAL6100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6600.html">OVAL6600</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7717.html">OVAL7717</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7865.html">OVAL7865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17651">ie-ms04038-patch(17651)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616383332055&amp;w=2">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110619893620517&amp;w=2">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316">oval:org.mitre.oval:def:5316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329">oval:org.mitre.oval:def:5329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100">oval:org.mitre.oval:def:6100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600">oval:org.mitre.oval:def:6600</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717">oval:org.mitre.oval:def:7717</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865">oval:org.mitre.oval:def:7865</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-0217" published="2004-04-15" seq="2004-0217" severity="Low" type="CVE"><desc><descript source="cve">The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694800908164&amp;w=2">Possible race condition in Symantec AntiVirus Scan Engine for Red</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15215">Symantec Antivirus Scan Engine race condition</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9662">bid 9662</ref></refs><vuln_soft><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers edition="Red Hat Linux" num="4.0"/><vers edition="Red Hat Linux" num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0218" published="2004-05-04" seq="2004-0218" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15518">OpenBSD ISAKMP zero-length payload denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349113">VU#349113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11156">11156</ref><ref source="BID" url="http://www.securityfocus.com/bid/10028">10028</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0219" published="2004-05-04" seq="2004-0219" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15518">OpenBSD ISAKMP zero-length payload denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15628">OpenBSD ISAKMP IPSEC SA payload denial of service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html">20040317 015: RELIABILITY FIX: March 17, 2004</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/785945">VU#785945</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0220" published="2004-05-04" seq="2004-0220" severity="High" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via a an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15629">OpenBSD ISAKMP Cert Request payload integer underflow</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/223273">VU#223273</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0221" published="2004-05-04" seq="2004-0221" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref adv="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15630">OpenBSD ISAKMP delete payload denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/524497">VU#524497</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0222" published="2004-05-04" seq="2004-0222" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15519">OpenBSD ISAKMP memory leak</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/996177">VU#996177</ref><ref source="BID" url="http://www.securityfocus.com/bid/10032">10028</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0224" published="2004-04-15" seq="2004-0224" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code &quot;when Unicode character is out of BMP range.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SourceForge" url="http://sourceforge.net/project/shownotes.php?release_id=5767">Courier Mail Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9845">bid 9845</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/11087/">Courier Japanese Codeset Conversion Buffer Overflow Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15434">courier-codeset-converter-bo(15434)</ref></refs><vuln_soft><prod name="SqWebMail" vendor="Double Precision Incorporated"><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.6 .0"/><vers num="3.6.1"/><vers num="3.6.2"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Courier-IMAP" vendor="Inter7"><vers num="1.6"/><vers num="1.7"/><vers num="2.0.0"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2.0"/><vers num="2.2.1"/></prod><prod name="Courier MTA" vendor="Double Precision Incorporated"><vers num="0.43"/><vers num="0.43.1"/><vers num="0.43.2"/><vers num="0.44"/><vers num="0.44.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0226" published="2004-08-18" seq="2004-0226" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">Updated mc packages resolve several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16016">Midnight Commander allows local elevation of privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-497">DSA-497</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-21.xml">GLSA-200405-21</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0227" published="2004-06-14" seq="2004-0227" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ZoneMinder" url="http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16136">zoneminder-zms-bo(16136)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10340">bugtraq 10340</ref></refs><vuln_soft><prod name="ZoneMinder" vendor="Triornis"><vers num="1.17.0"/><vers num="1.17.1"/><vers num="1.17.2"/><vers num="1.18.0"/><vers num="1.18.1"/><vers num="1.19.0"/><vers num="1.19.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0228" published="2004-08-18" seq="2004-0228" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/archives/fedora-announce-list/2004-April/msg00010.html">[SECURITY] Updated kernel packages fix security issues.</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:050">MDKSA-2004:050</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11429">11429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11486">11486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11491">11491</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11683">11683</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15951">linux-cpufreq-info-disclosure(15951)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-111.shtml">FEDORA-2004-111</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:050">MDKSA-2004:050</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0229" published="2004-08-18" seq="2004-0229" severity="Medium" type="CVE"><desc><descript source="cve">The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10211">Linux kernel Framebuffer Code Unspecified Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15974">Linux kernel framebuffer undisclosed issue</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0230" published="2004-08-18" seq="2004-0230" severity="Medium" type="CVE"><desc><descript source="cve">TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10183">Multiple Vendor TCP Sequence Number Approximation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15886">TCP spoofed reset denial of service</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-111A.html">Vulnerabilities in TCP</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc">20040403-01-A</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml">20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco Products</ref><ref source="CONFIRM" url="http://www.juniper.net/support/alert.html">http://www.juniper.net/support/alert.html</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc">NetBSD-SA2004-006</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt">SCOSA-2005.3</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt">SCOSA-2005.9</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt">SCOSA-2005.14</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/415294">VU#415294</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/236929/index.htm">http://www.uniras.gov.uk/vuls/2004/236929/index.htm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108302060014745&amp;w=2">20040425 Perl code exploting TCP not checking RST ACK.</ref><ref source="OSVDB" url="http://www.osvdb.org/4030">4030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11440">11440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11458">11458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4791.html">OVAL4791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2689.html">OVAL2689</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3508.html">OVAL3508</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108506952116653&amp;w=2">SSRT4696</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx">MS06-064</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3983">ADV-2006-3983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22341">22341</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded">HPSBST02161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791">oval:org.mitre.oval:def:4791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689">oval:org.mitre.oval:def:2689</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508">oval:org.mitre.oval:def:3508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270">oval:org.mitre.oval:def:270</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0231" published="2004-08-18" seq="2004-0231" severity="Low" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to &quot;Insecure temporary file and directory creations.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-21.xml"> Gentoo Linux Security Advisory</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16020">Midnight Commander creates insecure files</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-497">DSA-497-1 mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">RHSA-2004:172</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0232" published="2004-08-18" seq="2004-0232" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16021">Midnight Commander format string</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">Updated mc packages fix vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-497">DSA-497</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">RHSA-2004:172</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-21.xml">GLSA-200405-21</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0233" published="2004-08-18" seq="2004-0233" severity="Low" type="CVE"><desc><descript source="cve">Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10178">UTempter Multiple Local Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15904">Utempter symlink attack</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-174.html">Updated utempter package fixes vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:031">MDKSA-2004:031</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-175.html">RHSA-2004:175</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-05.xml">GLSA-200405-05</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval979.html">OVAL979</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404389">SSA:2004-110</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979">oval:org.mitre.oval:def:979</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:031">MDKSA-2004:031</ref></refs><vuln_soft><prod name="utempter" vendor="utempter"><vers num="0.5.2"/><vers num="0.5.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2004-0234" published="2004-08-18" seq="2004-0234" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10243">Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16012">LHA multiple buffer overflows</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2">[Ulf Harnhammar]: LHA Advisory + Patch</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html">20040501 LHa buffer overflows and directory traversal problems</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html">20040502 Lha local stack overflow Proof Of Concept Code</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-515">DSA-515</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-178.html">RHSA-2004:178</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-179.html">RHSA-2004:179</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-02.xml">GLSA-200405-02</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html">FEDORA-2004-119</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval977.html">OVAL977</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840">CLA-2004:840</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html">20060403 Barracuda LHA archiver security bug leads to remote compromise</ref><ref source="" url="http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1220">ADV-2006-1220</ref><ref source="OSVDB" url="http://www.osvdb.org/5753">5753</ref><ref source="OSVDB" url="http://www.osvdb.org/5754">5754</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015866">1015866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19514">19514</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977">oval:org.mitre.oval:def:977</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.20"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2003"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers num="2003"/><vers num="2004"/><vers edition="Client Security" num="5.5"/><vers edition="Client Security" num="5.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Workstations" num="4.51"/><vers edition="Linux Workstations" num="4.52"/><vers edition="MIMESweeper" num="5.41"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MS Exchange" num="6.21"/><vers edition="Samba Servers" num="4.60"/><vers edition="Windows Servers" num="5.41"/><vers edition="Windows Servers" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Workstations" num="5.42"/></prod><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14"/><vers num="1.15"/><vers num="1.17"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod><prod name="Iha" vendor="Red Hat"><vers edition="i386" num="1.14i_9"/></prod><prod name="F-Secure for Firewalls" vendor="F-Secure"><vers num="6.20"/></prod><prod name="WinZip" vendor="WinZip"><vers num="9.0"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6 SP1"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/></prod><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.31"/><vers num="6.32"/></prod><prod name="CGPMcAfee" vendor="Stalker"><vers num="3.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0235" published="2004-08-18" seq="2004-0235" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes (&quot;//absolute/path&quot;).</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10243">Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16013">LHA directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2">[Ulf Harnhammar]: LHA Advisory + Patch</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html">20040501 LHa buffer overflows and directory traversal problems</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-515">DSA-515</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-178.html">RHSA-2004:178</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-179.html">RHSA-2004:179</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-02.xml">GLSA-200405-02</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html">FEDORA-2004-119</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval978.html">OVAL978</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840">CLA-2004:840</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978">oval:org.mitre.oval:def:978</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.20"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2003"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers num="2003"/><vers num="2004"/><vers edition="Client Security" num="5.5"/><vers edition="Client Security" num="5.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Workstations" num="4.51"/><vers edition="Linux Workstations" num="4.52"/><vers edition="MIMESweeper" num="5.41"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MS Exchange" num="6.21"/><vers edition="Samba Servers" num="4.60"/><vers edition="Windows Servers" num="5.41"/><vers edition="Windows Servers" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Workstations" num="5.42"/></prod><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14"/><vers num="1.15"/><vers num="1.17"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod><prod name="Iha" vendor="Red Hat"><vers edition="i386" num="1.14i_9"/></prod><prod name="F-Secure for Firewalls" vendor="F-Secure"><vers num="6.20"/></prod><prod name="WinZip" vendor="WinZip"><vers num="9.0"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6 SP1"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/></prod><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.31"/><vers num="6.32"/></prod><prod name="CGPMcAfee" vendor="Stalker"><vers num="3.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0236" published="2004-11-23" seq="2004-0236" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9884">SteelID thePhotoTool Login.ASP SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15007">thePHOTOtool login.asp script SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107576894019530&amp;w=2">thePHOTOtool SQL Injection Vulnerability</ref></refs><vuln_soft><prod name="thePhotoTool" vendor="SteelID"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0237" published="2004-11-23" seq="2004-0237" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9540">Aprox Portal File Disclosure Vulnerability</ref><ref adv="1" source="CERT" url="http://xforce.iss.net/xforce/xfdb/15014">Aprox Portal File Disclosure Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577555527321&amp;w=2"> Directory Traversal in Aprox PHP Portal.</ref><ref source="OSVDB" url="http://www.osvdb.org/10859">10859</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008915">1008915</ref></refs><vuln_soft><prod name="Aprox Portal" vendor="Aprox Portal"><vers num="3.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0238" published="2004-11-23" seq="2004-0238" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9550">0verkill Game Client Multiple Local Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14999">Overkill client has multiple buffer overflows</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577335424509&amp;w=2">0verkill - little simple vulnerability.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html">20040202 0verkill - little simple vulnerability.</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5AP010KC0C.html">http://www.securiteam.com/securitynews/5AP010KC0C.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15000">overkill-server-parsecommandline-bo(15000)</ref></refs><vuln_soft><prod name="0verkill" vendor="0verkill"><vers num="0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0239" published="2004-11-23" seq="2004-0239" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9557">All Enthusiast Photopost PHP Pro SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15008">PhotoPost PHP Pro SQL injection</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5KP010UC0W.html">http://www.securiteam.com/securitynews/5KP010UC0W.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582512023998&amp;w=2">20040202 ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0240" published="2004-11-23" seq="2004-0240" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15033">X-Cart &quot;dot dot&quot; directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2"> X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0241" published="2004-11-23" seq="2004-0241" severity="High" type="CVE"><desc><descript source="cve">X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9560">Qualiteam X-Cart Remote Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15034">X-Cart perl_binary variable command execution</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2"> X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0242" published="2004-11-23" seq="2004-0242" severity="Medium" type="CVE"><desc><descript source="cve">X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/9563">Qualiteam X-Cart Multiple Remote Information Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15036">X-Cart general.php information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2">X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0243" published="2004-11-23" seq="2004-0243" severity="Medium" type="CVE"><desc><descript source="cve">AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107583269206044&amp;w=2"> Re: sqwebmail web login</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html">20040206 AIX password enumeration possible</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15172">aix-password-enumeration(15172)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-20" name="CVE-2004-0244" published="2004-11-23" seq="2004-0244" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9562">Cisco IOS MSFC2 Malformed Layer 2 Frame Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15013">Cisco 6000, 6500, and 7600 series systems frame containing a packet denial of service</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml">Cisco Security Advisory: Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/810062">VU#810062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10780">10780</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1 E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0245" published="2004-11-23" seq="2004-0245" severity="Medium" type="CVE"><desc><descript source="cve">Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9576/">Web Crossing Web Server Component Remote Denial Of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586518120516&amp;w=2">Web Crossing 4.x/5.x Denial of Service Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9576">9576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15022">webcrossing-contentlength-post-dos(15022)</ref></refs><vuln_soft><prod name="Web Crossing" vendor="Web Crossing Inc"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0246" published="2004-11-23" seq="2004-0246" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9536">Laurent Adda Les Commentaires PHP Script Multiple Module File Include Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15010">Les Commentaires multiple PHP file include</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584083719763&amp;w=2"> Les Commentaires (PHP) Include file</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10768/">10768</ref></refs><vuln_soft><prod name="Les Commentaires" vendor="Laurent Adda"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0247" published="2004-11-23" seq="2004-0247" severity="Medium" type="CVE"><desc><descript source="cve">The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9567">Cauldron Chaser Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15031">Chaser memory denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584109420084&amp;w=2">Remote crash of Chaser game &lt;= 1.50</ref></refs><vuln_soft><prod name="Chaser Server" vendor="Cauldron"><vers num="1.4.9"/><vers num="1.5"/></prod><prod name="Chaser Client" vendor="Cauldron"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0248" published="2004-11-23" seq="2004-0248" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
PHPX, PHPX, 3.2.4</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9569">PHPX Multiple Vulnerabilities</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15050">PHPX subject HTML injection</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15051">PHPX main.inc.php and help.inc.php cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2">Multiple Vulnerabilities in PHPX</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10797/">10797</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0249" published="2004-11-23" seq="2004-0249" severity="High" type="CVE"><desc><descript source="cve">PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie&apos;s PXL variable to reference another userID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9569">PHPX Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15052">PHPX could allow an attacker to modify cookie to hijack another user&apos;s account</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2">   Multiple Vulnerabilities in PHPX</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html">20040316 PHPX 2.x - 3.2.4</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10797/">10797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15512">phpx-session-hijack(15512)</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0250" published="2004-11-23" seq="2004-0250" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9557">All Enthusiast Photopost PHP Pro SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15008">PhotoPost PHP Pro SQL injection</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107593114909696&amp;w=2">ZH2004-04SA (security advisory): Multiple Sql Injection</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3864/">http://www.zone-h.org/en/advisories/read/id=3864/</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0251" published="2004-11-23" seq="2004-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9575">RXGoogle.CGI Cross Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15043">RxGoogle query cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107594183924958&amp;w=2"> rxgoogle.cgi XSS Vulnerability.</ref></refs><vuln_soft><prod name="rxgoogle.cgi" vendor="rxgoogle.cgi"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0252" published="2004-11-23" seq="2004-0252" severity="Medium" type="CVE"><desc><descript source="cve">TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9573">TYPSoft FTP Server Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15048">TYPSoft FTP Server empty username denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107591511716707&amp;w=2"> TYPSoft FTP Server 1.10 may be crashed</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Feb/1008943.html">1008943</ref></refs><vuln_soft><prod name="TYPSoft FTP Server" vendor="TYPSoft"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0253" published="2004-11-23" seq="2004-0253" severity="High" type="CVE"><desc><descript source="cve">IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9583">IBM Cloudscape Database Remote Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15067">IBM Cloudscape SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604065819233&amp;w=2">IBM cloudscape SQL Database (DB2J) vulnerable to remote command</ref></refs><vuln_soft><prod name="Cloudscape" vendor="IBM"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0254" published="2004-11-23" seq="2004-0254" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9584">Crossday Discuz! Cross Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15066">Discuz! Board image tag cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107606726417150&amp;w=2">Possible Cross Site Scripting in Discuz! Board</ref></refs><vuln_soft><prod name="Discuz" vendor="Crosscom Olicom"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0255" published="2004-11-23" seq="2004-0255" severity="Medium" type="CVE"><desc><descript source="cve">Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9585">XLight FTP Server Long Directory Request Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15064">Xlight ftp server long string denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107605633904122&amp;w=2">Remote crash Xlight ftp server 1.52</ref></refs><vuln_soft><prod name="XLight FTP Server" vendor="XLight FTP Server"><vers num="1.25"/><vers num="1.41"/><vers num="1.45"/><vers num="1.52"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0256" published="2004-11-23" seq="2004-0256" severity="Low" type="CVE"><desc><descript source="cve">GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9530">GNU LibTool Local Insecure Temporary Directory Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15017">GNU Libtool creates insecure temporary directory</ref><ref source="" url="http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/352333">20040130 Symlink Vulnerability in GNU libtool &lt;1.5.2</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000811">CLA-2004:811</ref><ref source="OSVDB" url="http://www.osvdb.org/3795">3795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10777">10777</ref></refs><vuln_soft><prod name="libtool" vendor="GNU"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0257" published="2004-11-23" seq="2004-0257" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.guninski.com/obsdmtu.html">http://www.guninski.com/obsdmtu.html</ref><ref source="CONFIRM" url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9577">BSD ICMPV6 Handling Routines Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15044">OpenBSD IPv6 packet denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604603226564&amp;w=2">OpenBSD IPv6 remote kernel crash</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016704.html">20040204 Remote openbsd crash with ip6, yet still openbsd much better than windows</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-002.txt.asc">NetBSD-SA2004-002</ref><ref source="OSVDB" url="http://www.osvdb.org/3825">3825</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.6"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0258" published="2004-11-23" seq="2004-0258" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9579">Multiple RealPlayer/RealOne Player Supported File Type Buffer Overrun Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15040">RealOne Player multiple file buffer overflows</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2"> Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/473814">Multiple Real media players vulnerable to buffer overflow when parsing crafted media files</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html">20040204 [VulnWatch] Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2">20040204 Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/realone.txt">http://www.nextgenss.com/advisories/realone.txt</ref><ref source="CONFIRM" url="http://www.service.real.com/help/faq/security/040123_player/EN/">http://www.service.real.com/help/faq/security/040123_player/EN/</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-075.shtml">O-075</ref></refs><vuln_soft><prod name="RealOne Desktop Manager" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/><vers num="6.0.11.868"/><vers num="6.0.11.853"/><vers num="6.0.11.841"/><vers num="6.0.11.830"/><vers num="6.0.11.818"/><vers edition="Win" num="2.0"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Win32" num="8.0"/><vers edition="Unix" num="8.0"/><vers edition="Mac OS" num="8.0"/><vers num="10.0 beta"/></prod><prod name="RealOne Enterprise Desktop" vendor="RealNetworks"><vers num="6.0.11.774"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0259" published="2004-11-23" seq="2004-0259" severity="High" type="CVE"><desc><descript source="cve">The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9591">Joe Lumbroso Jack&amp;#39;s Formmail.php Unauthorized Remote File Upload Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15079">Jack&apos;s FormMail.php PHP file upload</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619109629629&amp;w=2">formmail (PHP) Upload file using CSS</ref></refs><vuln_soft><prod name="FormMail.php" vendor="Joe Lumbroso acks"><vers num="2.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0260" published="2004-11-23" seq="2004-0260" severity="Medium" type="CVE"><desc><descript source="cve">The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9589">Cactusoft CactuShop Lite Remote Arbitrary File Deletion Backdoor Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15063">CactuShop Lite contains a backdoor</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619501815888&amp;w=2">  CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref></refs><vuln_soft><prod name="CactuShop Lite" vendor="CactuSoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0261" published="2004-11-23" seq="2004-0261" severity="High" type="CVE"><desc><descript source="cve">oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.grohol.com/downloads/oj/latest/changelog.txt">http://www.grohol.com/downloads/oj/latest/changelog.txt</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9598">OpenJournal Authentication Bypassing Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15069">OpenJournal uid could allow an attacker administrative access</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619136600713&amp;w=2">Open Journal Blog Authenticaion Bypassing Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3872">3872</ref></refs><vuln_soft><prod name="OpenJournal" vendor="OpenJournal"><vers num="2.0 5"/><vers num="2.0 4"/><vers num="2.0 3"/><vers num="2.0 2"/><vers num="2.0 1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0262" published="2004-11-23" seq="2004-0262" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9602">The Palace Graphical Chat Client Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15074">Palace long server address buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634556632195&amp;w=2">The Palace 3.x (Client) Stack Overflow Vulnerability</ref><ref source="MISC" url="http://www.elitehaven.net/thepalace.txt">http://www.elitehaven.net/thepalace.txt</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref></refs><vuln_soft><prod name="The Palace Client" vendor="The Palace"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0263" published="2004-11-23" seq="2004-0263" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9599">Apache mod_php Global Variables Information Disclosure Weakness</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15072">PHP virtual host information disclosure</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-01.xml">PHP setting leaks from .htaccess files on virtual hosts</ref><ref source="GENTOO" url="http://http://security.gentoo.org/glsa/glsa-200402-01.xml">GLSA-200402-01</ref><ref source="OSVDB" url="http://www.osvdb.org/3878">3878</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.5"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.6"/><vers edition="Dev" num="1.3.7"/><vers num="1.3.9"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.14"/><vers num="1.3.17"/><vers num="1.3.18"/><vers num="1.3.19"/><vers num="1.3.20"/><vers num="1.3.22"/><vers num="1.3.23"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.26"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.3.29"/><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28 Beta"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/></prod><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0264" published="2004-11-23" seq="2004-0264" severity="Medium" type="CVE"><desc><descript source="cve">palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9608">Shaun2k2 Palmhttpd Server Remote Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15090">palmhttpd accept function buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634638201570&amp;w=2">PalmOS httpd accept() queue overflow DoS vulnerability.</ref></refs><vuln_soft><prod name="palmhttpd" vendor="shaun2k2"><vers num="3.0"/></prod><prod name="Jim Rees httpd" vendor="Jim Rees"><vers num="PalmOS"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0265" published="2004-11-23" seq="2004-0265" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9605">PHP-Nuke &apos;News&apos; Module Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15076">PHP-Nuke News and Reviews modules cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634727520936&amp;w=2">[waraxe-2004-SA#002] - Cross-Site Scripting (XSS) in Php-Nuke 7.1.0</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/9613">PHP-Nuke &apos;Reviews&apos; Module Cross-Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0266" published="2004-11-23" seq="2004-0266" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the &quot;public message&quot; capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9615">PHP-Nuke Public Message SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15080">PHP-Nuke public message feature SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635110327066&amp;w=2">[waraxe-2004-SA#003] - SQL injection in Php-Nuke 7.1.0</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0267" published="2004-11-23" seq="2004-0267" severity="Low" type="CVE"><desc><descript source="cve">The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9616">Computer Associates eTrust InoculateIT For Linux Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15102">eTrust InoculateIT for Linux symlink attack</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2">[local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref><ref source="MISC" url="http://www.excluded.org/advisories/advisory10.txt">http://www.excluded.org/advisories/advisory10.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/4735">4735</ref><ref source="OSVDB" url="http://www.osvdb.org/4855">4855</ref><ref source="OSVDB" url="http://www.osvdb.org/4856">4856</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10833">10833</ref></refs><vuln_soft><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0268" published="2004-11-23" seq="2004-0268" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9631">EvolutionX Multiple Remote Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15104">EvolutionX command line denial of service</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016988.html">20040210 XBOX EvolutionX ftp cd command and telnet dir buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643394724891&amp;w=2">20040210 XBOX EvolutionX ftp &apos;cd&apos; command and telnet &apos;dir&apos; buffer overflow</ref></refs><vuln_soft><prod name="EvolutionX" vendor="EvolutionX"><vers num="Build 3935"/><vers num="Build 3921"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0269" published="2004-11-23" seq="2004-0269" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9630">PHPNuke Category Parameter SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15115">PHP-Nuke Search and Web_links modules SQL injection</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643348117646&amp;w=2"> [SCAN Associates Sdn Bhd Security Advisory] PHPNuke 6.9 &gt; and below SQL Injection in multiple module</ref><ref source="MISC" url="http://www.scan-associates.net/papers/phpnuke69.txt">http://www.scan-associates.net/papers/phpnuke69.txt</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="1.0"/><vers num="2.5"/><vers num="3.0"/><vers num="4.0"/><vers num="4.3"/><vers num="4.4"/><vers num="4.4.1a"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.2a"/><vers num="5.2"/><vers num="5.3.1"/><vers num="5.4"/><vers num="5.5"/><vers num="5.6"/><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0270" published="2004-11-23" seq="2004-0270" severity="Medium" type="CVE"><desc><descript source="cve">libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.freebsd.org/cgi/query-pr.cgi?pr=62586">http://www.freebsd.org/cgi/query-pr.cgi?pr=62586</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9610">ClamAV Daemon Malformed UUEncoded Message Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15077">Clam AntiVirus uuencoded message denial of service</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-07.xml">Clam Antivirus DoS vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634700823822&amp;w=2"> clamav 0.65 remote DOS exploit</ref><ref source="OSVDB" url="http://www.osvdb.org/3894">3894</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.65"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0271" published="2004-11-23" seq="2004-0271" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
MaxWebPortal, MaxWebPortal, 1.32</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9625">MaxWebPortal Multiple Input Validation Vulnerabilities</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15122">MaxWebPortal register form cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2"> XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15120">maxwebportal-multiple-xss(15120)</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.30"/><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0272" published="2004-11-23" seq="2004-0272" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9625">MaxWebPortal Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15121">MaxWebPortal Personal Messages SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2"> XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.30"/><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0273" published="2004-11-23" seq="2004-0273" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107642978524321&amp;w=2">Directory traversal in RealPlayer allows code execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9580">RealPlayer/RealOne Player RMP Skin File Handler Directory Traversal Vulnerability</ref><ref adv="1" patch="1" source="Real" url="http://service.real.com/help/faq/security/040123_player/EN/">RealNetworks, Inc. Releases Update to Address Security Vulnerabilities.</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/514734">VU#514734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15123">realoneplayer-rmp-directory-traversal(15123)</ref></refs><vuln_soft><prod name="RealOne Desktop Manager" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/><vers num="6.0.11.868"/><vers num="6.0.11.853"/><vers num="6.0.11.841"/><vers num="6.0.11.830"/><vers num="6.0.11.818"/><vers edition="Win" num="2.0"/></prod><prod name="RealOne Enterprise Desktop" vendor="RealNetworks"><vers num="6.0.11.774"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0274" published="2004-11-23" seq="2004-0274" severity="High" type="CVE"><desc><descript source="cve">Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://mogan.nonsoloirc.com/egg_advisory.txt">http://mogan.nonsoloirc.com/egg_advisory.txt</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9606">Eggdrop Share Module Arbitrary Share Bot Add Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15084">Eggdrop share.mod module allows unauthorized access</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634593827102&amp;w=2"> Eggrop bug</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643315623958&amp;w=2">Re: Eggrop bug</ref><ref source="" url="http://www.eggheads.org/news/2004/04/10/26"></ref><ref source="OSVDB" url="http://www.osvdb.org/3928">3928</ref></refs><vuln_soft><prod name="Eggdrop IRC bot" vendor="Eggheads"><vers num="1.6.10"/><vers num="1.6.11"/><vers num="1.6.12"/><vers num="1.6.13"/><vers num="1.6.14"/><vers num="1.6.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0275" published="2004-11-23" seq="2004-0275" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9639">BosDev BosDates SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15133">BosDates calendar SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651618613575&amp;w=2">ZH2004-05SA (security advisory): Sql Injection Vulnerability in</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3925/">http://www.zone-h.org/en/advisories/read/id=3925/</ref></refs><vuln_soft><prod name="BosDates" vendor="BosDev"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0276" published="2004-11-23" seq="2004-0276" severity="Medium" type="CVE"><desc><descript source="cve">The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of &quot;%&quot; characters and a missing Host field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/poc/monkeydos.zip"></ref><ref source="CONFIRM" url="http://monkeyd.sourceforge.net/">http://monkeyd.sourceforge.net/</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9642">Monkey HTTP Daemon Missing Host Field Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15187">Monkey httpd get_real_string denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652610506968&amp;w=2">Denial of Service in Monkey httpd &lt;= 0.8.1</ref><ref source="OSVDB" url="http://www.osvdb.org/3921">3921</ref></refs><vuln_soft><prod name="Monkey HTTP Daemon" vendor="Monkey"><vers num="0.1.4"/><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.6"/><vers num="0.6.1"/><vers num="0.6.2"/><vers num="0.6.3"/><vers num="0.7.0"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.8"/><vers num="0.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-0277" published="2004-11-23" seq="2004-0277" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9600">BolinTech Dream FTP Server User Name Format String Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15070">Dream FTP Server username format string</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016871.html">20040207 DreamFTP Server 1.02 Buffer Overflow</ref><ref source="MISC" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107656166402882&amp;w=2">20040211 Re: [Full-Disclosure] DreamFTP Server 1.02 Buffer Overflow</ref></refs><vuln_soft><prod name="Dream FTP Server" vendor="BolinTech"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0278" published="2004-11-23" seq="2004-0278" severity="Medium" type="CVE"><desc><descript source="cve">Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9644">Ratbag Game Engine Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15188">Ratbag data length denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107655269820530&amp;w=2">Denial of Service in Ratbag&apos;s game engine</ref></refs><vuln_soft><prod name="Dirt Track Racing Australia" vendor="Ratbag"><vers num=""/></prod><prod name="Leadfoot" vendor="Ratbag"><vers num=""/></prod><prod name="World of Outlaws Sprint Cars" vendor="Ratbag"><vers num=""/></prod><prod name="Dirt Track Racing" vendor="Ratbag"><vers num="1.0.3"/><vers num="2.0"/></prod><prod name="Dirt Track Racing Sprint Cars" vendor="Ratbag"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0279" published="2004-11-23" seq="2004-0279" severity="High" type="CVE"><desc><descript source="cve">AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9653">AIM Sniff Temporary File Symlink Attack Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15199">AIM Sniff symlink attack</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662243303439&amp;w=2">aimSniff.pl file &quot;deletion&quot; (local)</ref></refs><vuln_soft><prod name="AIM Sniff" vendor="AIM Sniff"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/><vers num="0.9b"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0280" published="2004-11-23" seq="2004-0280" severity="Medium" type="CVE"><desc><descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a &quot;%20&quot; (encoded space character), e.g. index.jsp%20.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9614">Caucho Technology Resin Source Code Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15085">Resin index.jsp information disclosure</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2"> Apache Http Server Reveals Script Source Code to Remote Users And</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers num="2.1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0281" published="2004-11-23" seq="2004-0281" severity="Medium" type="CVE"><desc><descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for &quot;WEB-INF..&quot;, which is equivalent to &quot;WEB-INF&quot; in Windows.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9617">Caucho Technology Resin Directory Listings Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15087">Resin &quot;dot dot&quot; directory traversal</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2"> Apache Http Server Reveals Script Source Code to Remote Users And</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers num="2.1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0282" published="2004-11-23" seq="2004-0282" severity="Medium" type="CVE"><desc><descript source="cve">Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9651">Crob FTP Server Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15201">Crob FTP Server multiple connections denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665920909374&amp;w=2"> crob ftpd Denial of Service</ref><ref source="OSVDB" url="http://www.osvdb.org/6621">6621</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10882">10882</ref></refs><vuln_soft><prod name="Crob FTP Server" vendor="Crob"><vers num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0283" published="2004-11-23" seq="2004-0283" severity="Low" type="CVE"><desc><descript source="cve">Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9654">Mailmgr Insecure Temporary File Creation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15203">Mailmgr insecure temporary directory</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665013714517&amp;w=2">Symlink vulnerabilities in mailmgr</ref></refs><vuln_soft><prod name="Mailmgr" vendor="Mailmgr"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0284" published="2004-11-23" seq="2004-0284" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if &quot;Do not save encrypted pages to disk&quot; is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9629">Microsoft Internet Explorer Double-Null URI Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15127">Microsoft Internet Explorer and Outlook null character in host name denial of service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643134712133&amp;w=2">ASPR #2004-01-20-1: Internet Explorer/Outlook double null character DoS</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0285" published="2004-11-23" seq="2004-0285" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9664">Voice Of Web AllMyPHP Remote File Include Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15226">AllMyLinks PHP file include</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696291728750&amp;w=2">AllMyLinks PHP Code Injection vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15227">AllMyGuests PHP file include</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15228">allmyvisitors-file-include(15228)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696235424865&amp;w=2">20040214 AllMyVisitors PHP Code Injection vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696209514155&amp;w=2">20040214 AllMyGuests PHP Code Injection vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/6721">6721</ref></refs><vuln_soft><prod name="AllMyVisitors" vendor="Voice Of Web"><vers num="0.3"/><vers num="0.4"/></prod><prod name="AllMyGuests" vendor="Voice Of Web"><vers num="0.1.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.4.1"/></prod><prod name="AllMyLinks" vendor="Voice Of Web"><vers num="0.3"/><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.3"/><vers num="0.4.4"/><vers num="0.4.9"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0286" published="2004-11-23" seq="2004-0286" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9672">RobotFTP Server Username Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15225">Robot FTP Server username buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696194306878&amp;w=2">buffer overflow in Robot FTP Server</ref></refs><vuln_soft><prod name="RobotFTP Server" vendor="RobotFTP"><vers num="1.0"/><vers num="2.0 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0287" published="2004-11-23" seq="2004-0287" severity="Medium" type="CVE"><desc><descript source="cve">Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9627">XLight FTP Server Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15220">Xlight ftp RETR denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695172917263&amp;w=2">Xlight ftp server 1.52 RETR bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/9668">9668</ref></refs><vuln_soft><prod name="XLight FTP Server" vendor="XLight FTP Server"><vers num="1.52"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0288" published="2004-11-23" seq="2004-0288" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9667">mnoGoSearch UdmDocToTextBuf Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15209">mnoGoSearch UdmDocToTextBuf function buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695139930726&amp;w=2">Buffer overflow in mnoGoSearch</ref></refs><vuln_soft><prod name="mnoGoSearch" vendor="mnoGoSearch"><vers num="3.1.19"/><vers num="3.1.20"/><vers num="3.2.10"/><vers num="3.2.13"/><vers num="3.2.14"/><vers num="3.2.15"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0289" published="2004-11-23" seq="2004-0289" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9661">Paul Daniels SignatureDB sdbscan Local Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15217">SignatureDB sdbscan buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695113832648&amp;w=2">problems with database files in &apos;SignatureDB&apos;</ref></refs><vuln_soft><prod name="SignatureDB" vendor="Paul L Daniels"><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0290" published="2004-11-23" seq="2004-0290" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9671">Freeform Interactive Purge/Purge Jihad Game Client Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15216">Purge and Purge Jihad battle type and map name buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695064204362&amp;w=2">Broadcast client buffer-overflow in Purge Jihad &lt;= 2.0.1</ref><ref source="CONFIRM" url="http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167">http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167</ref></refs><vuln_soft><prod name="Purge Jihad" vendor="Freeform Interactive"><vers num="2.0.1"/></prod><prod name="Purge" vendor="Freeform Interactive"><vers num="1.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0291" published="2004-11-23" seq="2004-0291" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9674">YABB SE Quote Parameter SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15224">YaBB SE post.php SQL injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696318522985&amp;w=2">20040216 Another YabbSE SQL Injection</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.4"/><vers edition="Second Edition" num="1.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0292" published="2004-11-23" seq="2004-0292" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9679">KarjaSoft Sami HTTP Server GET Request Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15237">Sami HTTP Server HTTP GET request buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703630913205&amp;w=2">KarjaSoft Sami HTTP Server 1.0.4 Buffer Overflow</ref><ref source="" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1746"></ref></refs><vuln_soft><prod name="Sami HTTP Server" vendor="KarjaSoft"><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0293" published="2004-11-23" seq="2004-0293" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9670">ShopCartCGI Remote File Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14982">ShopCartCGI &quot;dot dot&quot; directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703602707450&amp;w=2">ZH2004-06SA (security advisory): ShopCartCGI v2.3 Remote</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3962/">http://www.zone-h.org/en/advisories/read/id=3962/</ref></refs><vuln_soft><prod name="ShopCartCGI" vendor="ShopCartCGI"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0294" published="2004-11-23" seq="2004-0294" severity="Medium" type="CVE"><desc><descript source="cve">YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9677">YaBB Information Leakage Weakness</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15236">YABB invalid messages allow attacker to obtain username and password</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703591314745&amp;w=2">20040217 YABB information leakage on failed login</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="1 Gold - SP 1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0295" published="2004-11-23" seq="2004-0295" severity="Medium" type="CVE"><desc><descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9680">TransSoft Broker FTP Server Denial of Service Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15242">Broker FTP Server TsFtpSrv.exe denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2">Broker FTP DoS (Message Server)=?iso-8859-1?q?=0A?=</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref></refs><vuln_soft><prod name="Broker FTP Server" vendor="TransSoft"><vers num="6.1 .0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0296" published="2004-11-23" seq="2004-0296" severity="Medium" type="CVE"><desc><descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9680">TransSoft Broker FTP Server 6.1 .0.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15241">Broker FTP Server denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2">Broker FTP DoS (Message Server)=?iso-8859-1?q?=0A?=</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref></refs><vuln_soft><prod name="Broker FTP Server" vendor="TransSoft"><vers num="6.1 .0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0297" published="2004-11-23" seq="2004-0297" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9682">Ipswitch IMail Server Remote LDAP Daemon Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15243">Ipswitch IMail LDAP daemon large tag buffer overflow</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/972334">IMail Server LDAP daemon buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705541425564&amp;w=2"> iDEFENSE Security Advisory 02.17.04: Ipswitch IMail LDAP Daemon Remote Buffer Overflow</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=74">20040217 Ipswitch IMail LDAP Daemon Remote Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/3984">3984</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="8.0.3"/><vers num="8.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0298" published="2004-11-23" seq="2004-0298" severity="Medium" type="CVE"><desc><descript source="cve">CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9666">ACLogic CesarFTP Remote Resource Exhaustion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15252">CesarFTP user:pass command denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712057628250&amp;w=2">CesarFTP 0.99 : 100% employment of computer resources</ref></refs><vuln_soft><prod name="CesarFTP" vendor="ACLogic"><vers num="0.99e"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0299" published="2004-11-23" seq="2004-0299" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of &quot;/&quot; (slash) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9684">SmallFTPD Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15262">Small ftpd forward slash in request denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107714207708375&amp;w=2">Smallftpd 1.0.3 DoS</ref></refs><vuln_soft><prod name="smallftpd" vendor="smallftpd"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0300" published="2004-11-23" seq="2004-0300" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9676">Ecommerce Corporation Online Store Kit More.PHP Multiple Vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9687">Ecommerce Corporation Online Store Kit Multiple SQL Injection Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15232">Online Store Kit more.php SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712117913185&amp;w=2">ZH2004-07SA (security advisory): Multiple Sql injection</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3972/">http://www.zone-h.org/en/advisories/read/id=3972/</ref><ref source="MISC" url="http://www.systemsecure.org/advisories/ssadvisory16022004.php">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10902/">10902</ref><ref source="OSVDB" url="http://www.osvdb.org/3973">3973</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Feb/1009092.html">1009092</ref></refs><vuln_soft><prod name="Store Kit" vendor="Ecommerce Corporation Online"><vers num="3.0 Standard"/><vers num="3.0 Pro"/><vers num="3.0 Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0301" published="2004-11-23" seq="2004-0301" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9676">Ecommerce Corporation Online Store Kit More.PHP Multiple Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15235">Online Store Kit more.php cross-site scripting</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/10902/"></ref><ref source="MISC" url="http://www.systemsecure.org/advisories/ssadvisory16022004.php">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Feb/1009079.html">1009079</ref></refs><vuln_soft><prod name="Store Kit" vendor="Ecommerce Corporation Online"><vers num="3.0 Standard"/><vers num="3.0 Pro"/><vers num="3.0 Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0302" published="2004-11-23" seq="2004-0302" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9689">Owl&amp;#39;s Workshop Multiple Remote File Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15249">OWLS file retrieval</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2">ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3973/">http://www.zone-h.org/en/advisories/read/id=3973/</ref></refs><vuln_soft><prod name="Owls Workshop" vendor="Fools Workshop"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0303" published="2004-11-23" seq="2004-0303" severity="Medium" type="CVE"><desc><descript source="cve">OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9689">Owl&amp;#39;s Workshop Multiple Remote File Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15249">OWLS file retrieval</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2"> ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3973/">http://www.zone-h.org/en/advisories/read/id=3973/</ref></refs><vuln_soft><prod name="Owls Workshop" vendor="Fools Workshop"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0304" published="2004-11-23" seq="2004-0304" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/7766">WebCortex WebStores2000 SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15253">WebStores 2000 browse_items.asp SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2">WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040218.txt">http://www.s-quadra.com/advisories/Adv-20040218.txt</ref></refs><vuln_soft><prod name="Webstores 2000" vendor="WebCortex"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0305" published="2004-11-23" seq="2004-0305" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9693">WebCortex WebStores2000 Error.ASP Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15254">WebStores 2000 error.asp cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2">WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref></refs><vuln_soft><prod name="Webstores 2000" vendor="WebCortex"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0306" published="2004-11-23" seq="2004-0306" severity="Medium" type="CVE"><desc><descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9699">Cisco ONS Platform Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15264">Cisco ONS multiple devices could allow file upload and retrieval</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml">Cisco Security Advisory: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.5"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2004-0307" published="2004-11-23" seq="2004-0307" severity="Medium" type="CVE"><desc><descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9699">Cisco ONS Platform Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15265">Cisco ONS multiple devices ACK denial of service</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml">Cisco Security Advisory: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/4009">4009</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.5"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-30" name="CVE-2004-0308" published="2004-11-24" seq="2004-0308" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9699">Cisco ONS Platform Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15266">Cisco ONS multiple devices allow unauthorized access</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml">Cisco Security Advisory: Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/4010">4010</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.5"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0309" published="2004-11-23" seq="2004-0309" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://download.zonelabs.com/bin/free/securityAlert/8.html">http://download.zonelabs.com/bin/free/securityAlert/8.html</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9696">Zone Labs ZoneAlarm SMTP Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/619982">Zone Labs desktop security products fail to properly validate RCPT TO command argument</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722656827427&amp;w=2">EEYE: ZoneLabs SMTP Processing Buffer Overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14991">ZoneAlarm multiple products buffer overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-084.shtml">O-084</ref><ref source="OSVDB" url="http://www.osvdb.org/3991">3991</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="4.0"/></prod><prod name="ZoneAlarm Plus" vendor="Zone Labs"><vers num="4.0"/></prod><prod name="Zone Integrity" vendor="Zone Labs"><vers num="4.0"/></prod><prod name="ZoneAlarm Pro" vendor="Zone Labs"><vers num="4.0"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0310" published="2004-11-23" seq="2004-0310" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9700">LiveJournal HTML Injection Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15268">LiveJournal URL cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722627800820&amp;w=2"> LiveJournal XSS</ref></refs><vuln_soft><prod name="LiveJournal" vendor="LiveJournal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0311" published="2004-11-23" seq="2004-0311" severity="High" type="CVE"><desc><descript source="cve">American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9681">APC SmartSlot Web/SNMP Management Card Default Password Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15238">APC&apos;s Web/SNMP Management SmartSlot Card default password</ref><ref source="CONFIRM" url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703696631367&amp;w=2">20040216 APC 9606 SmartSlot Web/SNMP management card &quot;backdoor&quot;</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107721020803565&amp;w=2">20040219 Re: Fw: APC 9606 SmartSlot Web/SNMP management card &quot;backdoor&quot;</ref></refs><vuln_soft><prod name="WEB SNMP Management Card 9606 Firmware" vendor="APC"><vers num="3.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0312" published="2004-11-23" seq="2004-0312" severity="Medium" type="CVE"><desc><descript source="cve">Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9688">Linksys WAP55AG SNMP Community String Insecure Configuration Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15257">Linksys WAP55AG SNMP strings disclosure</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712101324233&amp;w=2">SNMP community string disclosure in Linksys WAP55AG</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730681012131&amp;w=2">Re: SNMP community string disclosure in Linksys WAP55AG</ref></refs><vuln_soft><prod name="WAP55AG" vendor="Linksys"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0313" published="2004-11-23" seq="2004-0313" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9706">PSOProxy Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15275">PSOProxy long HTTP GET request buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730731900261&amp;w=2">Remote Buffer Overflow in PSOProxy 0.91</ref></refs><vuln_soft><prod name="PSOProxy Server" vendor="PSOProxy"><vers num="0.91"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0314" published="2004-11-23" seq="2004-0314" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15289">WebzEdit done.jsp cross-site scripting</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757029514146&amp;w=2">20040221 Cross Site Scripting in WebzEdit</ref></refs><vuln_soft><prod name="WebzEdit" vendor="Freewebs"><vers num="1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0315" published="2004-11-23" seq="2004-0315" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9721">Avirt Voice HTTP GET Remote Buffer Overrun Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756584609841&amp;w=2">Remote Buffer Overflow in Avirt Voice 4.0</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15288">avirt-voice-get-bo(15288)</ref></refs><vuln_soft><prod name="Voice" vendor="Avirt"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0316" published="2004-11-23" seq="2004-0316" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Avirt Soho 4.3 allows remote attackers to cause a denial of service (crash) via (1) a large GET request to port 1080 or (2) a large GET request of % characters to port 8080.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9722">Avirt Soho Server HTTP GET Buffer Overrun Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9723">Avirt Soho Web Service HTTP GET Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15286">Avirt SOHO multiple buffer overflows</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756666701194&amp;w=2">Multiple Remote Buffer Overflow in Avirt Soho 4.3</ref></refs><vuln_soft><prod name="Avirt SOHO" vendor="Avirt"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0317" published="2004-11-23" seq="2004-0317" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9719">Platform Load Sharing Facility EAuth Component Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15282">Load Sharing Facility eauth component allows code execution</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756611501236&amp;w=2"> Lam3rZ Security Advisory #1/2004: LSF eauth vulnerability leads to</ref></refs><vuln_soft><prod name="LSF" vendor="Platform"><vers num="4.0"/><vers num="4.2"/><vers num="5.0"/><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0318" published="2004-11-23" seq="2004-0318" severity="High" type="CVE"><desc><descript source="cve">Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9724">Platform Load Sharing Facility EAuth Privilege Escalation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15278">Load Sharing Facility eauth component could allow attacker to hijack other user&apos;s process</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756600403557&amp;w=2"> Lam3rZ Security Advisory #2/2004: LSF eauth vulnerability leads to</ref></refs><vuln_soft><prod name="LSF" vendor="Platform"><vers num="4.0"/><vers num="4.2"/><vers num="5.0"/><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0319" published="2004-11-23" seq="2004-0319" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9725">EZBoard Font Tag HTML Injection Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15287">ezboard font tag cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756639427140&amp;w=2">ezBoard Cross Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="ezboard" vendor="ezboard"><vers num="7.3u"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0320" published="2004-11-23" seq="2004-0320" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module&apos;s run-time memory via certain sequences of commands.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9717">nCipher Hardware Security Module Firmware Secrets Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15281">nCipher HSM information disclosure</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755899018249&amp;w=2">nCipher Advisory #9: Host-side attackers can access secret data</ref><ref source="OSVDB" url="http://www.osvdb.org/4055">4055</ref></refs><vuln_soft><prod name="nShield" vendor="nCipher"><vers num="1.71.11"/><vers num="1.71.15"/><vers num="1.71.90"/><vers num="1.75.15"/><vers num="1.77.9"/><vers num="1.77.93"/><vers num="1.77.97"/><vers num="1.79.12"/><vers num="1.79.80"/><vers num="1.79.81"/><vers num="2.0"/><vers num="2.0.4"/><vers num="2.12"/><vers num="2.12.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0321" published="2004-11-23" seq="2004-0321" severity="Medium" type="CVE"><desc><descript source="cve">Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9708">Singularity Software Team Factor Integer Handling Memory Corruption Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15274">Team Factor packet denial of service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756001412888&amp;w=2">Remote server crash in Team Factor &lt;= 1.25</ref><ref source="MISC" url="http://www.zone-h.org/advisories/read/id=4006">http://www.zone-h.org/advisories/read/id=4006</ref></refs><vuln_soft><prod name="Team Factor" vendor="Singularity Software"><vers num="1.25m"/><vers num="1.25"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0322" published="2004-02-23" seq="2004-0322" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15292">xmb-multiple-scripts-xss(15292)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9726">9726</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref><ref source="" url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15294">xmb-bbcode-execute-code(15294)</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP2"/><vers num="1.8 SP1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0323" published="2004-12-31" seq="2004-0323" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php.  NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15295">xmb-multiple-sql-injection(15295)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9726">9726</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref><ref source="" url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP2"/><vers num="1.8 SP1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0324" published="2004-02-23" seq="2004-0324" severity="High" type="CVE"><desc><descript source="cve">Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as &quot;, `, |, ;, or $.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757320401858&amp;w=2">20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15290">confirm-header-gain-access(15290)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9728">9728</ref></refs><vuln_soft><prod name="Confirm" vendor="Confirm"><vers num="0.62"/><vers num="0.61"/><vers num="0.60"/><vers num="0.55"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0325" published="2004-12-31" seq="2004-0325" severity="Low" type="CVE"><desc><descript source="cve">TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via &quot;//../&quot; arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using &quot;//../qwerty&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107764173821905&amp;w=2">20040223 TYPSoft FTP Server 1.10 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9702">9702</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15306">typsoft-ftp-command-dos(15306)</ref></refs><vuln_soft><prod name="TYPSoft FTP Server" vendor="TYPSoft"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0326" published="2004-11-23" seq="2004-0326" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9716">Proxy-Pro Professional GateKeeper Web Proxy Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15277">Proxy-Pro GateKeeper Pro long HTTP GET buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755692400728&amp;w=2">GateKeeper Pro 4.7 buffer overflow</ref><ref adv="1" source="Netsys" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017703.html">GateKeeper Pro 4.7 buffer overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017703.html">20040222 GateKeeper Pro 4.7 buffer overflow</ref></refs><vuln_soft><prod name="Professional GateKeeper" vendor="Proxy-Pro"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0327" published="2004-11-23" seq="2004-0327" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via ..  (dot dot) sequences in the clang parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9720">phpNewsManager Functions Script File Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15283">PhpNewsManager &quot;dot dot&quot; directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107772470111000&amp;w=2">ZH2004-09SA (security advisory): PhpNewsManager Remote arbitrary</ref><ref source="MISC" url="http://www.zone-h.org/advisories/read/id=4024">http://www.zone-h.org/advisories/read/id=4024</ref></refs><vuln_soft><prod name="phpNewsManager" vendor="SkinTech"><vers num="1.36"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0328" published="2004-11-23" seq="2004-0328" severity="High" type="CVE"><desc><descript source="cve">Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router&apos;s html menu on a separate system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9740">Gigabyte Gn-B46B Wireless Router Authentication Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15313">Gigabyte Technology GN-B46B router allows authentication to be bypassed</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107766719227942&amp;w=2">Gigabyte Broadband Router  - Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Gn-B46B" vendor="Gigabyte"><vers num="1.003.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0329" published="2004-11-23" seq="2004-0329" severity="Medium" type="CVE"><desc><descript source="cve">FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using &quot;aaaaa&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9744">FreeChat Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15321">FreeChat string denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781043621074&amp;w=2">Denial Of Service in FreeChat 1.1.1a</ref></refs><vuln_soft><prod name="FreeChat" vendor="FreeChat"><vers num="0.1.1a"/><vers num="1.1.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0330" published="2004-11-23" seq="2004-0330" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9751">RhinoSoft Serv-U FTP Server MDTM Command Time Argument Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15323">Serv-U MDTM buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781164214399&amp;w=2"> [vulnwatch] Serv-U MDTM Command Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://www.cnhonker.com/advisory/serv-u.mdtm.txt">http://www.cnhonker.com/advisory/serv-u.mdtm.txt</ref></refs><vuln_soft><prod name="Serv-U" vendor="RhinoSoft"><vers num="3.0"/><vers num="3.1"/><vers num="4.0.0.4"/><vers num="4.1.0.11"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0331" published="2004-11-23" seq="2004-0331" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9750">Dell OpenManage Web Server POST Request Heap Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15325">Dell OpenManage Web Server OCSGetOEMINIPathFile function buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781539829143&amp;w=2">Dell OpenManage Web Server Heap Overflow (Pre-Auth)</ref><ref source="MISC" url="http://sh0dan.org/files/domadv.txt">http://sh0dan.org/files/domadv.txt</ref></refs><vuln_soft><prod name="OpenManage" vendor="Dell"><vers num="3.2"/><vers num="3.4"/><vers num="3.7"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0332" published="2004-11-23" seq="2004-0332" severity="High" type="CVE"><desc><descript source="cve">Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9754">eXtremail Authentication Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15329">eXtremail all digit password allows unauthorized access</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107783767517850&amp;w=2"> Extremail Security Problem</ref></refs><vuln_soft><prod name="eXtremail" vendor="eXtremail"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.8"/><vers num="1.1.9"/><vers num="1.1.10"/><vers num="1.5.8"/><vers num="1.5.5"/><vers num="1.5"/><vers num="1.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-26" name="CVE-2004-0333" published="2004-11-23" seq="2004-0333" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.</descript></desc><sols><sol source="nvd">This was fixed in WinZip 8.1 SR-2 in March of 2004. You can find more information on the subject on the following pages of the winzip site:
http://www.winzip.com/wz81sr2.htm
http://www.winzip.com/fmwz90.htm</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9758">UUDeview MIME Archive Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15336">WinZip UUDeview package MIME buffer overflow</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/116182">WinZip vulnerable to buffer overflow in handling of MIME archive parameters</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789846720924&amp;w=2">iDEFENSE Security Advisory 02.27.04a: WinZip MIME Parsing Buffer</ref><ref source="CONFIRM" url="http://www.winzip.com/fmwz90.htm">http://www.winzip.com/fmwz90.htm</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-092.shtml">O-092</ref><ref source="" url="http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html">http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html</ref><ref source="OSVDB" url="http://www.osvdb.org/4119">4119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10995">10995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11019">11019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15490">uudeview-multiple-bo(15490)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=76&amp;type=vulnerabiliti&amp;flashstatus=true">20040227 WinZip MIME Parsing Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/></prod><prod name="WinZip" vendor="WinZip"><vers num="7.0"/><vers num="8.0"/><vers num="8.1 SR1"/><vers num="8.1"/></prod><prod name="UUDeview" vendor="UUDeview"><vers num="0.5.18"/><vers num="0.5.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2004-0334" published="2004-11-23" seq="2004-0334" severity="Medium" type="CVE"><desc><descript source="cve">InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash).  NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7652">Axis Network Camera HTTP Authentication Bypass Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799556111784&amp;w=2">20040227 InnoMedia VideoPhone Authorization Bypass</ref><ref source="OSVDB" url="http://www.osvdb.org/4809">4809</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Mar/1009522.html">1009522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15636">InnoMedia-videophone-bypass-authentication(15636)</ref></refs><vuln_soft><prod name="InnoMedia VideoPhone" vendor="InnoMedia"><vers num="au75200xvi04010x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0335" published="2004-11-23" seq="2004-0335" severity="Medium" type="CVE"><desc><descript source="cve">LAN SUITE Web Mail 602Pro, when configured to use the &quot;Directory browsing&quot; feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15349">602Pro LAN SUITE could disclose directory listing</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9780">9780</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-17" name="CVE-2004-0336" published="2004-11-23" seq="2004-0336" severity="Medium" type="CVE"><desc><descript source="cve">LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9781">Software602 602Pro LAN Suite Web Mail Installation Path Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15350">602Pro LAN SUITE path disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2"> LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0337" published="2004-11-23" seq="2004-0337" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script.  NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9777">Software602 602Pro LAN Suite Web Mail Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15351">602Pro LAN SUITE index.html cross-site scripting</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0338" published="2004-11-23" seq="2004-0338" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15343">Invision Power Board search.php SQL injection</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799527428834&amp;w=2">Invision Power Board SQL injection!</ref><ref source="BID" url="http://www.securityfocus.com/bid/9766">9766</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.2"/><vers num="1.3"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0339" published="2004-11-23" seq="2004-0339" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
phpBB Group, phpBB, 2.0.7</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15348">phpBB viewtopic.php script allows cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799508130700&amp;w=2">New phpBB ViewTopic.php Cross Site Scripting Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9765">9765</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0 RC4"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0340" published="2004-11-23" seq="2004-0340" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9767">Multiple WFTPD Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15340">WFTPD Pro Server and Server FTP commands buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801208004699&amp;w=2">Critical WFTPD buffer overflow vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11001">11001</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers edition="Pro" num="3.0"/><vers edition="Pro" num="3.0 0R5"/><vers num="3.0 0R5"/><vers edition="Pro" num="3.0 0R4"/><vers num="3.0 0R4"/><vers num="3.0 0R3"/><vers num="3.0"/><vers num="3.10 R1"/><vers num="3.20"/><vers num="3.21"/><vers num="Pro 3.10 R1"/><vers num="Pro 3.20"/><vers num="Pro 3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0341" published="2004-11-23" seq="2004-0341" severity="Low" type="CVE"><desc><descript source="cve">WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9767">Multiple WFTPD Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15341">WFTPD Pro Server long strings without an 0Ah byte causes denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2"> Multiple WFTPD Denial of Service vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/4115">4115</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11001">11001</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers edition="Pro" num="3.0"/><vers edition="Pro" num="3.0 0R5"/><vers num="3.0 0R5"/><vers edition="Pro" num="3.0 0R4"/><vers num="3.0 0R4"/><vers num="3.0 0R3"/><vers num="3.0"/><vers num="3.10 R1"/><vers num="3.20"/><vers num="3.21"/><vers num="Pro 3.10 R1"/><vers num="Pro 3.20"/><vers num="Pro 3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0342" published="2004-11-23" seq="2004-0342" severity="Low" type="CVE"><desc><descript source="cve">WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9767">Multiple WFTPD Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15342">WFTPD Pro MKD or XMKD FTP commands can cause denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2"> Multiple WFTPD Denial of Service vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/4116">4116</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11001">11001</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers edition="Pro" num="3.0"/><vers edition="Pro" num="3.0 0R5"/><vers num="3.0 0R5"/><vers edition="Pro" num="3.0 0R4"/><vers num="3.0 0R4"/><vers num="3.0 0R3"/><vers num="3.0"/><vers num="3.10 R1"/><vers num="3.20"/><vers num="3.21"/><vers num="Pro 3.10 R1"/><vers num="Pro 3.20"/><vers num="Pro 3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0343" published="2004-11-23" seq="2004-0343" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9774">YABB SE Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15354">YaBB SE multiple modules allow SQL injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2">20040301 YabbSE  (3 on 1)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.4"/><vers edition="Second Edition" num="1.5.5b"/><vers edition="Second Edition" num="1.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0344" published="2004-11-23" seq="2004-0344" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9774">YABB SE Multiple Input Validation Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2">20040301 YabbSE  (3 on 1)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.5b"/><vers edition="Second Edition" num="1.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0345" published="2004-11-23" seq="2004-0345" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9775">Volition Red Faction Game Client Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15353">Red Faction buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816217901923&amp;w=2">Clients broadcast buffer overflow in Red Faction &lt;= 1.20</ref></refs><vuln_soft><prod name="Red Faction" vendor="Volition"><vers num="1.0"/><vers num="1.1"/><vers num="1.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0346" published="2004-11-23" seq="2004-0346" severity="High" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9782">ProFTPD _xlate_ascii_write() Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15387">ProFTPD off-by-one _xlate_ascii_write function buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107824679817240&amp;w=2">20040302 The Cult of a Cardinal Number</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9 rc2"/><vers num="1.2.9 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-19" name="CVE-2004-0347" published="2004-11-23" seq="2004-0347" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9791">NetScreen SA 5000 Series delhomepage.cgi Cross-Site Scripting Vulnerability</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107826362024112&amp;w=2">  03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850564102190&amp;w=2">NetScreen Advisory 58412: XSS Bug in NetScreen-SA SSL VPN</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018120.html">20040302 03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/114070">VU#114070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15368">netscreen-delhomepagecgi-xss(15368)</ref></refs><vuln_soft><prod name="NetScreen-SA 5000 Series" vendor="NetScreen"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0348" published="2004-11-23" seq="2004-0348" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9799">SpiderSales Shopping Cart Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15371">Spider Sales userId SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2">Spider Sales shopping cart software multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040303.txt">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref></refs><vuln_soft><prod name="SpiderSales" vendor="SpiderSales"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0349" published="2004-11-23" seq="2004-0349" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9742">GWeb HTTP Server Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15381">GWeb HTTP Server directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833161617397&amp;w=2">directory traversal in GWeb 0.6</ref></refs><vuln_soft><prod name="Gweb HTTP Server" vendor="Gweb"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0350" published="2004-11-23" seq="2004-0350" severity="Low" type="CVE"><desc><descript source="cve">SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9799">SpiderSales Shopping Cart Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15370">Spider Sales weak encryption</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2">Spider Sales shopping cart software multiple security vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040303.txt">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref></refs><vuln_soft><prod name="SpiderSales" vendor="SpiderSales"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0351" published="2004-11-23" seq="2004-0351" severity="Low" type="CVE"><desc><descript source="cve">Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9799">SpiderSales Shopping Cart Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15370">Spider Sales weak encryption</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2">Spider Sales shopping cart software multiple security vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref></refs><vuln_soft><prod name="SpiderSales" vendor="SpiderSales"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0352" published="2004-11-23" seq="2004-0352" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9806">Cisco Content Service Switch Management Port UDP Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15388">Cisco CSS switches UDP packet denial of service</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/363374">Cisco CSS 11000 Series Content Services Switch vulnerable to DoS via malformed UDP packets</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml">Cisco Security Advisory: Cisco CSS 11000 Series Content Services Switches Malformed UDP Packet Vulnerability</ref></refs><vuln_soft><prod name="Content Services Switch" vendor="Cisco"><vers num="CSS11000"/><vers num="CSS11050"/><vers num="CSS11150"/><vers num="CSS11800"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0353" published="2004-11-23" seq="2004-0353" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9772">GNU Anubis Multiple Remote Buffer Overflow and Format String Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15345">Anubis IDENT buffer overflow</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107894315012081&amp;w=2">GNU Anubis 3.6.2 remote root exploit</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2">GNU Anubis buffer overflows and format string bugs</ref><ref source="MLIST" url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html">[bug-anubis] 20040228 Important security update</ref></refs><vuln_soft><prod name="Anubis" vendor="GNU"><vers num="3.6.0"/><vers num="3.6.1"/><vers num="3.6.2"/><vers num="3.9.92"/><vers num="3.9.93"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0354" published="2004-11-23" seq="2004-0354" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9772">GNU Anubis Multiple Remote Buffer Overflow and Format String Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15346">Anubis format string error</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2">GNU Anubis buffer overflows and format string bugs</ref><ref source="MLIST" url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html">[bug-anubis] 20040228 Important security update</ref></refs><vuln_soft><prod name="Anubis" vendor="GNU"><vers num="3.6.0"/><vers num="3.6.1"/><vers num="3.6.2"/><vers num="3.9.92"/><vers num="3.9.93"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0355" published="2004-11-23" seq="2004-0355" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for &quot;Personal Photo&quot; that is not an image file, which displays the installation path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9810">Invision Power Board Error Message Path Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15400">Invision Power Board invalid character could disclose path</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850510428567&amp;w=2">Invision Power Board 1.3 Final Path Disclosure Vulnerability</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0356" published="2004-11-23" seq="2004-0356" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/slmailsrc.txt">http://www.nextgenss.com/advisories/slmailsrc.txt</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9809">Seattle Lab Software SLMail Pro Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15398">SLMail Pro Supervisor Report Center stack-based buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850488326232&amp;w=2">SLMail Pro Supervisor Report Center Buffer Overflow (#NISR05022004a)</ref></refs><vuln_soft><prod name="SLMail Pro" vendor="Seattle Lab Software"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0357" published="2004-11-23" seq="2004-0357" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9808">Seattle Lab Software SLWebMail Multiple Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15399">SLMail Pro SLWebmail buffer overflows</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850432827699&amp;w=2">SLWebMail Multiple Buffer Overflow Vulnerabilities (#NISR05022004b)</ref><ref source="CONFIRM" url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/slmailwm.txt">http://www.nextgenss.com/advisories/slmailwm.txt</ref></refs><vuln_soft><prod name="SLMail Pro" vendor="Seattle Lab Software"><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0358" published="2004-11-23" seq="2004-0358" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9812">VirtuaSystems VirtuaNews Multiple Module Cross-Site Scripting Vulnerabilities</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/9819">VirtuaSystems VirtuaNews Admin.PHP Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15402">VirtuaNews Admin Panel multiple cross-site scripting</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851556116088&amp;w=2">VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0069.html">20040307 RE: VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref></refs><vuln_soft><prod name="VirtuaNews Pro" vendor="VirtuaSystems"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0359" published="2004-11-23" seq="2004-0359" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9768">Invision Power Board Multiple Cross-Site Scripting Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15403">Invision Power Board cross-site scripting</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851589701916&amp;w=2">Invision Power Board v1.3 Final Cross Site Scripting Vulnerabillity</ref><ref source="OSVDB" url="http://www.osvdb.org/4154">4154</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11053">11053</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.3 Final"/><vers num="1.3.1 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0360" published="2004-11-23" seq="2004-0360" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9757">Sun Solaris Unspecified Passwd Local Root Compromise Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15327">Solaris passwd(1) allows elevated privileges</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/694782">Sun Solaris passwd command allows for privilege escalation</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107852274423414&amp;w=2">O-088: Sun passwd(1) Command Vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57454">57454</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-088.shtml">O-088</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0361" published="2004-11-23" seq="2004-0361" severity="Medium" type="CVE"><desc><descript source="cve">The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9815">Apple Safari Large JavaScript Array Handling Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15413">Safari Web browser application large array denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107861828510106&amp;w=2">Safari javascript array overflow</ref><ref source="MISC" url="http://www.insecure.ws/article.php?story=2004021918172533">http://www.insecure.ws/article.php?story=2004021918172533</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="Beta2"/><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0362" published="2004-04-15" seq="2004-0362" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107965651712378&amp;w=2">EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/166">Vulnerability in ICQ Parsing in ISS Products</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/947254">Internet Security Systems Protocol Analysis Module (PAM) does not properly handle ICQ server response messages</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9913">bid 9913</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15442">pam-icq-parsing-bo(15442)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040318.html">AD20040318</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-104.shtml">O-104</ref><ref source="OSVDB" url="http://www.osvdb.org/4355">4355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11073">11073</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15543">witty-worm-propagation(15543)</ref></refs><vuln_soft><prod name="RealSecure Guard" vendor="Internet Security Systems"><vers num="3.6ecd"/><vers num="3.6ecf"/><vers num="3.6ece"/><vers num="3.6ecc"/><vers num="3.6ecb"/><vers num="3.6eca"/><vers num="3.6ebz"/></prod><prod name="RealSecure Network Sensor" vendor="Internet Security Systems"><vers num="7.0 XPU 22.4"/><vers num="7.0 XPU 22.9"/><vers num="7.0 XPU 22.10"/><vers num="7.0 XPU 20.11"/><vers num="7.0"/></prod><prod name="RealSecure Server Sensor" vendor="Internet Security Systems"><vers num="6.0 Win"/><vers num="6.0.1 Win SR1.1"/><vers num="6.0.1 Win"/><vers num="6.5 Win SR3.9"/><vers num="6.5 Win SR3.8"/><vers num="6.5 Win SR3.7"/><vers num="6.5 Win SR3.6"/><vers num="6.5 Win SR3.5"/><vers num="6.5 Win SR3.4"/><vers num="6.5 Win SR3.3"/><vers num="6.5 Win SR3.2"/><vers num="6.5 Win SR3.10"/><vers num="6.5 Win SR3.1"/><vers num="6.5 Win"/><vers num="7.0 XPU22.9"/><vers num="7.0 XPU22.8"/><vers num="7.0 XPU22.7"/><vers num="7.0 XPU22.6"/><vers num="7.0 XPU22.5"/><vers num="7.0 XPU22.4"/><vers num="7.0 XPU22.3"/><vers num="7.0 XPU22.2"/><vers num="7.0 XPU22.11"/><vers num="7.0 XPU22.10"/><vers num="7.0 XPU22.1"/></prod><prod name="RealSecure Desktop" vendor="Internet Security Systems"><vers num="3.6ecf"/><vers num="3.6ece"/><vers num="3.6ecd"/><vers num="3.6ecb"/><vers num="3.6eca"/><vers num="3.6ebz"/><vers num="7.0ebl"/><vers num="7.0ebk"/><vers num="7.0ebj"/><vers num="7.0ebh"/><vers num="7.0ebg"/><vers num="7.0ebf"/><vers num="7.0eba"/></prod><prod name="Proventia A Series XPU" vendor="Internet Security Systems"><vers num="22.9"/><vers num="22.10"/><vers num="20.11"/><vers num="22.8"/><vers num="22.7"/><vers num="22.6"/><vers num="22.5"/><vers num="22.4"/><vers num="22.3"/><vers num="22.2"/><vers num="22.1"/></prod><prod name="BlackICE Server Protection" vendor="Internet Security Systems"><vers num="3.6ccf"/><vers num="3.6cce"/><vers num="3.6ccd"/><vers num="3.6ccc"/><vers num="3.6ccb"/><vers num="3.6cca"/><vers num="3.6cbz"/></prod><prod name="RealSecure Sentry" vendor="Internet Security Systems"><vers num="3.6ecd"/><vers num="3.6ecf"/><vers num="3.6ece"/><vers num="3.6ecc"/><vers num="3.6ecb"/><vers num="3.6eca"/><vers num="3.6ebz"/></prod><prod name="Proventia G Series XPU" vendor="Internet Security Systems"><vers num="22.9"/><vers num="22.8"/><vers num="22.7"/><vers num="22.6"/><vers num="22.5"/><vers num="22.4"/><vers num="22.3"/><vers num="22.2"/><vers num="22.11"/><vers num="22.10"/><vers num="22.1"/></prod><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6ccf"/><vers num="3.6cce"/><vers num="3.6ccd"/><vers num="3.6ccc"/><vers num="3.6ccb"/><vers num="3.6cca"/><vers num="3.6cbz"/></prod><prod name="Proventia M Series XPU" vendor="Internet Security Systems"><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod><prod name="BlackICE Agent Server" vendor="Internet Security Systems"><vers num="3.6ecf"/><vers num="3.6ece"/><vers num="3.6ecd"/><vers num="3.6ecc"/><vers num="3.6ecb"/><vers num="3.6eca"/><vers num="3.6ebz"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0363" published="2004-04-15" seq="2004-0363" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15536">Symantec Norton AntiSpam 2004 LaunchCustomRuleWizard buffer overflow</ref><ref adv="1" patch="1" source="Nextgenss.com" url="http://www.nextgenss.com/advisories/antispam.txt">Norton AntiSpam Remote Buffer Overrun</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9916">bid 9916</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970870606638&amp;w=2">Norton AntiSpam Remote Buffer Overrun (#NISR19042004a)</ref><ref source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/344718">VU#344718</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11169">11169</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref></refs><vuln_soft><prod name="Norton AntiSpam" vendor="Symantec"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0364" published="2004-04-15" seq="2004-0364" severity="High" type="CVE"><desc><descript source="cve">The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15538">Norton Internet Security LaunchURL command execution</ref><ref adv="1" patch="1" source="Nextgenss.com" url="http://www.nextgenss.com/advisories/nisrce.txt">Norton Internet Security Remote Command Execution</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9915">bid 9915</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970885922442&amp;w=2">Norton Internet Security Remote Command Execution (#NISR19042004b)</ref><ref source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/549054">VU#549054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11168">11168</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2004"/><vers edition="Professional" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0365" published="2004-05-04" seq="2004-0365" severity="Medium" type="CVE"><desc><descript source="cve">The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=ethereal-dev&amp;m=107962966700423&amp;w=2">[Ethereal-dev] ethereal radius dissector vulnerability</ref><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2">LNSA-#2004-0007: Multiple security problems in Ethereal</ref><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058024904698&amp;w=2">[ GLSA 200403-07 ] Multiple remote overflows and vulnerabilities in Ethereal</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200403-07.xml">Multiple remote overflows and vulnerabilities in Ethereal</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15571">Ethereal RADIUS packet denial of service</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00013.html">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-136.html">RHSA-2004:136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-137.html">RHSA-2004:137</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/124454">VU#124454</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval879.html">OVAL879</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval891.html">OVAL891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11185">11185</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835">CLA-2004:835</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:879">oval:org.mitre.oval:def:879</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:891">oval:org.mitre.oval:def:891</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0366" published="2004-05-04" seq="2004-0366" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-469">DSA-469-1 pam-pgsql -- missing input sanitising</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15651">pam-pgsql authentication module SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/10266">10266</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11237">11237</ref></refs><vuln_soft><prod name="pam-pgsql" vendor="Leon J Breedt"><vers num="0.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0367" published="2004-05-04" seq="2004-0367" severity="Medium" type="CVE"><desc><descript source="cve">Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2">LNSA-#2004-0007: Multiple security problems in Ethereal</ref><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058024904698&amp;w=2">[ GLSA 200403-07 ] Multiple remote overflows and vulnerabilities in Ethereal</ref><ref adv="1" source="conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835">Diversas vulnerabilidades remotas</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15570">Ethereal zero-length presentation protocol selector denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-137.html">Updated Ethereal packages fix security issues</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00013.html">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref><ref source="MLIST" url="http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html">[Ethereal-dev] 20040416 Possibly incorrect CVE entry CAN-2004-0367</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-07.xml">GLSA-200403-07</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-136.html">RHSA-2004:136</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/792286">VU#792286</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval880.html">OVAL880</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval905.html">OVAL905</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11185">11185</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:880">oval:org.mitre.oval:def:880</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:905">oval:org.mitre.oval:def:905</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0368" published="2004-05-04" seq="2004-0368" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="neohapsis" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0064.html">[VulnWatch] how much fun can you have with UDP?</ref><ref adv="1" source="immunity" url="http://lists.immunitysec.com/pipermail/dailydave/2004-March/000402.html">[Dailydave] dtlogin advisory</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15581">Common Desktop Environment dtlogin utility double-free</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/179804">Common Desktop Environment (CDE) dtlogin XDMCP parser improperly deallocates memory</ref><ref source="MISC" url="http://www.immunitysec.com/downloads/dtlogin.sxw.pdf">http://www.immunitysec.com/downloads/dtlogin.sxw.pdf</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P">20040801-01-P</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-129.shtml">O-129</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1436.html">OVAL1436</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11210/">11210</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11214/">11214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11614/">11614</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11495/">11495</ref><ref source="BID" url="http://www.securityfocus.com/bid/9958/">9958</ref><ref source="BID" url="http://www.securityfocus.com/bid/9958">9958</ref><ref source="HP" url="http://www.auscert.org.au/render.html?it=4103&amp;cid=3734">HPSBUX01038</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57539-1&amp;searchclause=security">57539</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101478-1">101478</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1436">oval:org.mitre.oval:def:1436</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="DeXtop" vendor="Xi Graphics"><vers num="2.1"/><vers num="3.0"/></prod><prod name="CDE Common Desktop Environment" vendor="Open Group"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.1"/><vers num="1.2"/><vers num="2.0"/><vers num="2.1.20"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0369" published="2004-12-31" seq="2004-0369" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/181">20040826 Entrust LibKmp Library Buffer Overflow</ref><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4339">ESB-2004.0538</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-206.shtml">O-206</ref><ref source="BID" url="http://www.securityfocus.com/bid/11039">11039</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15669">isakmp-spi-size-bo(15669)</ref></refs><vuln_soft><prod name="Entrust LibKMP ISAKMP Library" vendor="Entrust"><vers num=""/></prod><prod name="VelociRaptor" vendor="Symantec"><vers num="1.5"/></prod><prod name="Enterprise Firewall" vendor="Symantec"><vers edition="Solaris" num="7.0"/><vers edition="Windows 2000_NT" num="7.0.4"/><vers edition="Solaris" num="7.0.4"/><vers edition="Windows 2000_NT" num="8.0"/><vers edition="Solaris" num="8.0"/></prod><prod name="Gateway Security 5300" vendor="Symantec"><vers num="1.0"/></prod><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0370" published="2004-05-04" seq="2004-0370" severity="Low" type="CVE"><desc><descript source="cve">The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-"></ref><ref adv="1" patch="1" source="FreeBSD" url="http://xforce.iss.net/xforce/xfdb/15662">FreeBSD KAME Project IPv6 implementation denial of service</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:06.ipv6.asc">FreeBSD-SA-04:06</ref><ref source="BID" url="http://www.securityfocus.com/bid/9992">9992</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11233">11233</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0371" published="2004-05-04" seq="2004-0371" severity="Medium" type="CVE"><desc><descript source="cve">Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debin" url="http://www.debian.org/security/2004/dsa-476">DSA-476-1 heimdal -- cross-realm</ref><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152525510907&amp;w=2">[ GLSA 200404-09 ] Cross-realm trust vulnerability in Heimdal</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15701">Heimdal cross-realm spoofing</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200404-09.xml">Cross-realm trust vulnerability in Heimdal</ref><ref source="CONFIRM" url="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/">http://www.pdc.kth.se/heimdal/advisory/2004-04-01/</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.asc">FreeBSD-SA-04:08</ref><ref source="OPENBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patch">20040530 009: SECURITY FIX: May 30, 2004</ref></refs><vuln_soft><prod name="Heimdal" vendor="KTH"><vers num="0.4e"/><vers num="0.4d"/><vers num="0.4c"/><vers num="0.4b"/><vers num="0.4a"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.5.2"/><vers num="0.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0372" published="2004-04-15" seq="2004-0372" severity="Low" type="CVE"><desc><descript source="cve">xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997911025558&amp;w=2">xine-check/xine-bugreport symlink vulnerability.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15564">xine xine-bugreport and xine-check symlink attack</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9939">bid 9939</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-477">DSA-477-1 xine-ui -- insecure temporary file creation</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-20.xml">GLSA-200404-20</ref></refs><vuln_soft><prod name="xine" vendor="xine"><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0a"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="0.9.13"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0374" published="2004-05-04" seq="2004-0374" severity="Medium" type="CVE"><desc><descript source="cve">Interchange before 5.0.1 allows remote attackers to &quot;expose the content of arbitrary variables&quot; and read or modify sensitive SQL information via an HTTP request ending with the &quot;__SQLUSER__&quot; string.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-471">DSA-471-1 interchange -- missing input sanitising</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15670">Interchange URL could allow an attacker to obtain information</ref><ref source="CONFIRM" url="http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW">http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW</ref><ref source="BID" url="http://www.securityfocus.com/bid/10005">10005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11234">11234</ref><ref source="MLIST" url="http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html">[interchange-announce] 20040329 Security Problem in Interchange</ref></refs><vuln_soft><prod name="Interchange" vendor="Interchange Development Group"><vers num="4.8.1"/><vers num="4.8.2"/><vers num="4.8.3"/><vers num="4.8.4"/><vers num="4.8.5"/><vers num="4.8.6"/><vers num="4.8.7"/><vers num="4.8.8"/><vers num="4.8.9"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-0375" published="2004-08-18" seq="2004-0375" severity="Medium" type="CVE"><desc><descript source="cve">SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9912">Symantec Client Firewall Products SYMNDIS.SYS Driver Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15936">Symantec Firewalls TCP attack denial of service</ref><ref source="CONFIRM" url="http://www.symantec.com/avcenter/security/Content/2004.04.20.html">http://www.symantec.com/avcenter/security/Content/2004.04.20.html</ref><ref source="MISC" url="http://www.eeye.com/html/Research/Upcoming/20040309.html">http://www.eeye.com/html/Research/Upcoming/20040309.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009379">1009379</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009380">1009380</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15433">norton-firewalls-dos(15433)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108275582432246&amp;w=2">20040423 EEYE: Symantec Multiple Firewall TCP Options Denial of Service</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Internet Security Pro" vendor="Symantec"><vers num="2003"/><vers num="2004"/></prod><prod name="Symantec Client Security" vendor="Symantec"><vers num="1.0"/><vers num="1.1"/></prod><prod name="Symantec Client Firewall" vendor="Symantec"><vers num="5.01"/><vers num="5.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0376" published="2004-05-04" seq="2004-0376" severity="Medium" type="CVE"><desc><descript source="cve">oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057965417879&amp;w=2">[ GLSA 200403-08 ] oftpd DoS vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-473">DSA-473-1 oftpd -- denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9980">OFTPD Port Argument Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15622">oftpd PORT denial of service</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-08.xml">GLSA-200403-08</ref><ref source="CONFIRM" url="http://www.time-travellers.org/oftpd/oftpd-dos.html">http://www.time-travellers.org/oftpd/oftpd-dos.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11220">11220</ref></refs><vuln_soft><prod name="oftpd" vendor="oftpd"><vers num="0.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0377" published="2004-05-04" seq="2004-0377" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the win32_stat function for (1) ActiveState&apos;s ActivePerl and (2) Larry Wall&apos;s Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-April/019794.html">[Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15732">Perl and ActivePerl win32_stat buffer overflow</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/722414">Perl vulnerable to buffer overflow in win32_stat()</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html">20040405 iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref><ref source="CONFIRM" url="http://public.activestate.com/cgi-bin/perlbrowse?patch=22552">http://public.activestate.com/cgi-bin/perlbrowse?patch=22552</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118694327979&amp;w=2">20040405 [Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref><ref source="" url="http://www.idefense.com/application/poi/display?id=93&amp;type=vulnerabilities"></ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.8.3" prev="1"/></prod><prod name="ActivePerl" vendor="ActiveState"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0379" published="2004-05-04" seq="2004-0379" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118352303273&amp;w=2">Multiple XSS vulnerabilities in Microsoft SharePoint Portal Server</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15729">Microsoft SharePoint Portal Server cross-site scripting</ref></refs><vuln_soft><prod name="SharePoint Portal Server" vendor="Microsoft"><vers num="2001 SP2A"/><vers num="2001 SP2"/><vers num="2001 SP1"/><vers num="2001"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0380" published="2004-05-04" seq="2004-0380" severity="High" type="CVE"><desc><descript source="cve">The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the &quot;MHTML URL Processing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/354447">Microsoft Internet Explorer Unspecified CHM File Processing Arbitrary Code Execution Vulnerability (bid 9658)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/358913">IE ms-its: and mk:@MSITStore: vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx">Cumulative Security Update for Outlook Express (837009)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15705">Microsoft Outlook Express MHTML URL allows execution of code</ref><ref source="MISC" url="http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php">http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/323070">VU#323070</ref><ref source="BID" url="http://www.securityfocus.com/bid/9658">9658</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1010.html">OVAL1010</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1028.html">OVAL1028</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval882.html">OVAL882</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval990.html">OVAL990</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref source="BID" url="http://www.securityfocus.com/bid/9105">9105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1010">oval:org.mitre.oval:def:1010</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1028">oval:org.mitre.oval:def:1028</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:882">oval:org.mitre.oval:def:882</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:990">oval:org.mitre.oval:def:990</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10523">10523</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="5.5"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0381" published="2004-05-04" seq="2004-0381" severity="Low" type="CVE"><desc><descript source="cve">mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023246916294&amp;w=2">mysqlbug tmpfile/symlink vulnerability</ref><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2">[OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9976">mysqlbug</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15617">MySQL mysqlbug script symlink attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023246916294&amp;w=2">20040324 mysqlbug tmpfile/symlink vulnerability.</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-483">DSA-483</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-20.xml">GLSA-200405-20</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:034">MDKSA-2004:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-569.html">RHSA-2004:569</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">RHSA-2004:597</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034">MDKSA-2004:034</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.20.32a"/><vers num="3.22.26"/><vers num="3.22.27"/><vers num="3.22.28"/><vers num="3.22.29"/><vers num="3.22.30"/><vers num="3.22.32"/><vers num="3.23.2"/><vers num="3.23.3"/><vers num="3.23.5"/><vers num="3.23.8"/><vers num="3.23.9"/><vers num="3.23.10"/><vers num="3.23.22"/><vers num="3.23.23"/><vers num="3.23.24"/><vers num="3.23.25"/><vers num="3.23.26"/><vers num="3.23.27"/><vers num="3.23.28 gamma"/><vers num="3.23.28"/><vers num="3.23.29"/><vers num="3.23.30"/><vers num="3.23.31"/><vers num="3.23.32"/><vers num="3.23.33"/><vers num="3.23.34"/><vers num="3.23.36"/><vers num="3.23.37"/><vers num="3.23.38"/><vers num="3.23.39"/><vers num="3.23.40"/><vers num="3.23.41"/><vers num="3.23.42"/><vers num="3.23.43"/><vers num="3.23.44"/><vers num="3.23.45"/><vers num="3.23.46"/><vers num="3.23.47"/><vers num="3.23.48"/><vers num="3.23.49"/><vers num="3.23.50"/><vers num="3.23.51"/><vers num="3.23.52"/><vers num="3.23.53a"/><vers num="3.23.53"/><vers num="3.23.54a"/><vers num="3.23.54"/><vers num="3.23.55"/><vers num="3.23.56"/><vers num="3.23.58"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.0.14"/><vers num="4.0.15"/><vers num="4.0.18"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0382" published="2004-05-04" seq="2004-0382" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15769">Mac OS X CUPS undisclosed configuration security issue</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00047.html">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0383" published="2004-05-04" seq="2004-0383" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to &quot;the handling of HTML-formatted email.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15768">Mac OS X undisclosed Mail security issue</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00047.html">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0385" published="2004-06-01" seq="2004-0385" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener.  NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple &quot;vulnerabilities.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="InAccess Networks" url="http://www.inaccessnetworks.com/ian/services/secadv01.txt">Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref><ref adv="1" patch="1" source="Oracle" url="http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf">Security Alert 66</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/413006">VU#413006</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945649127635&amp;w=2">20040316 new security alert #66 issued in Oracle web cache</ref><ref source="BID" url="http://www.securityfocus.com/bid/9868">9868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15463">oracle-web-cache-vulnerabilities(15463)</ref><ref source="OSVDB" url="http://www.osvdb.org/4249">4249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11118">11118</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144419001770&amp;w=2">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i"/></prod><prod name="Oracle9iAS Web Cache" vendor="Oracle"><vers num="9.0.4.0.0"/><vers num="9.0.3.1.0"/><vers num="9.0.2.3.0"/><vers num="9.0.0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0386" published="2004-05-04" seq="2004-0386" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15675">MPlayer header buffer overflow</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/359025">20040330 Heap overflow in MPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067020624076&amp;w=2">20040330 MPlayer Security Advisory #002 - HTTP parsing vulnerability</ref><ref source="CONFIRM" url="http://www.mplayerhq.hu/homepage/design6/news.html">http://www.mplayerhq.hu/homepage/design6/news.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-13.xml">GLSA-200403-13</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/723910">VU#723910</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10008">10008</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11259">11259</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:026">MDKSA-2004:026</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/><vers num="1.2"/><vers num="1.1a"/><vers num="0.7"/><vers num="0.5"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.2"/></prod><prod name="Mplayer" vendor="Mplayer"><vers num="0.90"/><vers num="0.90 pre"/><vers num="0.90 rc"/><vers num="0.91"/><vers num="1.0 pre1"/><vers num="1.0 pre2"/><vers num="1.0 pre3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0387" published="2004-06-01" seq="2004-0387" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108135350810135&amp;w=2">20040307 REAL One Player R3T File Format Stack Overflow</ref><ref adv="1" patch="1" source="NGSSoftware" url="http://www.ngssoftware.com/advisories/realr3t.txt">REAL One Player R3T File Format Stack Overflow</ref><ref adv="1" patch="1" source="Real" url="http://www.service.real.com/help/faq/security/040406_r3t/en/"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15774">realplayer-r3t-bo(15774)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108135350810135&amp;w=2">20040307 REAL One Player R3T File Format Stack Overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html">20040307 REAL One Player R3T File Format Stack Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/10070">10070</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=4977">4977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11314">11314</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="8.0"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num=""/><vers num="10 Beta"/><vers edition="Enterprise" num="Any"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0388" published="2004-06-01" seq="2004-0388" severity="Low" type="CVE"><desc><descript source="cve">The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-483">DSA-483</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-20.xml">Insecure Temporary File Creation In MySQL</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:034">MDKSA-2004:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-569.html">RHSA-2004:569</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">RHSA-2004:597</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref><ref source="" url="http://dev.mysql.com/doc/mysql/en/news-4-1-2.html"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="BID" url="http://www.securityfocus.com/bid/10142">10142</ref><ref source="OSVDB" url="http://www.osvdb.org/6421">6421</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009784">1009784</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11223/">11223</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15883">mysql-mysqldmulti-symlink(15883)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034">MDKSA-2004:034</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.33"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0389" published="2004-06-01" seq="2004-0389" severity="High" type="CVE"><desc><descript source="cve">RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108207428402378&amp;w=2">20040415 [Full-Disclosure] iDEFENSE Security Advisory 04.15.04: RealNetworks Helix Universal Server Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=102&amp;type=vulnerabilities">RealNetworks Helix Universal Server Denial of Service Vulnerability</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=102&amp;type=vulnerabilities">20040415 RealNetworks Helix Universal Server Denial of Service Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/10157">10157</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11395">11395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15880">helix-get-dos(15880)</ref></refs><vuln_soft><prod name="Helix Universal Server" vendor="RealNetworks"><vers num="9.0.1"/><vers num="9.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0390" published="2004-12-31" seq="2004-0390" severity="High" type="CVE"><desc><descript source="cve">SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html">20040510 OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol</ref><ref source="SCO" url="http://www.securityfocus.com/advisories/6684">SCOSA-2004.5</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16113">openserver-x-session-insecure(16113)</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0391" published="2004-06-01" seq="2004-0391" severity="High" type="CVE"><desc><descript source="cve">Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml">20040407 A Default Username and Password in WLSE and HSE Devices</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/659228">VU#659228</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-111.shtml">O-111</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15773">cisco-default-password(15773)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10076">10076</ref></refs><vuln_soft><prod name="Hosting Solution Engine" vendor="Cisco"><vers num="1.7"/><vers num="1.7.0"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Wireless LAN Solution Engine" vendor="Cisco"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0392" published="2004-06-14" seq="2004-0392" severity="Medium" type="CVE"><desc><descript source="cve">racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) &quot;Security Association Next Payload&quot; and (2) &quot;RESERVED&quot; fields.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="vuxml" url="http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html">40fcf20f-8891-11d8-90d1-0020ed76ef5a</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15893">racoon-isakmp-dos(15893)</ref><ref source="CONFIRM" url="http://orange.kame.net/dev/query-pr.cgi?">http://orange.kame.net/dev/query-pr.cgi?</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt">SCOSA-2005.10</ref><ref source="" url="http://orange.kame.net/dev/query-pr.cgi?pr=555"></ref></refs><vuln_soft><prod name="racoon" vendor="KAME"><vers num="2004-04-07a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0393" published="2004-12-06" seq="2004-0393" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108810992313652&amp;w=2">20040624 Rlpr Advisory</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-524">DSA-524</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10578">Bugtraq id 10578</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16453">rlpr-msg-format-string(16453)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10578">10578</ref></refs><vuln_soft><prod name="rlpr" vendor="rlpr"><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0394" published="2004-08-18" seq="2004-0394" severity="Low" type="CVE"><desc><descript source="cve">A &quot;potential&quot; buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15953">Linux Kernel panic function buffer overflow</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.com/de/security/2004_10_kernel.html">SUSE Security Announcement: kernel</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref adv="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">Correes para vulnerabilidades do kernel</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref><ref source="MLIST" url="http://lwn.net/Articles/81773/">[fedora-announce] 20040422 Fedora alert FEDORA-2004-111 (kernel)</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc">20040504-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc">20040505-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="BID" url="http://www.securityfocus.com/bid/10233">10233</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0395" published="2004-12-06" seq="2004-0395" severity="High" type="CVE"><desc><descript source="cve">The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/><env/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-509">DSA-509</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10437">bugtraq id 10437</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16273">gatos-xatitv-gain-privileges(16273)</ref></refs><vuln_soft><prod name="gatos" vendor="gatos"><vers num=".5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0396" published="2004-06-14" seq="2004-0396" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/192038">VU#192038</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108507880526969&amp;w=2">20040520 [ GLSA 200405-12 ] CVS heap overflow vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-190.html">RHSA-2004:190</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-505">DSA-505</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498454829020&amp;w=2">20040519 Advisory 07/2004: CVS remote vulnerability</ref><ref source="MISC" url="http://security.e-matters.de/advisories/072004.html">http://security.e-matters.de/advisories/072004.html</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-147A.html">TA04-147A</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:10.cvs.asc">FreeBSD-SA-04:10</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc">NetBSD-SA2004-008</ref><ref source="SUSE" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html">SuSE-SA:2004:013</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:048">MDKSA-2004:048</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-12.xml">GLSA-200405-12</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval970.html">OVAL970</ref><ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html">20040519 Advisory 07/2004: CVS remote vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html">20040519 Advisory 07/2004: CVS remote vulnerability</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-147.shtml">O-147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16193">cvs-entry-line-bo(16193)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10384">10384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11641">11641</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11647">11647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11651">11651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11652">11652</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11674">11674</ref><ref source="OSVDB" url="http://www.osvdb.org/6305">6305</ref><ref source="OPENBSD" url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108508894405639&amp;w=2">20040520 cvs server buffer overflow vulnerability</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2">FEDORA-2004-1620</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.395865">SSA:2004-140-01</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500040719512&amp;w=2">20040519 [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:970">oval:org.mitre.oval:def:970</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:048">MDKSA-2004:048</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.11"/><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0397" published="2004-07-07" seq="2004-0397" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10386">bugtraq id 10386</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16191">subversion-date-parsing-command-execution(16191)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/363814">20040519 [OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498676517697&amp;w=2">20040519 Advisory 08/2004: Subversion remote vulnerability</ref><ref adv="1" source="FEDORA" url="http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html">FEDORA-2004-128</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html">20040519 Advisory 08/2004: Subversion remote vulnerability</ref><ref source="MISC" url="http://security.e-matters.de/advisories/082004.html">http://security.e-matters.de/advisories/082004.html</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1748">FLSA:1748</ref><ref source="" url="http://subversion.tigris.org/svn-sscanf-advisory.txt">http://subversion.tigris.org/svn-sscanf-advisory.txt</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml">GLSA-200405-14</ref><ref source="OSVDB" url="http://www.osvdb.org/6301">6301</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11642">11642</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11675">11675</ref></refs><vuln_soft><prod name="Subversion" vendor="Subversion"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0398" published="2004-07-07" seq="2004-0398" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108508006713614&amp;w=2">20040520 [ GLSA 200405-15 ] cadaver heap-based buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108507887710742&amp;w=2">20040520 [ GLSA 200405-13 ] neon heap-based buffer overflow</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:049">MDKSA-2004:049</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000841">CLA-2004:841</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-191.html">RHSA-2004:191</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-506">DSA-506</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-507">DSA-507</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1552">FEDORA-2004-1552</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-13.xml">GLSA-200405-13</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-15.xml">GLSA-200405-15</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-148.shtml">O-148</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10385">10385</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16192">neon-library-nerfc1036parse-bo(16192)</ref><ref source="OSVDB" url="http://www.osvdb.org/6302">6302</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11638">11638</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11650">11650</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11673">11673</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498433632333&amp;w=2">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500057108022&amp;w=2">20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:049">MDKSA-2004:049</ref></refs><vuln_soft><prod name="Cadaver WebDAV Client" vendor="Cadaver"><vers num="0.22.1"/><vers num="0.22.0"/><vers num="0.21.0"/><vers num="0.20.5"/><vers num="0.20.4"/><vers num="0.20.3"/><vers num="0.20.2"/><vers num="0.20.1"/><vers num="0.20.0"/></prod><prod name="Subversion" vendor="Subversion"><vers num=""/></prod><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.2"/></prod><prod name="Neon Client Library" vendor="Neon"><vers num="0.24.4"/><vers num="0.24.3"/><vers num="0.24.2"/><vers num="0.24.1"/><vers num="0.24"/><vers num="0.23.8"/><vers num="0.23.7"/><vers num="0.23.6"/><vers num="0.23.5"/><vers num="0.23.4"/><vers num="0.23.3"/><vers num="0.23.2"/><vers num="0.23.1"/><vers num="0.23"/><vers num="0.19.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0399" published="2004-07-07" seq="2004-0399" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021015.html">20040506 Buffer overflows in exim, yet still exim much better than windows</ref><ref adv="1" patch="1" source="Quninski" url="http://www.guninski.com/exim1.html">Georgi Guninski security advisory #68</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-501">DSA-501</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-502">DSA-502</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16079">exim-requireverify-bo(16079)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html">20040506 Buffer overflows in exim, yet still exim much better than windows</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11558">11558</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="3.35"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0400" published="2004-07-07" seq="2004-0400" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021015.html">20040506 Buffer overflows in exim, yet still exim much better than windows</ref><ref adv="1" patch="1" source="Quininski" url="http://www.guninski.com/exim1.html">Georgi Guninski security advisory #68</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-501">DSA-501</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-502">DSA-502</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16077">exim-headerschecksyntax-bo(16077)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html">20040506 Buffer overflows in exim, yet still exim much better than windows</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="4.32" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0401" published="2004-07-07" seq="2004-0401" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Backports" url="http://www.backports.org/changelog.html"></ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16157">libtasn1-der-parsing(16157)</ref><ref source="" url="http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog">http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog</ref><ref source="BID" url="http://www.securityfocus.com/bid/10360">10360</ref><ref source="OSVDB" url="http://www.osvdb.org/15126">15126</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010159">1010159</ref></refs><vuln_soft><prod name="libtasn1" vendor="Free Software Foundation Inc."><vers num="0.1"/><vers num="0.1.0"/><vers num="0.1.1"/><vers num="0.2.0"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="0.2.5"/><vers num="0.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0402" published="2004-07-07" seq="2004-0402" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-508">DSA-508</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10403">XPCD XPCD-SVGA Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16236">xpcd xpcd-svga pcd_open buffer overflow</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:053">MDKSA-2004:053</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053">MDKSA-2004:053</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="xpcd" vendor="xpcd"><vers num="2.08"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0403" published="2004-06-01" seq="2004-0403" severity="Medium" type="CVE"><desc><descript source="cve">Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="VuXML" url="http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html">ccd698df-8e20-11d8-90d1-0020ed76ef5a</ref><ref source="KAME" url="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&amp;r2=1.181"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108283512401974&amp;w=2">20040424 [ GLSA 200404-17 ] ipsec-tools and iputils contain a remote DoS vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-165.html">RHSA-2004:165</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-17.xml">GLSA-200404-17</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069">MDKSA-2004:069</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt">SCOSA-2005.10</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc">20040506-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval984.html">OVAL984</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=232288"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10172">10172</ref><ref source="OSVDB" url="http://www.osvdb.org/5491">5491</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009937">1009937</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11410">11410</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11877">11877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15893">racoon-isakmp-dos(15893)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:984">oval:org.mitre.oval:def:984</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num="2004-04-08a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0404" published="2004-07-07" seq="2004-0404" severity="Low" type="CVE"><desc><descript source="cve">logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-488">DSA-488</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10162">10162</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11399">11399</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15888">logcheck-directory-symlink(15888)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:155">MDKSA-2004:155</ref></refs><vuln_soft><prod name="logcheck" vendor="Psionic"><vers num="1.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0405" published="2004-06-01" seq="2004-0405" severity="Medium" type="CVE"><desc><descript source="cve">CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-486">DSA-486</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc">FreeBSD-SA-04:07</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2"> [FLSA-2004:1620] Updated cvs resolves security vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1060.html">OVAL1060</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-13.xml">GLSA-200404-13</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15891">cvs-dotdot-directory-traversal(15891)</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181">SSA:2004-108-02</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1060">oval:org.mitre.oval:def:1060</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0407" published="2004-06-01" seq="2004-0407" severity="Low" type="CVE"><desc><descript source="cve">The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213782629001&amp;w=2">20040416 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]</ref><ref adv="1" patch="1" source="Macromedia" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html">MPSB04-06</ref><ref source="BID" url="http://www.securityfocus.com/bid/10158">10158</ref><ref source="OSVDB" url="http://www.osvdb.org/5402">5402</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009825">1009825</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11392">11392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15882">coldfusion-upload-file-dos(15882)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0408" published="2004-09-28" seq="2004-0408" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-494">DSA-494-1 ident2 -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10192">Michael Bacarella IDent2 Daemon Child_Service Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15938">ident2 child_service buffer overflow</ref></refs><vuln_soft><prod name="ident2" vendor="Michael Bacarella"><vers num=".999c"/><vers num="1.3_1"/><vers num="1.3"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0409" published="2004-06-01" seq="2004-0409" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><input bound="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NL.linux.org" url="http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html">[xchat-announce] 20040405 xchat 2.0.x Socks5 Vulnerability</ref><ref adv="1" patch="1" source="Xchat" url="http://www.xchat.org/"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258002427226&amp;w=2">DSA-493</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-177.html">RHSA-2004:177</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239528906383&amp;w=2">20040419 [ GLSA 200404-15 ] XChat 2.0.x SOCKS5 Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-585.html">RHSA-2004:585</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-15.xml">GLSA-200404-15</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_123013">FLSA:123013</ref></refs><vuln_soft><prod name="XChat" vendor="XChat"><vers num="1.8.0"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5"/><vers num="1.8.6"/><vers num="1.8.7"/><vers num="1.8.8"/><vers num="1.8.9"/><vers num="1.9.0"/><vers num="1.9.1"/><vers num="1.9.2"/><vers num="1.9.3"/><vers num="1.9.4"/><vers num="1.9.5"/><vers num="1.9.6"/><vers num="1.9.7"/><vers num="1.9.8"/><vers num="1.9.9"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/></prod></vuln_soft></entry><entry modified="2006-02-08" name="CVE-2004-0410" published="2004-12-31" reject="1" seq="2004-0410" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0411" published="2004-07-07" seq="2004-0411" severity="High" type="CVE"><desc><descript source="cve">The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter &quot;-&quot; characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/363225">20040513 Opera Telnet URI Handler Vulnerability also applies to other browsers</ref><ref adv="1" patch="1" source="KDE" url="http://www.kde.org/info/security/advisory-20040517-1.txt"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108499410427739&amp;w=2">20040519 [ GLSA 200405-11 ] KDE URI Handler Vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-222.html">RHSA-2004:222</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_14_kdelibs.html">SuSE-SA:2003:014</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-11.xml">GLSA-200405-11</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-518">DSA-518</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval954.html">OVAL954</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-146.shtml">O-146</ref><ref source="BID" url="http://www.securityfocus.com/bid/10358">10358</ref><ref source="OSVDB" url="http://www.osvdb.org/6107">6107</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11602">11602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16163">kde-url-handler-gain-access(16163)</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/6717">FEDORA-2004-121</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/6743">FEDORA-2004-122</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481412427344&amp;w=2">20040517 KDE Security Advisory: URI Handler Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000843">CLA-2004:843</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.362635">SSA:2004-238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:954">oval:org.mitre.oval:def:954</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num=""/></prod><prod name="Konqueror" vendor="KDE"><vers num="3.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0412" published="2004-08-18" seq="2004-0412" severity="Medium" type="CVE"><desc><descript source="cve">Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-04.xml">Mailman: Member password disclosure vulnerability</ref><ref adv="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842">Diversas correes para mailman</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034869927955&amp;w=2"> [FLSA-2004:1734] Updated mailman resolves security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10412">GNU Mailman Unspecified Password Retrieval Vulnerability</ref><ref source="MLIST" url="http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html">[Mailman-Announce] 20040515 RELEASED Mailman 2.1.5</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051">MDKSA-2004:051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11701">11701</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16256">mailman-obtain-password(16256)</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1b1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0413" published="2004-08-06" seq="2004-0413" severity="High" type="CVE"><desc><descript source="cve">libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10519">Subversion SVN Protocol Parser Remote Integer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16396">Subversion svn protocol buffer overflow</ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-07.xml">Subversion: Remote heap overflow</ref><ref source="CONFIRM" url="http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt">http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/6847">FEDORA-2004-165</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1748">FLSA:1748</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_18_subversion.html">SuSE-SA:2004:018</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/365836">20041012 [FMADV] Subversion &lt;= 1.04 Heap Overflow</ref></refs><vuln_soft><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="2.0"/></prod><prod name="Subversion" vendor="Subversion"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0414" published="2004-08-06" seq="2004-0414" severity="High" type="CVE"><desc><descript source="cve">CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed &quot;Entry&quot; lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2">[OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-06.xml">CVS: additional DoS and arbitrary code execution vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-517">DSA-517-1 cvs -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10499">CVS Multiple Vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref><ref source="MISC" url="http://security.e-matters.de/advisories/092004.html">http://security.e-matters.de/advisories/092004.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-233.html">RHSA-2004:233</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval993.html">OVAL993</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:993">oval:org.mitre.oval:def:993</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="1.3"/><vers num="2.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/><vers num="3.4"/><vers num="3.5"/></prod><prod name="CVS" vendor="CVS"><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/><vers num="1.11.5"/><vers num="1.11.6"/><vers num="1.11.10"/><vers num="1.11.11"/><vers num="1.11.14"/><vers num="1.11.15"/><vers num="1.11.16"/><vers num="1.12.1"/><vers num="1.12.2"/><vers num="1.12.5"/><vers num="1.12.7"/><vers num="1.12.8"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0415" published="2004-11-23" seq="2004-0415" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-418.html">Updated kernel packages fix security issues</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16877">Linux kernel offset pointer information disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10852/">Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml">GLSA-200408-24</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:087">MDKSA-2004:087</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">RHSA-2004:413</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000879">CLA-2004:879</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0416" published="2004-08-06" seq="2004-0416" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2"> [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-519">DSA-519-1 cvs -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10499/">CVS Multiple Vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref><ref source="MISC" url="http://security.e-matters.de/advisories/092004.html">http://security.e-matters.de/advisories/092004.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200406-06.xml">GLSA-200406-06</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-233.html">RHSA-2004:233</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval994.html">OVAL994</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:994">oval:org.mitre.oval:def:994</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="1.3"/><vers num="2.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/><vers num="3.4"/><vers num="3.5"/></prod><prod name="CVS" vendor="CVS"><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/><vers num="1.11.5"/><vers num="1.11.6"/><vers num="1.11.10"/><vers num="1.11.11"/><vers num="1.11.14"/><vers num="1.11.15"/><vers num="1.11.16"/><vers num="1.12.1"/><vers num="1.12.2"/><vers num="1.12.5"/><vers num="1.12.7"/><vers num="1.12.8"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0417" published="2004-08-06" seq="2004-0417" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the &quot;Max-dotdot&quot; CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2">[OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-06.xml">CVS: additional DoS and arbitrary code execution vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-519">DSA-519-1 cvs -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10499">CVS Multiple Vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref><ref source="MISC" url="http://security.e-matters.de/advisories/092004.html">http://security.e-matters.de/advisories/092004.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-233.html">RHSA-2004:233</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1001.html">OVAL1001</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1001">oval:org.mitre.oval:def:1001</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="1.3"/><vers num="2.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/><vers num="3.4"/><vers num="3.5"/></prod><prod name="CVS" vendor="CVS"><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/><vers num="1.11.5"/><vers num="1.11.6"/><vers num="1.11.10"/><vers num="1.11.11"/><vers num="1.11.14"/><vers num="1.11.15"/><vers num="1.11.16"/><vers num="1.12.1"/><vers num="1.12.2"/><vers num="1.12.5"/><vers num="1.12.7"/><vers num="1.12.8"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0418" published="2004-08-06" seq="2004-0418" severity="High" type="CVE"><desc><descript source="cve">serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an &quot;out-of-bounds&quot; write for a single byte to execute arbitrary code or modify critical program data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2">[OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-06.xml">CVS: additional DoS and arbitrary code execution vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-519">DSA-519-1 cvs -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10499/">CVS Multiple Vulnerabilities</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref><ref source="MISC" url="http://security.e-matters.de/advisories/092004.html">http://security.e-matters.de/advisories/092004.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-233.html">RHSA-2004:233</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1003.html">OVAL1003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1003">oval:org.mitre.oval:def:1003</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058">MDKSA-2004:058</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num=""/><vers num="1.3"/><vers num="2.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/><vers num="3.4"/><vers num="3.5"/></prod><prod name="CVS" vendor="CVS"><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/><vers num="1.11.5"/><vers num="1.11.6"/><vers num="1.11.10"/><vers num="1.11.11"/><vers num="1.11.14"/><vers num="1.11.15"/><vers num="1.11.16"/><vers num="1.12.1"/><vers num="1.12.2"/><vers num="1.12.5"/><vers num="1.12.7"/><vers num="1.12.8"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0419" published="2004-08-18" seq="2004-0419" severity="High" type="CVE"><desc><descript source="cve">XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-05.xml">XFree86, X.org: XDM ignores requestPort setting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10423">XFree86 XDM RequestPort Random Open TCP Socket Vulnerability</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:073">MandrakeSoft Security Advisory MDKSA-2004:073 : XFree86</ref><ref source="CONFIRM" url="http://bugs.xfree86.org/show_bug.cgi?id=1376">http://bugs.xfree86.org/show_bug.cgi?id=1376</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#xdm">20040526 008: SECURITY FIX: May 26, 2004</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-478.html">RHSA-2004:478</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-001.shtml">P-001</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010306">1010306</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12019">12019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16264">xdm-socket-gain-access(16264)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.7.0"/></prod><prod name="xdm" vendor="XFree86 Project"><vers num="CVS"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0420" published="2004-07-07" seq="2004-0420" severity="High" type="CVE"><desc><descript source="cve">The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/351379">20040127 GOOROO CROSSING: File Spoofing Internet Explorer 6</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9510">bugtraq id 9510</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-024.asp">MS04-024</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/106324">VU#106324</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2245.html">OVAL2245</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2381.html">OVAL2381</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2894.html">OVAL2894</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3533.html">OVAL3533</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3386.html">OVAL3386</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3604.html">OVAL3604</ref><ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2004-01/0300.html">20040127 RE: GOOROO CROSSING: File Spoofing Internet Explorer 6</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10736/">10736</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14964">ie-clsid-file-extension-spoofing(14964)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2245">oval:org.mitre.oval:def:2245</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2381">oval:org.mitre.oval:def:2381</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2894">oval:org.mitre.oval:def:2894</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3533">oval:org.mitre.oval:def:3533</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3386">oval:org.mitre.oval:def:3386</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3604">oval:org.mitre.oval:def:3604</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0.2800.1106" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0421" published="2004-08-18" seq="2004-0421" severity="Medium" type="CVE"><desc><descript source="cve">The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16022">libpng PNG image denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10244">LibPNG Broken PNG Out Of Bounds Access Denial Of Service Vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-180.html">Updated libpng packages fix crash</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00056.html">APPLE-SA-2004-09-09</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-498">DSA-498</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:040">MDKSA-2004:040</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-181.html">RHSA-2004:181</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334922320309&amp;w=2">20040429 [OpenPKG-SA-2004.017] OpenPKG Security Advisory (png)</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2">2004-0025</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451350029261&amp;w=2">FEDORA-2004-105</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451353608968&amp;w=2">FEDORA-2004-106</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval971.html">OVAL971</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:971">oval:org.mitre.oval:def:971</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22958">22958</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:040">MDKSA-2004:040</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="libpng" vendor="Red Hat"><vers edition="i386" num="1.2.2.16"/><vers edition="i386" num="1.2.2.20"/><vers edition="i386 dev" num="1.2.2.16"/><vers edition="i386 dev" num="1.2.2.20"/><vers edition="i386" num="10.1.0.13.11"/><vers edition="i386" num="10.1.0.13.8"/><vers edition="i386 dev" num="10.1.0.13.11"/><vers edition="i386 dev" num="10.1.0.13.8"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="libpng" vendor="Greg Roelofs"><vers num="1.0"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.0.9"/><vers num="1.0.10"/><vers num="1.0.11"/><vers num="1.0.12"/><vers num="1.0.13"/><vers num="1.0.14"/></prod><prod name="libpng3" vendor="Greg Roelofs"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="1.3"/><vers num="2.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0422" published="2004-07-07" seq="2004-0422" severity="Low" type="CVE"><desc><descript source="cve">flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-500">DSA-500</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16027">flim-insecure-temporary-file(16027)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-344.html">RHSA-2004:344</ref></refs><vuln_soft><prod name="flim" vendor="GNU"><vers num="1.14.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0423" published="2004-07-07" seq="2004-0423" severity="Low" type="CVE"><desc><descript source="cve">The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239608131119&amp;w=2">20040418 ssmtp insecure file creation</ref></refs><vuln_soft><prod name="ssmtp" vendor="ssmtp"><vers num="2.50.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0424" published="2004-07-07" seq="2004-0424" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISEC" url="http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt">20040420 Linux kernel setsockopt MCAST_MSFILTER integer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108253171301153&amp;w=2">20040420 Linux kernel setsockopt MCAST_MSFILTER integer overflow</ref><ref adv="1" patch="1" source="Engarde" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10179">bugtraq id 10179</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15907">linux-ipsetsockopt-integer-bo(15907)</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-183.html">RHSA-2004:183</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc">20040504-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval939.html">OVAL939</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.659586">SSA:2004-119</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-183.html">RHSA-2004:183</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:939">oval:org.mitre.oval:def:939</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.24 ow1"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="current"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0425" published="2004-08-18" seq="2004-0425" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10198">Netegrity SiteMinder Affiliate Agent Heap Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15950">SiteMinder Affiliate Agent SMPROFILE cookie buffer overflow</ref><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a042204-1.txt">SiteMinder Affiliate Agent Cookie Overflow</ref></refs><vuln_soft><prod name="SideMinder Affiliate Agent" vendor="Netegrity"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0426" published="2004-07-07" seq="2004-0426" severity="Medium" type="CVE"><desc><descript source="cve">rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module&apos;s path.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="rsync" url="http://rsync.samba.org/"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-499">DSA-499</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:042">MDKSA-2004:042</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515912212018&amp;w=2">20040521 [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync)</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-192.html">RHSA-2004:192</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-10.xml">GLSA-200407-10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval967.html">OVAL967</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/misc/2004/TSL-2004-0024-rsync.asc.txt">TSL-2004-0024</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-134.shtml">O-134</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref source="BID" url="http://www.securityfocus.com/bid/10247">10247</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11514">11514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11515">11515</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11523">11523</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11537">11537</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11583">11583</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11669">11669</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11688">11688</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11993">11993</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12054">12054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16014">rsync-write-files(16014)</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.403462">SSA:2004-124-01</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:967">oval:org.mitre.oval:def:967</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:042">MDKSA-2004:042</ref></refs><vuln_soft><prod name="rsync" vendor="Andrew Tridgell"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0427" published="2004-07-07" seq="2004-0427" severity="Low" type="CVE"><desc><descript source="cve">The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108139073506983&amp;w=2">[linux-kernel] 20040408 [PATCH]: 2.4/2.6 do_fork() error path memory leak</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref><ref adv="1" patch="1" source="Engarde" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc">20040504-01-U</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc">20040505-01-U</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-111.shtml">FEDORA-2004-111</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-255.html">RHSA-2004:255</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA">http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A">http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2819.html">OVAL2819</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-260.html">RHSA-2004:260</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-327.html">RHSA-2004:327</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-164.shtml">O-164</ref><ref source="BID" url="http://www.securityfocus.com/bid/10221">10221</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11429">11429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11486">11486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11541">11541</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11861">11861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11892">11892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16002">linux-dofork-memory-leak(16002)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2819">oval:org.mitre.oval:def:2819</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0428" published="2004-05-03" seq="2004-0428" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to &quot;the handling of an environment variable,&quot; has unknown attack vectors and unknown impact.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.virus.org/macsec-0405/msg00000.html">APPLE-SA-2004-05-03</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4070">ESB-2004.0314</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1010045">http://securitytracker.com/id?1010045</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10270">10270</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11539">11539</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16051">macos-corefoundation-environment(16051)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0429" published="2004-12-31" seq="2004-0429" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability related to &quot;the handling of large requests&quot; in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">20040503 [product-security@apple.com: APPLE-SA-2004-05-03 Security Update 2004-05-03]</ref><ref patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/May/1010045.html">http://www.securitytracker.com/alerts/2004/May/1010045.html</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/May/msg00000.html">APPLE-SA-2004-05-03</ref><ref patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4070">ESB-2004.0314</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11539/">11539</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1010045">1010045</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-138.shtml">O-138</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16053">macos-radmin-large-request(16053)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0430" published="2004-07-07" seq="2004-0430" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="@stake" url="http://www.atstake.com/research/advisories/2004/a050304-1.txt">A050304-1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16049">applefileserver-afp-pathname-bo(16049)</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00049.html">APPLE-SA-2004-05-03</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5QP0115CUO.html">http://www.securiteam.com/securitynews/5QP0115CUO.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/648406">VU#648406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11539">11539</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010039">1010039</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3" prev="1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0431" published="2004-07-07" seq="2004-0431" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large &quot;number of entries&quot; field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360110618389&amp;w=2">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108356485013237&amp;w=2">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16026">quicktime-heap-bo(16026)</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00048.html">APPLE-SA-2004-04-30</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/782958">VU#782958</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="6.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0432" published="2004-08-18" seq="2004-0432" severity="High" type="CVE"><desc><descript source="cve">ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10252">ProFTPD CIDR Access Control Rule Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16038">ProFTPD CIDR entry ACL bypass</ref><ref source="CONFIRM" url="http://bugs.proftpd.org/show_bug.cgi?id=2267">http://bugs.proftpd.org/show_bug.cgi?id=2267</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:041">MDKSA-2004:041</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2">2004-0025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11527">11527</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335051011341&amp;w=2">20040430 [OpenPKG-SA-2004.018] OpenPKG Security Advisory (proftpd)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:041">MDKSA-2004:041</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0433" published="2004-08-18" seq="2004-0433" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Transport (RDT) packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16019">MPlayer and xine-lib RTSP RDT buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-24.xml">MPlayer, xine-lib: vulnerabilities in RTSP stream handling</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10245">MPlayer/Xine-Lib Multiple RealRTSP Buffer Overrun Vulnerabilities</ref><ref source="CONFIRM" url="http://www.xinehq.de/index.php/security/XSA-2004-3">http://www.xinehq.de/index.php/security/XSA-2004-3</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc2"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/></prod><prod name="Mplayer" vendor="Mplayer"><vers num="1.0 pre3try2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0434" published="2004-07-07" seq="2004-0434" severity="High" type="CVE"><desc><descript source="cve">k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108386148126457&amp;w=2">20040505 Advisory: Heimdal kadmind version4 remote heap overflow</ref><ref adv="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/020998.html">20040506 Advisory: Heimdal kadmind version4 remote heap overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-504">DSA-504</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108567749831913&amp;w=2">20040527 [ GLSA 200405-23 ] Heimdal: Kerberos 4 buffer overflow in kadmin</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16071">heimdal-kadmind-bo(16071)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020998.html">20040506 Advisory: Heimdal kadmind version4 remote heap overflow</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:09.kadmind.asc">FreeBSD-SA-04:09</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-23.xml">GLSA-200405-23</ref></refs><vuln_soft><prod name="Heimdal" vendor="KTH"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0435" published="2004-08-18" seq="2004-0435" severity="Low" type="CVE"><desc><descript source="cve">Certain &quot;programming errors&quot; in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to files from being committed to disk.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10416/">FreeBSD Msync(2) System Call Buffer Cache Implementation Vulnerability</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:11.msync.asc">FreeBSD-SA-04:11</ref><ref source="BID" url="http://www.securityfocus.com/bid/10416">10416</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11714">11714</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16254">freebsd-msync-gain-privileges(16254)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0 Releng"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.2.1 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0437" published="2004-07-07" seq="2004-0437" severity="Medium" type="CVE"><desc><descript source="cve">Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a &quot;LIST -L&quot; command, which causes Titan to access an invalid socket.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378048513596&amp;w=2">20040505 Titan FTP Server Aborted LIST DoS</ref><ref adv="1" patch="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0025.html">20040505 Titan FTP Server Aborted LIST DoS</ref><ref adv="1" patch="1" source="SecuriTeam.com" url="http://www.securiteam.com/windowsntfocus/5RP0215CUU.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16057">titan-list-command-dos(16057)</ref></refs><vuln_soft><prod name="Titan FTP Server" vendor="South River Technologies"><vers num="3.01 build 163"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-0444" published="2004-07-07" seq="2004-0444" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021360.html">20040512 EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow</ref><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021362.html">20040512 EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption</ref><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021361.html">20040512 EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/634414">VU#634414</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/294998">VU#294998</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021360.html">20040512 EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021362.html">20040512 EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021361.html">20040512 EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow</ref><ref source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/637318">VU#637318</ref><ref source="BID" url="http://www.securityfocus.com/bid/10333">10333</ref><ref source="BID" url="http://www.securityfocus.com/bid/10334">10334</ref><ref source="BID" url="http://www.securityfocus.com/bid/10335">10335</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11066">11066</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-141.shtml">O-141</ref><ref source="OSVDB" url="http://www.osvdb.org/6099">6099</ref><ref source="OSVDB" url="http://www.osvdb.org/6101">6101</ref><ref source="OSVDB" url="http://www.osvdb.org/6102">6102</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010144">1010144</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010145">1010145</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010146">1010146</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16137">symantec-dns-response-bo(16137)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16135">symantec-firewalls-nbns-bo(16135)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16134">symantec-nbns-response-bo(16134)</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Internet Security Pro" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton AntiSpam" vendor="Symantec"><vers num="2004"/></prod><prod name="Symantec Client Security" vendor="Symantec"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.8"/><vers num="1.9"/><vers num="2.0"/></prod><prod name="Symantec Client Firewall" vendor="Symantec"><vers num="5.01"/><vers num="5.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-0445" published="2004-07-07" seq="2004-0445" severity="Low" type="CVE"><desc><descript source="cve">The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021359.html">20040512 EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service</ref><ref adv="1" patch="1" source="Symantec" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html">CAN 2004-0445</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/682110">VU#682110</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html">20040512 EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11066">11066</ref><ref source="BID" url="http://www.securityfocus.com/bid/10336">10336</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16132">symantec-firewall-dns-dos(16132)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-141.shtml">O-141</ref><ref source="OSVDB" url="http://www.osvdb.org/6100">6100</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010144">1010144</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010145">1010145</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010146">1010146</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton Internet Security Pro" vendor="Symantec"><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Norton AntiSpam" vendor="Symantec"><vers num="2004"/></prod><prod name="Symantec Client Security" vendor="Symantec"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.8"/><vers num="1.9"/><vers num="2.0"/></prod><prod name="Symantec Client Firewall" vendor="Symantec"><vers num="5.01"/><vers num="5.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2004-0447" published="2004-08-06" seq="2004-0447" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact.  NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477.  This is the proper candidate to use for the Linux local DoS.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html">Linux 2.4.26-ow2</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10783">Linux Kernel Unspecified Local Denial of Service Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">RHSA-2004:413</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-16.xml">GLSA-200407-16</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-193.shtml">O-193</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16661">linux-ia64-dos(16661)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers edition="IA64" num="2.4.25" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0448" published="2004-12-06" seq="2004-0448" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-510">DSA-510</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10438">bugtraq id 10438</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16271">jftpgw-log-format-string(16271)</ref></refs><vuln_soft><prod name="jftpgw" vendor="jftpgw"><vers num="0.13"/><vers num="0.13.1"/><vers num="0.13.2"/><vers num="0.13.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0450" published="2004-08-06" seq="2004-0450" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-513">DSA-513-1 log2mail -- format string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10460">Michael Krax log2mail Log File Writing Format String Vulnerability</ref><ref source="" url="http://felinemenace.org/~jaguar/advisories/log2mail.txt"></ref><ref source="OSVDB" url="http://osvdb.org/6711">6711</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11768">11768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11769">11769</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16311">log2mail-syslog-format-string(16311)</ref></refs><vuln_soft><prod name="log2mail" vendor="log2mail"><vers num="0.2.2.2"/><vers num="0.2.5.2"/><vers num="0.2.5.1"/><vers num="0.2.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0451" published="2004-12-06" seq="2004-0451" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-521">DSA-521</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10571">bugtraq id 10571</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16459">sup-format-string(16459)</ref><ref adv="1" patch="1" source="Security Tracker" url="http://www.securitytracker.com/alerts/2004/Jun/1010539.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-521">DSA-521</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010539">1010539</ref></refs><vuln_soft><prod name="sup" vendor="sup"><vers num="1.8"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0452" published="2004-12-21" seq="2004-0452" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.free.net.ph/message/20041221.102713.5d5e603a.html">20041223 [USN-44-1] perl information leak</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-620">DSA-620</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml">GLSA-200501-38</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547693019788&amp;w=2">20050111 [OpenPKG-SA-2005.001] OpenPKG Security Advisory (perl)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18650">perl-filepathrmtree-insecure-permissions(18650)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</ref><ref source="BID" url="http://www.securityfocus.com/bid/12072">12072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12991">12991</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18517">18517</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.6.1"/><vers num="5.8.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0453" published="2004-08-06" seq="2004-0453" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the monitor &quot;memory dump&quot; command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10543">VICE Monitor Memory Dump Format String Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16404">VICE memory dump command format string attack</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108723630730487&amp;w=2">VICE emulator format string vulnerability</ref></refs><vuln_soft><prod name="VICE" vendor="VICE"><vers num="1.6"/><vers num="1.13"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0454" published="2004-12-06" seq="2004-0454" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-524">DSA-524</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10578">bugtraq id 10578</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16454">rlpr-msg-bo(16454)</ref></refs><vuln_soft><prod name="rlpr" vendor="rlpr"><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0455" published="2004-12-06" seq="2004-0455" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="Debian" url="http://www.debian.org/security/2004/dsa-523">DSA-523</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16455">wwwsql-cgi-command-execution(16455)</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/10577">bugtraq id 10577</ref></refs></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0456" published="2004-12-06" seq="2004-0456" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-July/023322.html">20040702 pavuk buffer overflow</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-22.xml">GLSA-200406-22</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-527">DSA-527</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16551">pavuk-location-bo(16551)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10633">Bugtraq id 10633</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023322.html">20040702 pavuk buffer overflow</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Pavuk" vendor="Pavuk"><vers num="0.9pl28i"/><vers num="0.928r1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0457" published="2004-09-28" seq="2004-0457" severity="Medium" type="CVE"><desc><descript source="cve">The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="debian" url="http://www.debian.org/security/2004/dsa-540">DSA-540-1 mysql -- insecure file creation</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17030">MySQL mysqlhotcopy insecure temoprary file</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">RHSA-2004:597</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.0.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0458" published="2004-09-28" seq="2004-0458" severity="Medium" type="CVE"><desc><descript source="cve">mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="debian" url="http://www.debian.org/security/2004/dsa-503">DSA-503-1 mah-jong -- missing argument check</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10343">Mah-Jong Server NULL Pointer Dereference Remote Denial Of Service Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16143">mah-jong NULL pointer denial of service</ref></refs><vuln_soft><prod name="Mah-Jong" vendor="Nicolas Boullis"><vers num="1.4"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0459" published="2004-07-07" seq="2004-0459" severity="Medium" type="CVE"><desc><descript source="cve">The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka &quot;jabber&quot;), which prevents devices from transmitting data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4091">AA-2004.02</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/106678">VU#106678</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0631.html">20040513 802.11b (others) single packet DoS</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2004-009.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10342">10342</ref><ref source="OSVDB" url="http://www.osvdb.org/16034">16034</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010152">1010152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16138">ieee80211-cca-dos(16138)</ref></refs><vuln_soft><prod name="802.11 Wireless Protocol" vendor="IEEE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0460" published="2004-08-06" seq="2004-0460" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10590">ISC DHCPD Hostname Options Logging Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16475">ISC DHCP daemon ASCII characters in log lines buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2">ISC DHCP overflows</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html">Multiple Vulnerabilities in ISC DHCP 3</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:061">MDKSA-2004:061</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/317350">VU#317350</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html">SuSE-SA:2004:019</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2">20040622 DHCP Vuln // no code 0day //</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref><ref source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4791">ADV-2006-4791</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017337">1017337</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23265">23265</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061">MDKSA-2004:061</ref></refs><vuln_soft><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="9.0"/><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="III"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="DNS One Appliance" vendor="Infoblox"><vers num="2.3.1 R5"/><vers num="2.4.0.8A"/><vers num="2.4.0.8"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="7"/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="SuSE Linux Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="DHCPD" vendor="ISC"><vers num="3.0.1 rc13"/><vers num="3.0.1 rc12"/></prod><prod name="SuSE Linux Admin-CD for Firewall" vendor="SuSE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0461" published="2004-08-06" seq="2004-0461" severity="High" type="CVE"><desc><descript source="cve">The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10591">ISC DHCPD VSPRINTF Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16476">ISC DHCP daemon C include file buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2"> ISC DHCP overflows</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html">Multiple Vulnerabilities in ISC DHCP 3</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:061">MDKSA-2004:061</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/654390">VU#654390</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html">SuSE-SA:2004:019</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2">20040622 DHCP Vuln // no code 0day //</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref><ref source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4791">ADV-2006-4791</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017337">1017337</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23265">23265</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061">MDKSA-2004:061</ref></refs><vuln_soft><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="9.0"/><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="III"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="DNS One Appliance" vendor="Infoblox"><vers num="2.3.1 R5"/><vers num="2.4.0.8A"/><vers num="2.4.0.8"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="7"/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="SuSE Linux Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="DHCPD" vendor="ISC"><vers num="3.0.1 rc13"/><vers num="3.0.1 rc12"/></prod><prod name="SuSE Linux Admin-CD for Firewall" vendor="SuSE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0462" published="2004-12-31" seq="2004-0462" severity="Low" type="CVE"><desc><descript source="cve">The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/546483">VU#546483</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17702">network-device-secure-plaintext(17702)</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0465" published="2004-12-31" seq="2004-0465" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via &quot;..//&quot; sequences in the WCP_USER parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JSHA-69HVPK">http://www.kb.cert.org/vuls/id/JSHA-69HVPK</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/628411">VU#628411</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14006/">14006</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19394">webconnect-wcpuser-directory-traversal(19394)</ref></refs><vuln_soft><prod name="WebConnect" vendor="OpenConnect"><vers num="6.5"/><vers num="6.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0466" published="2004-02-21" seq="2004-0466" severity="Medium" type="CVE"><desc><descript source="cve">WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JSHA-69FVMM">http://www.kb.cert.org/vuls/id/JSHA-69FVMM</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/552561">VU#552561</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14006/">14006</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19393">webconnect-device-name-dos(19393)</ref></refs><vuln_soft><prod name="WebConnect" vendor="OpenConnect"><vers num="6.5"/><vers num="6.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0467" published="2004-12-31" seq="2004-0467" severity="Medium" type="CVE"><desc><descript source="cve">Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other packets are processed.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en">http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/409555">VU#409555</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ">http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12379">12379</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19094">junos-dos(19094)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013039">1013039</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14049">14049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-081.html">RHSA-2005:081</ref></refs><vuln_soft><prod name="JUNOS" vendor="Juniper"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="5.7"/><vers num="5.6"/><vers num="5.5"/><vers num="5.4"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0468" published="2004-12-06" seq="2004-0468" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/658859">VU#658859</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/JSHA-6253CC"></ref><ref adv="1" patch="1" source="CERT Japan" url="http://www.jpcert.or.jp/at/2004/at040009.txt"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16548">juniper-ipv6-dos(16548)</ref></refs><vuln_soft><prod name="JUNOS" vendor="Juniper"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0469" published="2004-07-07" seq="2004-0469" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Check Point" url="http://www.checkpoint.com/techsupport/alerts/ike_vpn.html">20040504 ISAKMP Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16060">vpn1-isakmp-bo(16060)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10273">bugtraq id 10273</ref></refs><vuln_soft><prod name="NG-AI" vendor="Checkpoint"><vers num="R55"/><vers num="R54"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="VSX 2.0.1"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="Next Generation" vendor="Checkpoint"><vers num="FP3"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="VSX 2.0.1"/><vers num="VSX NG with Application Intelligence"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0470" published="2004-07-07" seq="2004-0470" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Dev2Dev" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp">BEA04-59.00</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/950070">BEA WebLogic Server contains vulnerability in handling of certain tags when editing </ref><ref source="BID" url="http://www.securityfocus.com/bid/10328">10328</ref><ref source="OSVDB" url="http://www.osvdb.org/6076">6076</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010128">1010128</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11593">11593</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16123">weblogic-application-unauth-access(16123)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0"/><vers num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0471" published="2004-07-07" seq="2004-0471" severity="Low" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Dev2Dev" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10327">10327</ref><ref source="OSVDB" url="http://www.osvdb.org/6077">6077</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010129">1010129</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11594">11594</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16121">weblogic-server-policy-bypass(16121)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0"/><vers num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0472" published="2004-07-07" reject="1" seq="2004-0472" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a reservation duplicate of CVE-2004-0434.  Notes: All CVE users should reference CVE-2004-0434 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0473" published="2004-07-07" seq="2004-0473" severity="Low" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Opera before 7.50 does not properly filter &quot;-&quot; characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the &quot;-f&quot; option on Windows XP or (2) the &quot;-n&quot; option on Linux.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108551529413719&amp;w=2">20040525 [ GLSA 200405-19 ] Opera telnet URI handler file</ref><ref source="CONFIRM" url="http://www.opera.com/linux/changelogs/750/index.dml">http://www.opera.com/linux/changelogs/750/index.dml</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-19.xml">GLSA-200405-19</ref><ref source="BID" url="http://www.securityfocus.com/bid/10341">10341</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010142">1010142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16139">opera-telnet-file-overwrite(16139)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=104&amp;type=vulnerabilities">20040512 Opera Telnet URI Handler File Creation/Truncation Vulnerability</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0474" published="2004-07-07" seq="2004-0474" severity="Medium" type="CVE"><desc><descript source="cve">Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an &quot;http://&quot; or &quot;file://&quot; argument to the topic parameter in an hcp:// URL.  NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="Bugtraq" url="http://www.securityfocus.com/archive/1/353248">20040207 HelpCtr - allow open any page or run</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652584102003&amp;w=2">20040211 Re: HelpCtr - allow open any page or run</ref><ref adv="1" source="Full-Disclosure" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0440.html">20040210 Re: HelpCtr - allow open any page or run</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9621">bugtraq id 9621</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15101">winxp-helpctr-hcp-xss(15101)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0450.html">20040210 Re: HelpCtr - allow open any page or run</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0688.html">20040213 Re: HelpCtr - allow open any page or run</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0475" published="2004-07-07" seq="2004-0475" severity="Medium" type="CVE"><desc><descript source="cve">The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash (&quot;\\&quot;) before the target CHM file, as demonstrated using an &quot;ms-its&quot; URL to ntshared.chm.  NOTE: this bug may overlap CVE-2003-1041.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/363202">20040513 Showhelp() local CHM file execution</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16147">ie-showhelp-chm-execution(16147)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10348">bugtraq id 10348</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0476" published="2004-08-18" seq="2004-0476" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10419">3Com OfficeConnect Remote 812 ADSL Router Telnet Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108559293303558&amp;w=2">[Full-Disclosure] iDEFENSE Security Advisory 05.26.04: 3Com OfficeConnect Remote 812</ref><ref adv="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=105&amp;type=vulnerabilities">3Com OfficeConnect Remote 812 ADSL Router Telnet Protocol DoS Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021992.html">20040526 OfficeConnect Remote 812 ADSL Router Telnet Protocol DoS Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11716">11716</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16257">3com-officeconnect-telnet-bo(16257)</ref></refs><vuln_soft><prod name="OfficeConnect Remote 812 ADSL Router" vendor="3Com"><vers num=""/><vers num="1.1.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0477" published="2004-12-06" seq="2004-0477" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password.  NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447.  This candidate is ONLY for the ADSL router bypass.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108589507022827&amp;w=2">20040527 [Full-Disclosure] iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=106&amp;type=vulnerabilities&amp;flashstatus=false"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16267">3com-officeconnect-gain-access(16267)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/bid/10426">Bugtraq id 10426</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11716">11716</ref></refs><vuln_soft><prod name="OfficeConnect Remote 812 ADSL Router" vendor="3Com"><vers num=""/><vers num="1.1.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0478" published="2004-07-07" seq="2004-0478" severity="Low" type="CVE"><desc><descript source="cve">Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop  that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Immunity" url="http://lists.immunitysec.com/pipermail/dailydave/2004-May/000587.html">[Dailydave] 20040514 Mozilla bug might even get fixed!</ref><ref adv="1" source="Bugzilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=243540">243540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16225">mozilla-javascript-dos(16225)</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0479" published="2004-07-07" seq="2004-0479" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021500.html">20040514 IE Crash - Anyone Seen This Before?</ref><ref adv="1" source="Vuln-Dev" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108457938412310&amp;w=2">20040514 IE Crash - Anyone Seen This Before?</ref><ref adv="1" source="Vuln-Dev" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108476938219070&amp;w=2">20040516 Re: IE Crash - Anyone Seen This Before?</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021500.html">20040514 IE Crash - Anyone Seen This Before?</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0480" published="2004-12-06" seq="2004-0480" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843896506099&amp;w=2">20040627 Lotus Notes URL argument injection vulnerability</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=111&amp;type=vulnerabilities"></ref><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/support/docview.wss?rs=475/context=SSKTWP&amp;uid=swg21169510"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16496">lotus-notes-xss(16496)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10600">bugtraq id 10600</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.5"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0481" published="2005-02-23" seq="2004-0481" severity="Low" type="CVE"><desc><descript source="cve">The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=206&amp;type=vulnerabilities">20050223 Sun Solaris kcms_configure Arbitrary File Corruption Vulnerability</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57706-1">57706</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="x86" num="8.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0482" published="2004-07-07" seq="2004-0482" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly perform other unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="OpenBSD-Security-Announce" url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108445767103004&amp;w=2">[openbsd-security-announce] 20040513 procfs vulnerability</ref><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch"></ref><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16226">openbsd-procfs-gain-privileges(16226)</ref><ref source="" url="http://www.deprotect.com/advisories/DEPROTECT-20041305.txt"></ref><ref source="OPENBSD" url="http://www.openbsd.org/errata34.html">20040513 [3.4] 020: SECURITY FIX: May 13, 2004</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata35.html">20040513 [3.5] 006: SECURITY FIX: May 13, 2004</ref><ref source="OSVDB" url="http://www.osvdb.org/6114">6114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11605">11605</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108481812926420&amp;w=2">20040517 OpenBSD procfs</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0483" published="2004-07-07" seq="2004-0483" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040503-01-P">20040503-01-P</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10372">10372</ref><ref source="OSVDB" url="http://www.osvdb.org/6201">6201</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010185">1010185</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11628">11628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16175">rpcmountd-rpc-dos(16175)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0484" published="2004-07-07" seq="2004-0484" severity="Low" type="CVE"><desc><descript source="cve">mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose &quot;float: left&quot; class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108490218632590&amp;w=2">20040518 Unknown IE bug with css-styles</ref><ref source="BID" url="http://www.securityfocus.com/bid/10382">10382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16189">ie-css-dos(16189)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0485" published="2004-07-07" seq="2004-0485" severity="Medium" type="CVE"><desc><descript source="cve">The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="lixlpixel" url="http://fundisom.com/owned/warning"></ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/11622/">SA11622</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16166">Mac OS X runscript code execution</ref><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">APPLE-SA-2004-05-28</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/210606">VU#210606</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00053.html">APPLE-SA-2004-05-21</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0486" published="2004-07-07" seq="2004-0486" severity="High" type="CVE"><desc><descript source="cve">HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="lixlpixel" url="http://www.fundisom.com/owned/warning"></ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/11622/">SA11622</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16166">Mac OS X runscript code execution</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/578798">VU#578798</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10356">Apple Mac OS X Help Protocol Remote Code Execution Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00053.html">APPLE-SA-2004-05-21</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0837.html">20040516 Vuln. MacOSX/Safari: Remote help-call, execute scripts</ref><ref source="OSVDB" url="http://www.osvdb.org/6184">6184</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010167">1010167</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0487" published="2004-08-18" seq="2004-0487" severity="High" type="CVE"><desc><descript source="cve">A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10392">Symantec Norton AntiVirus ActiveX Control Remote Code Execution Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/312510">Symantec Norton AntiVirus 2004 ActiveX control fails to properly validate input</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16220">Norton AntiVirus 2004 ActiveX code execution</ref><ref source="MISC" url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html</ref><ref source="CONFIRM" url="http://www.symantec.com/avcenter/security/Content/2004.05.20.html">http://www.symantec.com/avcenter/security/Content/2004.05.20.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-149.shtml">O-149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11676">11676</ref><ref source="OSVDB" url="http://www.osvdb.org/6303">6303</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515369718455&amp;w=2">20040521 [SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability</ref></refs><vuln_soft><prod name="Norton AntiVirus" vendor="Symantec"><vers edition="MS Exchange" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0488" published="2004-07-07" seq="2004-0488" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021610.html">20040517 mod_ssl ssl_util_uuencode_binary potential problem</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10355">bugtraq id 10355</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16214">Apache mod_ssl ssl_util_uuencode_binary buffer overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.html">20040517 mod_ssl ssl_util_uuencode_binary potential problem</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-532">DSA-532</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1888">FLSA:1888</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2">SSRT4777</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215056218824&amp;w=2">SSRT4788</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:054">MDKSA-2004:054</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:055">MDKSA-2004:055</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0031/">2004-0031</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619129727620&amp;w=2">20040601 TSSA-2004-008 - apache</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200406-05.xml">GLSA-200406-05</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-245.html">RHSA-2004:245</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-342.html">RHSA-2004:342</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">RHSA-2004:405</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108567431823750&amp;w=2">20040527 [OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:054">MDKSA-2004:054</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:055">MDKSA-2004:055</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Mod_ssl" vendor="mod_ssl"><vers num="2.8.7"/><vers num="2.8.10"/><vers num="2.8.12"/><vers num="2.8.15"/><vers num="2.8.16"/></prod><prod name="tinysofa Enterprise Server" vendor="tinysofa"><vers num="1.0 U1"/><vers num="1.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="current"/><vers num="3.4"/><vers num="3.5"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.6"/><vers edition="Dev" num="1.3.7"/><vers num="1.3.9"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.14"/><vers num="1.3.17"/><vers num="1.3.18"/><vers num="1.3.19"/><vers num="1.3.20"/><vers num="1.3.22"/><vers num="1.3.23"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.26"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.3.29"/><vers num="1.3.31"/><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28 Beta"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0489" published="2004-07-07" seq="2004-0489" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/021871.html">20040524 SSH URI handler remote arbitrary code execution</ref><ref adv="1" source="INSECURE.WS" url="http://www.insecure.ws/article.php?story=200405222251133">safari_0x06</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16242">Mac OS X SSH URL handler code execution</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021871.html">20040524 SSH URI handler remote arbitrary code execution</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0490" published="2004-08-18" seq="2004-0490" severity="High" type="CVE"><desc><descript source="cve">cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker&apos;s script after the user&apos;s script, which executes the attacker&apos;s script with the user&apos;s privileges, a different vulnerability than CVE-2004-0529.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10407">cPanel Local Privilege Escalation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16239">cPanel mod_phpsuexec allows command execution</ref><ref adv="1" source="Securiteam" url="http://www.securiteam.com/tools/5TP0N15CUA.html">cPanel Multiple Vulnerabilities Testing Script</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/364112">20040524 cPanel mod_phpsuexec Vulnerability</ref><ref source="MISC" url="http://www.a-squad.com/audit/explain10.html">http://www.a-squad.com/audit/explain10.html</ref><ref source="MISC" url="http://bugzilla.cpanel.net/show_bug.cgi?id=283">http://bugzilla.cpanel.net/show_bug.cgi?id=283</ref><ref source="CONFIRM" url="http://bugzilla.cpanel.net/show_bug.cgi?id=664">http://bugzilla.cpanel.net/show_bug.cgi?id=664</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="5.0"/><vers num="5.3"/><vers num="6.0"/><vers num="6.2"/><vers num="6.4"/><vers num="6.4.1"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="7.0"/><vers num="8.0"/><vers num="9.0"/><vers num="9.1.0 R85"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0491" published="2004-12-31" seq="2004-0491" severity="Low" type="CVE"><desc><descript source="cve">The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108087017610947&amp;w=2">[linux-kernel] 20040402 Re: disable-cap-mlock</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1117.html">OVAL1117</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</ref><ref source="BID" url="http://www.securityfocus.com/bid/13769">13769</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1117">oval:org.mitre.oval:def:1117</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0492" published="2004-08-06" seq="2004-0492" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16387">Apache HTTP Server mod_proxy Content-Length buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108711172710140&amp;w=2">[OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-525">DSA-525-1 apache -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10508">Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-245.html">Updated httpd and mod_ssl packages fix minor Apache security vulnerabilities</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2004/Jun/0296.html">20040610 Buffer overflow in apache mod_proxy,yet still apache much better than windows</ref><ref source="MISC" url="http://www.guninski.com/modproxy1.html">http://www.guninski.com/modproxy1.html</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1737">FLSA:1737</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:065">MDKSA-2004:065</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4863.html">OVAL4863</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/541310">VU#541310</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11841">11841</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100112.html">OVAL100112</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1">101841</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4863">oval:org.mitre.oval:def:4863</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100112">oval:org.mitre.oval:def:100112</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:065">MDKSA-2004:065</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.26"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.3.29"/><vers num="1.3.31"/></prod><prod name="Webproxy" vendor="HP"><vers num="2.0"/><vers num="2.1"/></prod><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.26.2"/><vers num="1.3.26.1"/><vers num="1.3.26"/><vers num="1.3.28"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/><vers num="3.4"/><vers num="3.5"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/></prod><prod name="VirtualVault" vendor="HP"><vers num="11.0.4"/></prod><prod name="HP-UX VVOS" vendor="HP"><vers num="11.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0493" published="2004-08-06" seq="2004-0493" severity="Medium" type="CVE"><desc><descript source="cve">The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10619">Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16524">Apache HTTP Server ap_get_mime_headers_core denial of service</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023133.html">20040628 DoS in apache httpd 2.0.49, yet still apache much better than windows</ref><ref source="MISC" url="http://www.guninski.com/httpd1.html">http://www.guninski.com/httpd1.html</ref><ref source="CONFIRM" url="http://www.apacheweek.com/features/security-20">http://www.apacheweek.com/features/security-20</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-03.xml">GLSA-200407-03</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2">SSRT4777</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:064">MDKSA-2004:064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-342.html">RHSA-2004:342</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0039/">2004-0039</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108853066800184&amp;w=2">20040629 TSSA-2004-012 - apache</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:064">MDKSA-2004:064</ref></refs><vuln_soft><prod name="S8500" vendor="Avaya"><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="IBM HTTP Server" vendor="IBM"><vers num="2.0.42.2"/><vers num="2.0.42.1"/><vers num="2.0.42"/><vers num="2.0.47.1"/><vers num="2.0.47"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0494" published="2004-11-23" seq="2004-0494" severity="High" type="CVE"><desc><descript source="cve">Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16897">GNOME VFS extfs scripts gain access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10864">Gnome VFS &amp;#39;extfs&amp;#39; Scripts Undisclosed Vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-373.html">GNOME VFS updates address extfs vulnerability</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1944">FLSA:1944</ref><ref source="" url="http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html"></ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="CVLAN" vendor="Avaya"><vers num=""/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0495" published="2004-08-06" seq="2004-0495" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10566">Linux Kernel Multiple Device Driver Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16449">Linux Kernel multiple drivers allows elevated privileges</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-255.html">Updated kernel packages fix security vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845">CLA-2004:845</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="FEDORA" url="http://lwn.net/Articles/91155/">FEDORA-2004-186</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066">MDKSA-2004:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-260.html">RHSA-2004:260</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2961.html">OVAL2961</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2961">oval:org.mitre.oval:def:2961</ref></refs><vuln_soft><prod name="SuSE Office Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="3.1"/><vers num="III"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="SuSE Linux Admin-CD for Firewall" vendor="SuSE"><vers num=""/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="LX"/></prod><prod name="SuSE Linux Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="7"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="8.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0496" published="2004-12-06" seq="2004-0496" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/security/2004_20_kernel.html">SUSE-SA:2004:020</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16625">linux-gain-privileges(16625)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref></refs><vuln_soft><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Mandrake Linux Corporate Server" vendor="MandrakeSoft"><vers num="2.1"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Firewall" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="7"/><vers num="8"/></prod><prod name="SuSE eMail Server III" vendor="SuSE"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="SPARC" num="9.0"/><vers num="9.1"/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="3.1"/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0497" published="2004-12-06" seq="2004-0497" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066">MDKSA-2004:066</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-354.html">RHSA-2004:354</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/security/2004_20_kernel.html">SUSE-SA:2004:020</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16599">linux-fchown-groupid-modify(16599)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-360.html">RHSA-2004:360</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Mandrake Linux Corporate Server" vendor="MandrakeSoft"><vers num="2.1"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.0"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0498" published="2004-12-31" seq="2004-0498" severity="Medium" type="CVE"><desc><descript source="cve">The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.uniras.gov.uk/niscc/docs/re-20041026-00956.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.stonesoft.com/support/Security_Advisories/6735.html"></ref></refs><vuln_soft><prod name="Firewall Engine" vendor="StoneSoft"><vers num="2.2.8" prev="1"/></prod></vuln_soft></entry><entry modified="2006-04-28" name="CVE-2004-0499" published="2004-12-31" reject="1" seq="2004-0499" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0500" published="2004-09-28" seq="2004-0500" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200408-12.xml">Gaim: MSN protocol parsing function buffer overflow</ref><ref source="FEDORA" url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml">FEDORA-2004-278</ref><ref source="FEDORA" url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml">FEDORA-2004-279</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml">GLSA-200408-27</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:081">MDKSA-2004:081</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-400.html">RHSA-2004:400</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_25_gaim.html">SUSE-SA:2004:025</ref><ref source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=0">http://gaim.sourceforge.net/security/?id=0</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10865">10865</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16920">gaim-msn-bo(16920)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10"/><vers num="0.10.3"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.59.1"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0501" published="2004-08-18" seq="2004-0501" severity="Medium" type="CVE"><desc><descript source="cve">Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10323">Microsoft Outlook Mail Client E-mail Address Verification Weakness</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16116">Microsoft Outlook VML information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108430168919965&amp;w=2"> PING: Outlook 2003 Spam</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2">20040604 RE: PING: Outlook 2003 Spam</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2">20040604 RE: PING: Outlook 2003 Spam</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0502" published="2004-08-18" seq="2004-0502" severity="Medium" type="CVE"><desc><descript source="cve">Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the &quot;src&quot; of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10307">Microsoft Outlook 2003 Predictable File Location Weakness</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420583612655&amp;w=2"> OUTLOOK 2003: OuchLook</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2"> RE: PING: Outlook 2003 Spam</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11572">11572</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16104">outlook-file-location-predictable(16104)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2">20040604 RE: PING: Outlook 2003 Spam</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0503" published="2004-08-18" seq="2004-0503" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player&apos;s setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10369">Microsoft Outlook 2003 Media File Script Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16173">Microsoft Outlook 2003 OLE object bypass restricted security zone</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108483193328605&amp;w=2"> ROCKET SCIENCE: Outllook 2003</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0885.html">20040517 ROCKET SCIENCE: Outllook 2003</ref><ref source="OSVDB" url="http://www.osvdb.org/6217">6217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11629">11629</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0504" published="2004-08-18" seq="2004-0504" severity="Medium" type="CVE"><desc><descript source="cve">Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-01.xml">Ethereal: Multiple security problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10347">Ethereal Multiple Protocol Dissector Vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-234.html">Updated Ethereal packages fix security issues</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00014.html">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref><ref source="MLIST" url="http://www.ethereal.com/lists/ethereal-users/200405/msg00018.html">[Ethereal-users] 20040503 Re: HotSIP sip-messages crasching ethereal</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval982.html">OVAL982</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-150.shtml">O-150</ref><ref source="OSVDB" url="http://www.osvdb.org/6131">6131</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010158">1010158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11608">11608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11776">11776</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11836">11836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16148">ethereal-sip-packet-dos(16148)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:982">oval:org.mitre.oval:def:982</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0505" published="2004-08-18" seq="2004-0505" severity="Medium" type="CVE"><desc><descript source="cve">The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10347">Ethereal Multiple Protocol Dissector Vulnerabilities</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-01.xml">Ethereal: Multiple security problems</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-234.html">Updated Ethereal packages fix security issues</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00014.html">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval986.html">OVAL986</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-150.shtml">O-150</ref><ref source="OSVDB" url="http://www.osvdb.org/6132">6132</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010158">1010158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11608">11608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11776">11776</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11836">11836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16150">ethereal-aim-dissector-dos(16150)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:986">oval:org.mitre.oval:def:986</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0506" published="2004-08-18" seq="2004-0506" severity="Medium" type="CVE"><desc><descript source="cve">The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10347">Ethereal Multiple Protocol Dissector Vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-234.html">Updated Ethereal packages fix security issues</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-01.xml">Ethereal: Multiple security problems</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00014.html">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval987.html">OVAL987</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-150.shtml">O-150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010158">1010158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11608">11608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11776">11776</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11836">11836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16151">ethereal-spnego-dos(16151)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:987">oval:org.mitre.oval:def:987</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0507" published="2004-08-18" seq="2004-0507" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Ethereal" url="http://www.ethereal.com/appnotes/enpa-sa-00014.html">Multiple security problems in Ethereal 0.10.3</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-01.xml">Ethereal: Multiple security problems</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-245.html">Updated httpd and mod_ssl packages fix minor Apache security vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-234.html">RHSA-2004:234</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval988.html">OVAL988</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-150.shtml">O-150</ref><ref source="BID" url="http://www.securityfocus.com/bid/10347">10347</ref><ref source="OSVDB" url="http://www.osvdb.org/6134">6134</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010158">1010158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11608">11608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11776">11776</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11836">11836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16152">ethereal-mmse-bo(16152)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:988">oval:org.mitre.oval:def:988</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0510" published="2004-12-23" seq="2004-0510" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10758">bid 10758</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16738">SCO OpenServer MMDF buffer overflow</ref><ref source="MISC" url="http://www.deprotect.com/advisories/DEPROTECT-20040206.txt">http://www.deprotect.com/advisories/DEPROTECT-20040206.txt</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt">SCOSA-2004.7</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889281711636&amp;w=2">20041027 MMDF deliver local root exploit for SCO OpenServer 5.0.7 x86</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.6a"/><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0511" published="2004-12-23" seq="2004-0511" severity="Low" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="sco.com" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt">OpenServer 5.0.6 OpenServer 5.0.7 : MMDF Various buffer overflows and other security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10758">bid 10758</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16739">SCO OpenServer MMDF name denial of service</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.6a"/><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0512" published="2004-12-23" seq="2004-0512" severity="Low" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="sco.com" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt">OpenServer 5.0.6 OpenServer 5.0.7 : MMDF Various buffer overflows and other security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10758">bid 10758</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16740">SCO OpenServer MMDF denial of service</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.6a"/><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0513" published="2004-08-18" seq="2004-0513" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to &quot;logging when tracing system calls.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="BID" url="http://www.securityfocus.com/bid/10432">10432</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/May/1010329.html">1010329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16291">macosx-nfs-logging(16291)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/May/msg00005.html">APPLE-SA-2004-05-28</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0514" published="2004-08-18" seq="2004-0514" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to &quot;handling of directory services lookups.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/174790">Apple Mac OS X vulnerable to privilege escalation when using Directory Services</ref><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10432">Apple Mac OS X Multiple Unspecified Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010330">1010330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16289">macosx-loginwindow-gain-privileges(16289)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0515" published="2004-08-18" seq="2004-0515" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to &quot;handling of console log files.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10432">Apple Mac OS X Multiple Unspecified Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010330">1010330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16289">macosx-loginwindow-gain-privileges(16289)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0516" published="2004-08-18" seq="2004-0516" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to &quot;package installation scripts,&quot; a different vulnerability than CVE-2004-0517.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10432">Apple Mac OS X Multiple Unspecified Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010331">1010331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16290">macosx-package-installation(16290)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0517" published="2004-08-18" seq="2004-0517" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to &quot;handling of process IDs during package installation,&quot; a different vulnerability than CVE-2004-0516.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10432">Apple Mac OS X Multiple Unspecified Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010331">1010331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16290">macosx-package-installation(16290)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0518" published="2004-08-18" seq="2004-0518" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to &quot;the use of SSH and reporting errors,&quot; has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10432">Apple Mac OS X Multiple Unspecified Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010333">1010333</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16288">applefileserver-reporting-error(16288)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0519" published="2004-08-18" seq="2004-0519" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10246/">SquirrelMail Folder Name Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16025">SquirrelMail compose.php script cross-site scripting</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-16.xml">Multiple XSS Vulnerabilities in SquirrelMail</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/361857">20040430 Re: SquirrelMail Cross Scripting Attacks....</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-535">DSA-535</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1733">FEDORA-2004-1733</ref><ref adv="1" patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-240.html">RHSA-2004:240</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1006.html">OVAL1006</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.securityfocus.com/advisories/6827">FEDORA-2004-160</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11531">11531</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11686">11686</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11870">11870</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12289">12289</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10246">10246</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334862800260">20040429 SquirrelMail Cross Scripting Attacks....</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858">CLA-2004:858</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006">oval:org.mitre.oval:def:1006</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0520" published="2004-08-18" seq="2004-0520" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10439">SquirrelMail Email Header HTML Injection Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611554415078&amp;w=2">RS-2004-1: SquirrelMail </ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-08.xml">Squirrelmail: Another XSS vulnerability</ref><ref adv="1" source="MISC" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt">http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-535">DSA-535</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1733">FEDORA-2004-1733</ref><ref adv="1" patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-240.html">RHSA-2004:240</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1012.html">OVAL1012</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.securityfocus.com/advisories/6827">FEDORA-2004-160</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11870">11870</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12289">12289</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712">[squirrelmail-cvs] 20040523 [SM-CVS] CVS: squirrelmail/functions mime.php,1.265.2.27,1.265.2.28</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858">CLA-2004:858</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1012">oval:org.mitre.oval:def:1012</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3 RC1"/><vers num="1.5 dev"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Open Webmail" vendor="Open Webmail"><vers num="2.30"/><vers num="2.31"/><vers num="2.32"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0521" published="2004-08-18" seq="2004-0521" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10397">SquirrelMail Unspecified SQL Injection Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108309375029888">[SM-CVS] CVS: squirrelmail/functions abook_database.php,1.15.2.1,1.15.2.2</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-16.xml">Multiple XSS Vulnerabilities in SquirrelMail</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-535">DSA-535</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1733">FEDORA-2004-1733</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-240.html">RHSA-2004:240</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1033.html">OVAL1033</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11685">11685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16235">squirrelmail-sql-injection(16235)</ref><ref source="APPLE" url="http://www.securityfocus.com/advisories/7148">APPLE-SA-2004-09-07</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/6827">FEDORA-2004-160</ref><ref source="OSVDB" url="http://www.osvdb.org/6841">6841</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11686">11686</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11870">11870</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12289">12289</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712">[squirrelmail-devel] 20040511 [SM-DEVEL] SquirrelMail 1.4.3-RC1 Release</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858">CLA-2004:858</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1033">oval:org.mitre.oval:def:1033</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2004-0522" published="2004-08-06" seq="2004-0522" severity="High" type="CVE"><desc><descript source="cve">Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16301">Gallery user bypass authentication</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-512">DSA-512-1 gallery -- unauthenticated access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10451">Gallery Authentication Bypass Vulnerability</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200406-10.xml">GLSA-200406-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11752">11752</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.4 pl2"/><vers num="1.4 pl1"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3 pl1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-0523" published="2004-08-18" seq="2004-0523" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/686862">MIT Kerberos 5 krb5_aname_to_localname() contains several heap overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-520">DSA-520-1 krb5 -- buffer overflows</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10448/">MIT Kerberos 5 KRB5_AName_To_Localname Multiple Principal Name Buffer Overrun Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860">CLA-2004:860</ref><ref source="FEDORA" url="http://lwn.net/Articles/88206/">FEDORA-2004-149</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-21.xml">GLSA-200406-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:056">MDKSA-2004:056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-236.html">RHSA-2004:236</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619250923790&amp;w=2">2004-0032</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619161815320&amp;w=2">20040602 TSSA-2004-009 - kerberos5</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc">20040605-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval991.html">OVAL991</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2002.html">OVAL2002</ref><ref source="BID" url="http://www.securityfocus.com/bid/10448">10448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16268">Kerberos-krb5anametolocalname-bo(16268)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108612325909496&amp;w=2">20040601 MITKRB5-SA-2004-001: buffer overflows in krb5_aname_to_localname</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101512-1">101512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:991">oval:org.mitre.oval:def:991</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2002">oval:org.mitre.oval:def:2002</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:724">oval:org.mitre.oval:def:724</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.0.8"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2.Beta1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3 alpha1"/><vers num="1.3"/><vers num="5.0_1.3.3"/><vers num="5.0_1.2 Beta2"/><vers num="5.0_1.2 Beta1"/><vers num="5.0_1.1.1"/><vers num="5.0_1.1"/><vers num="5.0_1.0"/></prod><prod name="SEAM" vendor="Sun"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod><prod name="tinysofa Enterprise Server" vendor="tinysofa"><vers num="1.0 U1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-0524" published="2004-08-06" seq="2004-0524" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10166">SquirrelMail Change_Passwd Plug-in Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15889">SquirrelMail chpasswd binary buffer overflow</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108222863917958&amp;w=2">Squirrelmail Chpasswod bof</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311782032370&amp;w=2">Re:  Squirrelmail Chpasswod bof</ref><ref source="CONFIRM" url="http://www.squirrelmail.org/plugin_view.php?id=117">http://www.squirrelmail.org/plugin_view.php?id=117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11415">11415</ref></refs><vuln_soft><prod name="change_passwd" vendor="Thiago Melo de Paula"><vers num="3.1.1.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0525" published="2004-08-06" seq="2004-0525" severity="Medium" type="CVE"><desc><descript source="cve">HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10415">HP Integrated Lights Out Remote Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16251">HP Integrated Lights-Out port zero denial of service</ref><ref source="HP" url="http://seclists.org/lists/bugtraq/2004/May/0281.html">SSRT4724</ref></refs><vuln_soft><prod name="Integrated Lights Out" vendor="HP"><vers num="1.6 A"/><vers num="1.10"/><vers num="1.15 A"/><vers num="1.15"/><vers num="1.16 A"/><vers num="1.20 A"/><vers num="1.26 A"/><vers num="1.27 A"/><vers num="1.40 A"/><vers num="1.41 A"/><vers num="1.42 A"/><vers num="1.50 A"/><vers num="1.50"/><vers num="1.51 A"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0526" published="2004-08-06" seq="2004-0526" severity="Medium" type="CVE"><desc><descript source="cve">Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified &quot;alt&quot; values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a &quot;phishing&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10308">Microsoft Internet Explorer Embedded Image URI Obfuscation Weakness</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16102">Microsoft Internet Explorer and Outlook Express A HREF URL spoofing</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422905510713&amp;w=2"> DEEP SEA PHISHING: Internet Explorer / Outlook Express</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html">20040517 Microsoft Internet Explorer ImageMap URL Spoof Vulnerability</ref><ref source="MISC" url="http://www.kurczaba.com/securityadvisories/0405132poc.htm">http://www.kurczaba.com/securityadvisories/0405132poc.htm</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2000 SR1"/><vers num="2000 SP2"/><vers num="2000"/><vers num="2002 SP3"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/><vers num="2003"/><vers num="97"/><vers num="98"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="4.01 SP2"/><vers num="4.0"/><vers num="4.27.3110"/><vers num="4.72.2106"/><vers num="4.72.3120"/><vers num="4.72.3612"/><vers num="5.0.1"/><vers num="5.0"/><vers num="5.5"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0527" published="2004-08-06" seq="2004-0527" severity="Medium" type="CVE"><desc><descript source="cve">KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified &quot;alt&quot; values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a &quot;phishing&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10383">KDE Konqueror Embedded Image URI Obfuscation Weakness</ref><ref source="OSVDB" url="http://www.osvdb.org/6579">6579</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16102">ie-ahref-url-spoofing(16102)</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="2.1.1"/><vers num="2.2.2"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.5"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0528" published="2004-08-06" seq="2004-0528" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified &quot;alt&quot; values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a &quot;phishing&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10389">Netscape Navigator Embedded Image URI Obfuscation Weakness</ref><ref source="OSVDB" url="http://www.osvdb.org/6580">6580</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16102">ie-ahref-url-spoofing(16102)</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0529" published="2004-08-06" seq="2004-0529" severity="High" type="CVE"><desc><descript source="cve">The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108663003608211&amp;w=2">cPanel mod_php suEXEC Taint Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10478">ClueCentral Apache Suexec Patch Security Weakness</ref><ref source="CONFIRM" url="http://bugzilla.cpanel.net/show_bug.cgi?id=668">http://bugzilla.cpanel.net/show_bug.cgi?id=668</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010411">1010411</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11798">11798</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16347">cpanel-suexec-command-execute(16347)</ref></refs><vuln_soft><prod name="suexec.patch" vendor="cluecentral"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0530" published="2004-08-06" seq="2004-0530" severity="High" type="CVE"><desc><descript source="cve">The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Slackware" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.419765">[slackware-security] PHP local security issue (SSA:2004-154-02)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10461/">Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/10461">10461</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11760">11760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16310">linux-php-gain-privileges(16310)</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="8.1"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0533" published="2004-12-31" seq="2004-0533" severity="Low" type="CVE"><desc><descript source="cve">Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026549.html">20040907 Corsaire Security Advisory - Business Objects WebIntelligence arbitrary document deletion issue</ref><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0056.html">20040917 Corsaire Security Advisory - Business Objects WebIntelligence arbitrary document deletion issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/11208">11208</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12587/">12587</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17422">webintelligence-url-delete-files(17422)</ref></refs><vuln_soft><prod name="WebIntelligence" vendor="businessobjects"><vers num="2.7.4"/><vers num="2.7.3"/><vers num="2.7.2"/><vers num="2.7.1"/><vers num="2.7"/></prod><prod name="InfoView" vendor="businessobjects"><vers num="5.1.8"/><vers num="5.1.7"/><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0534" published="2004-09-17" seq="2004-0534" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026550.html">20040907 Corsaire Security Advisory - Business Objects WebIntelligence XSS issue</ref><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0057.html">20040917 Corsaire Security Advisory - Business Objects WebIntelligence XSS issue</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12587/">12587</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17419">webintelligence-input-document-xss(17419)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11209">11209</ref></refs><vuln_soft><prod name="WebIntelligence" vendor="businessobjects"><vers num="2.7.4"/><vers num="2.7.3"/><vers num="2.7.2"/><vers num="2.7.1"/><vers num="2.7"/></prod><prod name="InfoView" vendor="businessobjects"><vers num="5.1.8"/><vers num="5.1.7"/><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0535" published="2004-08-06" seq="2004-0535" severity="Low" type="CVE"><desc><descript source="cve">The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory.  NOTE: this issue was originally incorrectly reported as a &quot;buffer overflow&quot; by some sources.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10352">Linux Kernel e1000 Ethernet Card Driver Kernel Memory Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16159">Linux Kernel e1000 driver buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">Updated kernel packages fix security vulnerabilities</ref><ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.4/testing/patch-2.4.27.log">http://www.kernel.org/pub/linux/kernel/v2.4/testing/patch-2.4.27.log</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=125168">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=125168</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845">CLA-2004:845</ref><ref source="FEDORA" url="http://lwn.net/Articles/91155/">FEDORA-2004-186</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:062">MDKSA-2004:062</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-418.html">RHSA-2004:418</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:062">MDKSA-2004:062</ref></refs><vuln_soft><prod name="Secure Community" vendor="EnGarde"><vers num="2.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Secure Professional" vendor="EnGarde"><vers num="1.5"/></prod><prod name="SuSE Linux Admin-CD for Firewall" vendor="SuSE"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre1"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE Linux Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="7"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="SuSE Office Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="SuSE Linux Live-CD Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="3.1"/><vers num="III"/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="8.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0536" published="2004-08-06" seq="2004-0536" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-02.xml">tripwire: Format string vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10454/">Tripwire Email Reporting Format String Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/10454">10454</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16309">tripwire-fprintf-format-string(16309)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108627481507249&amp;w=2">20040602 Format String Vulnerability in Tripwire</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108630983009228&amp;w=2">20040603 Re: Format String Vulnerability in Tripwire</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-244.html">RHSA-2004:244</ref></refs><vuln_soft><prod name="Tripwire" vendor="Tripwire"><vers num="2.2.1"/><vers num="2.3.0"/><vers num="2.3.1.2"/><vers num="2.3.1"/><vers num="2.4.0"/><vers num="2.4.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0537" published="2004-08-06" seq="2004-0537" severity="Medium" type="CVE"><desc><descript source="cve">Opera 7.50 and earlier allows remote web sites to provide a &quot;Shortcut Icon&quot; (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108627581717738&amp;w=2">Phishing for Opera (GM#007-OP)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10452">Opera Browser Favicon Address Bar Spoofing Weakness</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html">20040603 Phishing for Opera (GM#007-OP)</ref><ref source="MISC" url="http://security.greymagic.com/security/advisories/gm007-op/">http://security.greymagic.com/security/advisories/gm007-op/</ref><ref source="CONFIRM" url="http://www.opera.com/linux/changelogs/751/index.dml">http://www.opera.com/linux/changelogs/751/index.dml</ref><ref source="OSVDB" url="http://osvdb.org/6590">6590</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11762">11762</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16307">opera-favicon-spoofing(16307)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.23"/><vers num="7.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0538" published="2004-08-06" seq="2004-0538" severity="High" type="CVE"><desc><descript source="cve">LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10486">bid 10486</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0539" published="2004-08-06" seq="2004-0539" severity="High" type="CVE"><desc><descript source="cve">The &quot;Show in Finder&quot; button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10486">bid 10486</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/773190">VU#773190</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0540" published="2004-08-06" seq="2004-0540" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Microsoft" url="http://support.microsoft.com/default.aspx?scid=kb;en-us;830847">Users who have expired passwords can still log on to the domain if the FQDN is exactly eight characters long in Windows 2000</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11746/">11746</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0541" published="2004-08-06" seq="2004-0541" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password (&quot;pass&quot; variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16360">Squid Web Proxy Cache NTLM buffer overflow</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml">Squid: NTLM authentication helper buffer overflow</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-242.html">Updated squid package fixes security vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.idefense.com/application/poi/display?id=107&amp;type=vulnerabilities">http://www.idefense.com/application/poi/display?id=107&amp;type=vulnerabilities</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0033/">2004-0033</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc">20040604-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval980.html">OVAL980</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/10500">10500</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:980">oval:org.mitre.oval:def:980</ref></refs><vuln_soft><prod name="Squid Web Proxy Cache" vendor="National Science Foundation"><vers num="2.5 Stable"/><vers num="3 Pre"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-0542" published="2004-08-06" seq="2004-0542" severity="High" type="CVE"><desc><descript source="cve">PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the &quot;%&quot;, &quot;|&quot;, or &quot;&gt;&quot; characters to the escapeshellcmd function, or (2) the &quot;%&quot; character to the escapeshellarg function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16331">PHP escapeshellarg and escapeshellcmd execute command</ref><ref adv="1" source="MISC" url="http://www.idefense.com/application/poi/display?id=108">http://www.idefense.com/application/poi/display?id=108</ref><ref patch="1" source="CONFIRM" url="http://www.php.net/release_4_3_7.php">http://www.php.net/release_4_3_7.php</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0543" published="2004-08-06" seq="2004-0543" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16324">Oracle E-Business SQL injection</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-160A.html">SQL Injection Vulnerabilities in Oracle E-Business Suite</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/961579">Oracle E-Business Suite SQL Injection vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10465">Oracle E-Business Suite Multiple Unspecified SQL Injection Vulnerabilities</ref><ref source="MISC" url="http://www.integrigy.com/alerts/OraAppsSQLInjection.htm">http://www.integrigy.com/alerts/OraAppsSQLInjection.htm</ref><ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2004alert67.pdf">http://otn.oracle.com/deploy/security/pdf/2004alert67.pdf</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0032.html">20040604 Integrigy Security Alert - Multiple SQL Injection Vulnerabilities in Oracle E-Business Suite</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-153.shtml">O-153</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108638417302229&amp;w=2">20040604 Integrigy Security Alert - Multiple SQL Injection Vulnerabilities in Oracle E-Business Suite</ref></refs><vuln_soft><prod name="Oracle Applications" vendor="Oracle"><vers num="11.0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i"/><vers num="11i 11.5.1"/><vers num="11i 11.5.2"/><vers num="11i 11.5.3"/><vers num="11i 11.5.4"/><vers num="11i 11.5.5"/><vers num="11i 11.5.6"/><vers num="11i 11.5.7"/><vers num="11i 11.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0544" published="2004-08-06" seq="2004-0544" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9905">AIX Getlvcb Command Line Argument Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15555">IBM AIX getlvcb and putlvcb utilities buffer overflow</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-131.shtml">O-131: AIX Symlink and Buffer Overflow Vulnerabilities in LVM Commands</ref><ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2">MSS-OAR-E01-2004.0544</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY55681">IY55681</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY55682">IY55682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11158/">11158</ref><ref source="BID" url="http://www.securityfocus.com/bid/9906">9906</ref><ref source="OSVDB" url="http://www.osvdb.org/4392">4392</ref><ref source="OSVDB" url="http://www.osvdb.org/4393">4393</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18317">aix-getlvcb-bo(18317)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0545" published="2004-08-06" seq="2004-0545" severity="High" type="CVE"><desc><descript source="cve">LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10230">Multiple IBM AIX Unspecified LVM Utilities Symbolic Link Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16011">IBM AIX LVM commands symlink attack</ref><ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2">MSS-OAR-E01-2004.0544</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-131.shtml">O-131</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0547" published="2004-08-06" seq="2004-0547" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16329">PostgreSQL ODBC driver buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-516">DSA-516-1 postgresql -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10470">PostgreSQL ODBC Driver Unspecified Remote Buffer Overflow Vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:072">MDKSA-2004:072</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0548" published="2004-08-06" seq="2004-0548" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) &quot;c&quot; compress option or (2) &quot;d&quot; decompress option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108675120224531&amp;w=2">Aspell &apos;word-list-compress&apos; stack overflow vulnerability</ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-14.xml">aspell: Buffer overflow in word-list-compress</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10497/">GNU Aspell Stack Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Aspell" vendor="GNU"><vers num="0.50.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0549" published="2004-08-06" seq="2004-0549" severity="High" type="CVE"><desc><descript source="cve">The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a &quot;URL:&quot; prepended to a &quot;ms-its&quot; protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-163A.html">Cross-Domain Redirect Vulnerability in Internet Explorer</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0031.html">20040602 180 Solutions Exploits and Toolbars Hacking Patched Users(I.E Exploits)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0104.html">20040606 Internet explorer 6 execution of arbitrary code (An analysis of the 180 Solutions Trojan)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108852642021426&amp;w=2">20040628 JS.Scob.Trojan Source Code ...</ref><ref source="An analysis of the ILookup Trojan" url="http://62.131.86.111/analysis.htm">http://62.131.86.111/analysis.htm</ref><ref source="MISC" url="http://umbrella.name/originalvuln/msie/InsiderPrototype/">http://umbrella.name/originalvuln/msie/InsiderPrototype/</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx">MS04-025</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html">TA04-212A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/713878">VU#713878</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1133.html">OVAL1133</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval207.html">OVAL207</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval241.html">OVAL241</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval519.html">OVAL519</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-184A.html">TA04-184A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16348">ie-location-restriction-bypass(16348)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786396622284&amp;w=2">20040621 IE/0DAY -&gt; Insider Prototype</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1133">oval:org.mitre.oval:def:1133</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:207">oval:org.mitre.oval:def:207</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:241">oval:org.mitre.oval:def:241</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:519">oval:org.mitre.oval:def:519</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/><vers num="5.5"/><vers num="SP2"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0550" published="2004-08-06" seq="2004-0550" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of &quot;.&quot; (period) characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16388">RealPlayer dot file buffer overflow</ref><ref adv="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=109&amp;type=vulnerabilities&amp;flashstatus=false">Real Networks RealPlayer URL Parsing Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=109&amp;type=vulnerabilities&amp;flashstatus=false">http://www.idefense.com/application/poi/display?id=109&amp;type=vulnerabilities&amp;flashstatus=false</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0551" published="2004-08-06" seq="2004-0551" severity="Medium" type="CVE"><desc><descript source="cve">Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka &quot;TCP-ACK DoS attack.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16370">Cisco Catalyst CatOS ACK denial of service</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/245190">Cisco CatOS TCP ACK handling vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10504/">Cisco CatOS TCP-ACK Denial Of Service Vulnerability</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml">20040609 Cisco CatOS Telnet, HTTP and SSH Vulnerability</ref></refs><vuln_soft><prod name="Catalyst 4506" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 4912G" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 4503" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 4510R" vendor="Cisco"><vers num=""/></prod><prod name="CatOS" vendor="Cisco"><vers num="3.0(7)"/><vers num="2.1 (9)"/><vers num="2.1 (8)"/><vers num="2.1 (7)"/><vers num="2.1 (6)"/><vers num="2.1 (5)"/><vers num="2.1 (4)"/><vers num="2.1 (3)"/><vers num="2.1 (2)"/><vers num="2.1 (12)"/><vers num="2.1 (11)"/><vers num="2.1 (10)"/><vers num="2.1 (1)"/><vers num="2.2 (2)"/><vers num="2.2 (1)"/><vers num="2.3 (1)"/><vers num="2.4 (5a)"/><vers num="2.4 (5)"/><vers num="2.4 (4)"/><vers num="2.4 (3)"/><vers num="2.4 (2)"/><vers num="2.4 (1)"/><vers num="3.1 (2a)"/><vers num="3.1 (2)"/><vers num="3.1 (1)"/><vers num="3.2 (8) - GDR"/><vers num="3.2 (7)"/><vers num="3.2 (6)"/><vers num="3.2 (5)"/><vers num="3.2 (4)"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1b)"/><vers num="3.2 (1)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.2 (2)"/><vers num="4.2 (1)"/><vers num="4.3 (1a)"/><vers num="4.4 (1)"/><vers num="4.5 (9)"/><vers num="4.5 (8)"/><vers num="4.5 (7)"/><vers num="4.5 (6a)"/><vers num="4.5 (6)"/><vers num="4.5 (5)"/><vers num="4.5 (4)"/><vers num="4.5 (3)"/><vers num="4.5 (2)"/><vers num="4.5 (14)"/><vers num="4.5 (13a)"/><vers num="4.5 (13)"/><vers num="4.5 (12a)"/><vers num="4.5 (12)"/><vers num="4.5 (11)"/><vers num="4.5 (10)"/><vers num="4.5 (1)"/><vers num="5.1 (2b)"/><vers num="5.1 (2a)"/><vers num="5.1 (1a)CSX"/><vers num="5.1 (1a)"/><vers num="5.1 (1)CSX"/><vers num="5.1 (1)"/><vers num="5.2 (7a)"/><vers num="5.2 (7)"/><vers num="5.2 (6)"/><vers num="5.2 (5)"/><vers num="5.2 (4)"/><vers num="5.2 (3a)CSX"/><vers num="5.2 (3)CSX"/><vers num="5.2 (3)"/><vers num="5.2 (2)CSX"/><vers num="5.2 (2)"/><vers num="5.2 (1)CSX"/><vers num="5.2 (1)"/><vers num="5.3 (6a)CSX"/><vers num="5.3 (6)CSX"/><vers num="5.3 (5a)CSX"/><vers num="5.3 (5)CSX"/><vers num="5.3 (4)CSX"/><vers num="5.3 (3)CSX"/><vers num="5.3 (2)CSX"/><vers num="5.3 (1a)CSX"/><vers num="5.4 (4a)"/><vers num="5.4 (4)"/><vers num="5.4 (3)"/><vers num="5.4 (2a)"/><vers num="5.4 (2)"/><vers num="5.4 (1) - deferred"/><vers num="5.4 (1)"/><vers num="5.4"/><vers num="5.5 (9)"/><vers num="5.5 (8a)CV"/><vers num="5.5 (8a)"/><vers num="5.5 (8)"/><vers num="5.5 (7a)"/><vers num="5.5 (7)"/><vers num="5.5 (6a)"/><vers num="5.5 (6)"/><vers num="5.5 (5)"/><vers num="5.5 (4b)"/><vers num="5.5 (4a)"/><vers num="5.5 (4)"/><vers num="5.5 (3)"/><vers num="5.5 (2)"/><vers num="5.5 (1a)"/><vers num="5.5 (19)"/><vers num="5.5 (18)"/><vers num="5.5 (17)"/><vers num="5.5 (16.2)"/><vers num="5.5 (16)"/><vers num="5.5 (15)"/><vers num="5.5 (14)"/><vers num="5.5 (13a)"/><vers num="5.5 (13.5)"/><vers num="5.5 (13)"/><vers num="5.5 (12a)"/><vers num="5.5 (12)"/><vers num="5.5 (11a)"/><vers num="5.5 (11)"/><vers num="5.5 (10a)"/><vers num="5.5 (10)"/><vers num="5.5 (1)"/><vers num="5.5"/><vers num="6.1 (4b)"/><vers num="6.1 (4)"/><vers num="6.1 (3a)"/><vers num="6.1 (3)"/><vers num="6.1 (2a)"/><vers num="6.1 (2)"/><vers num="6.1 (1e)"/><vers num="6.1 (1d)"/><vers num="6.1 (1c)"/><vers num="6.1 (1b)"/><vers num="6.1 (1a)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.2 (3a)"/><vers num="6.2 (3)"/><vers num="6.2 (2a)"/><vers num="6.2 (2)"/><vers num="6.2 (1a)"/><vers num="6.2 (1)"/><vers num="6.3 (9)"/><vers num="6.3 (8.3)"/><vers num="6.3 (8)"/><vers num="6.3 (7)"/><vers num="6.3 (6)"/><vers num="6.3 (5.10)"/><vers num="6.3 (5)"/><vers num="6.3 (4a)"/><vers num="6.3 (4)"/><vers num="6.3 (3a)"/><vers num="6.3 (3)x1"/><vers num="6.3 (3)x"/><vers num="6.3 (3)"/><vers num="6.3 (2a)"/><vers num="6.3 (2)"/><vers num="6.3 (1a)"/><vers num="6.3 (10)"/><vers num="6.3 (1)"/><vers num="6.4 (8)"/><vers num="6.4 (7)"/><vers num="6.4 (6)"/><vers num="6.4 (5)"/><vers num="6.4 (4a)"/><vers num="6.4 (3)"/><vers num="6.4 (2)"/><vers num="6.4 (1)"/><vers num="7.1 (2a)"/><vers num="7.1 (2)"/><vers num="7.1 (1a)"/><vers num="7.1 (1)"/><vers num="7.2 (2)"/><vers num="7.2 (1)"/><vers num="7.2 (0.65)"/><vers num="7.3 (2)"/><vers num="7.3 (1)"/><vers num="7.3"/><vers num="7.4 (3)"/><vers num="7.4 (2)"/><vers num="7.4 (1)"/><vers num="7.4 (0.63)"/><vers num="7.4 (0.2)CLR"/><vers num="7.4"/><vers num="7.5 (1)"/><vers num="7.5"/><vers num="7.6 (5)"/><vers num="7.6 (4)"/><vers num="7.6 (3)"/><vers num="7.6 (2)"/><vers num="7.6 (1)"/><vers num="7.6"/><vers num="8.1 (3)"/><vers num="8.1 (2)"/><vers num="8.1"/><vers num="8.2 (1)"/><vers num="8.2"/><vers num="8.3 GLX"/><vers num="8.3 (1)GLX"/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num="2.1 (2)WS-X6380-NAM"/><vers num="2.2 (1a)WS-SVC-NAM-2"/><vers num="2.2 (1a)WS-SVC-NAM-1"/><vers num="3.1 (1a)WS-X6380-NAM"/><vers num="3.1 (1a)WS-SVC-NAM-2"/><vers num="3.1 (1a)WS-SVC-NAM-1"/><vers num="5.3 (6)CSX"/><vers num="5.3 (5a)CSX"/><vers num="5.3 (5)CSX"/><vers num="5.3 (4)CSX"/><vers num="5.3 (3)CSX"/><vers num="5.3 (2)CSX"/><vers num="5.3 (1a)CSX"/><vers num="5.3 (1)CSX"/><vers num="5.4 (4)"/><vers num="5.4 (3)"/><vers num="5.4 (2)"/><vers num="5.4 (1)"/><vers num="5.4"/><vers num="5.4.1"/><vers num="5.5 (4b)"/><vers num="5.5 (4a)"/><vers num="5.5 (4)"/><vers num="5.5 (3)"/><vers num="5.5 (2)"/><vers num="5.5 (13)"/><vers num="5.5 (1)"/><vers num="5.5"/><vers num="6.1 (2.13)"/><vers num="6.1 (1c)"/><vers num="6.1 (1b)"/><vers num="6.1 (1a)"/><vers num="6.1 (1)"/><vers num="6.2 (0.111)"/><vers num="6.2 (0.110)"/><vers num="6.3 (4)"/><vers num="6.3 (0.7)PAN"/><vers num="7.1 (2)"/><vers num="7.1"/><vers num="7.5 (1)"/><vers num="7.6 (1)"/></prod><prod name="Catalyst 4500" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst" vendor="Cisco"><vers num="2980G-A"/><vers num="2980G"/><vers num="2901"/><vers num="2902"/><vers num="2926"/><vers num="2926F"/><vers num="2926GL"/><vers num="2926GS"/><vers num="2926T"/><vers num="2948"/><vers num="2948G"/><vers num="2948G-GE-TX"/><vers num="2948G-l3"/><vers num="4000"/><vers num="4000 4.5 (9)"/><vers num="4000 4.5 (8)"/><vers num="4000 4.5 (7)"/><vers num="4000 4.5 (6)"/><vers num="4000 4.5 (5)"/><vers num="4000 4.5 (4b)"/><vers num="4000 4.5 (4)"/><vers num="4000 4.5 (3)"/><vers num="4000 4.5 (2)"/><vers num="4000 4.5 (10)"/><vers num="4000 5.1 (2a)"/><vers num="4000 5.1 (1a)"/><vers num="4000 5.1 (1)"/><vers num="4000 5.1"/></prod><prod name="Catalyst 5000" vendor="Cisco"><vers num=""/><vers num="4.5 (9)"/><vers num="4.5 (8)"/><vers num="4.5 (7)"/><vers num="4.5 (6)"/><vers num="4.5 (5)"/><vers num="4.5 (4b)"/><vers num="4.5 (4)"/><vers num="4.5 (3)"/><vers num="4.5 (2)"/><vers num="4.5 (13a)"/><vers num="4.5 (12)"/><vers num="4.5 (11)"/><vers num="4.5.10"/><vers num="5.1 (2a)"/><vers num="5.1 (1)"/><vers num="5.1"/><vers num="5.2 (4)"/><vers num="5.2 (3)"/><vers num="5.2 (2)"/><vers num="5.2 (1)"/><vers num="5.2"/><vers num="5.4 (4)"/><vers num="5.4 (3)"/><vers num="5.4 (2)"/><vers num="5.4 (1)"/><vers num="5.4.1"/><vers num="5.5 (7)"/><vers num="5.5 (6)"/><vers num="5.5 (4b)"/><vers num="5.5 (4)"/><vers num="5.5 (3)"/><vers num="5.5 (2)"/><vers num="5.5 (13)"/><vers num="5.5 (1)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1c)"/><vers num="6.1 (1b)"/><vers num="6.1 (1a)"/><vers num="6.1 (1)"/><vers num="6.3 (4)"/></prod><prod name="Catalyst 4507R" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 4000" vendor="Cisco"><vers num="5.2 (7)"/><vers num="5.2 (6)"/><vers num="5.2 (5)"/><vers num="5.2 (4)"/><vers num="5.2 (2)"/><vers num="5.2 (1a)"/><vers num="5.2 (1)"/><vers num="5.2"/><vers num="5.4 (3)"/><vers num="5.4 (2)"/><vers num="5.4 (1)"/><vers num="5.4"/><vers num="5.4.1"/><vers num="5.5 (4b)"/><vers num="5.5 (4)"/><vers num="5.5 (3)"/><vers num="5.5 (2)"/><vers num="5.5 (13)"/><vers num="5.5 (1)"/><vers num="5.5"/><vers num="5.5.5"/><vers num="6.1 (1c)"/><vers num="6.1 (1b)"/><vers num="6.1 (1a)"/><vers num="6.1 (1)"/><vers num="6.3 (4)"/><vers num="6.3.5"/><vers num="7.1 (2)"/><vers num="7.1"/><vers num="7.1.2"/><vers num="7.5 (1)"/><vers num="7.6 (1)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0552" published="2004-11-03" seq="2004-0552" severity="High" type="CVE"><desc><descript source="cve">Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Kurt Seifried" url="http://www.seifried.org/security/advisories/kssa-005.html">Kurt Seifried Security Advisory 005 (KSSA-005)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17468">Sophos Small Business Suite bypass security</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=143&amp;type=vulnerabilities">20040922 Sophos Small Business Suite Reserved Device Name Handling Vulnerability</ref></refs><vuln_soft><prod name="Small Business Suite" vendor="Sophos"><vers num="1.00" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0554" published="2004-08-06" seq="2004-0554" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a &quot;crash.c&quot; program.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10566">Linux Kernel Multiple Device Driver Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16412">Linux Kernel fsave and frstor denial of service</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/973654">Linux kernel fails to properly handle floating point signals generated by </ref><ref source="MISC" url="http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905">http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905</ref><ref source="MISC" url="http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html">http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108681568931323&amp;w=2">[linux-kernel] 20040609 timer + fpu stuff locks my console race</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845">CLA-2004:845</ref><ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108793699910896&amp;w=2">ESA-20040621-005</ref><ref source="FEDORA" url="http://lwn.net/Articles/91155/">FEDORA-2004-186</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:062">MDKSA-2004:062</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-255.html">RHSA-2004:255</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-260.html">RHSA-2004:260</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_17_kernel.html">SuSE-SA:2004:017</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0034/">2004-0034</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2915.html">OVAL2915</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786114032681&amp;w=2">20040620 TSSA-2004-011 - kernel</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2915">oval:org.mitre.oval:def:2915</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:062">MDKSA-2004:062</ref><ref source="BID" url="http://www.securityfocus.com/bid/10538">10538</ref></refs><vuln_soft><prod name="SuSE Office Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE eMail Server" vendor="SuSE"><vers num="3.1"/><vers num="III"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="SuSE Linux Admin-CD for Firewall" vendor="SuSE"><vers num=""/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/></prod><prod name="SuSE Linux Connectivity Server" vendor="SuSE"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="LX"/></prod><prod name="SuSE Linux Firewall CD" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="7"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SuSE Linux Office Server" vendor="SuSE"><vers num=""/></prod><prod name="SuSE Linux Database Server" vendor="SuSE"><vers num=""/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="8.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0555" published="2004-12-31" seq="2004-0555" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-643">DSA-643</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012929.html">http://www.securitytracker.com/alerts/2005/Jan/1012929.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18945">queue-bo(18945)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012929">1012929</ref></refs><vuln_soft><prod name="queue" vendor="GNU"><vers num="1.20.2"/><vers num="1.20.1"/><vers num="1.12.9"/><vers num="1.20.0pre4"/><vers num="1.12.8"/><vers num="1.20.0pre3"/><vers num="1.12.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0557" published="2004-08-06" seq="2004-0557" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10819">SoX WAV File Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16827">SoX .wav file buffer overflow</ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-23.xml">SoX: Multiple buffer overflows</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-409.html">Updated sox packages fix buffer overflows</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2004/Jul/1229.html">20040728 SoX buffer overflows when handling .WAV files</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0014.html">20040728 SoX buffer overflows when handling .WAV files</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-565">DSA-565</ref><ref source="FEDORA" url="http://lwn.net/Articles/95530/">FEDORA-2004-244</ref><ref source="FEDORA" url="http://lwn.net/Articles/95529/">FEDORA-2004-235</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1945">FLSA:1945</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:076">MDKSA-2004:076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12175">12175</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000855">CLA-2004:855</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:076">MDKSA-2004:076</ref><ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2004/Jul/1227.html">20040728 SoX buffer overflows when handling .WAV files</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="8.0"/><vers num="9.0"/><vers num="10.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="SoX" vendor="SoX"><vers num="12.17.2"/><vers num="12.17.3"/><vers num="12.17.4"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/><vers num="Core 1.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0558" published="2004-09-28" seq="2004-0558" severity="Medium" type="CVE"><desc><descript source="cve">The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="redhat" url="http://www.redhat.com/support/errata/RHSA-2004-449.html">Updated CUPS packages fix security vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-545">DSA-545</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2072">FLSA:2072</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17389">cups-udp-dos(17389)</ref><ref source="SCO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760654431316&amp;w=2">SCOSA-2004.15</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000872">CLA-2004:872</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57646-1">57646</ref><ref source="BID" url="http://www.securityfocus.com/bid/11183">11183</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.1.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0559" published="2004-10-20" seq="2004-0559" severity="Low" type="CVE"><desc><descript source="cve">The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200409-15.xml">Webmin, Usermin: Multiple vulnerabilities in Usermin</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/12488/">Usermin Shell Command Injection and Insecure Installation Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17299">Usermin installation of directory prior to installation of interface causes unspecified issue</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11153">bid 11153</ref><ref source="CONFIRM" url="http://www.webmin.com/uchanges-1.089.html">http://www.webmin.com/uchanges-1.089.html</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Usermin" vendor="Usermin"><vers num="1.080"/><vers num="1.070"/><vers num="1.060"/><vers num="1.051"/><vers num="1.040"/><vers num="1.030"/><vers num="1.020"/><vers num="1.010"/><vers num="1.000"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.0.90"/><vers num="1.0.80"/><vers num="1.0.70"/><vers num="1.0.60"/><vers num="1.0.50"/><vers num="1.0.20"/><vers num="1.0.00"/><vers num="1.1.00"/><vers num="1.1.10"/><vers num="1.1.21"/><vers num="1.1.30"/><vers num="1.1.40"/><vers num="1.1.50"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0560" published="2004-12-31" seq="2004-0560" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-638">DSA-638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13855">13855</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0561" published="2004-12-31" seq="2004-0561" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-638">DSA-638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13855">13855</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0563" published="2004-12-23" seq="2004-0563" severity="Low" type="CVE"><desc><descript source="cve">The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a username and password.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-555">freenet6 -- wrong file permissions</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11280">bid 11280</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17544">Freenet6 permissions are world-readable</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011460">1011460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12705/">12705</ref></refs><vuln_soft><prod name="Freenet6" vendor="Freenet6"><vers num="0.9.6"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0564" published="2004-12-23" seq="2004-0564" severity="Low" type="CVE"><desc><descript source="cve">Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files.  NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe &quot;is NOT designed to run setuid-root.&quot;  Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer&apos;s warnings.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-557">rp-pppoe -- missing privilege dropping</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17576">PPPoE allows attacker to overwrite files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11315">bid 11315</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110247119200510&amp;w=2"> MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC1/2005-11-14-FLSA_2005_152794__Updated_rp_pppoe_package_fixes_security_issue.html">FLSA:152794</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110253341209450&amp;w=2">20041208 Re: MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability</ref></refs><vuln_soft><prod name="PPPoE" vendor="Roaring Penguin"><vers num="3.0"/><vers num="3.3"/><vers num="3.5"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0565" published="2004-12-06" seq="2004-0565" severity="Low" type="CVE"><desc><descript source="cve">Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Redhat Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734">124734</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html">[owl-users] 20040619 Linux 2.4.26-ow2</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:066">MDKSA-2004:066</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16644">linux-ia64-info-disclosure(16644)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="BID" url="http://www.securityfocus.com/bid/10687">10687</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:066">MDKSA-2004:066</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Linux Corporate Server" vendor="MandrakeSoft"><vers num="2.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0566" published="2004-07-27" seq="2004-0566" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9663">BID:9663</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0806.html">20040215 GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15210">ie-bmp-integer-overflow(15210)</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html">Critical Vulnerabilities in Microsoft Windows</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx">MS04-025</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/266926">VU#266926</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval216.html">OVAL216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval306.html">OVAL306</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval322.html">OVAL322</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval507.html">OVAL507</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval515.html">OVAL515</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:216">oval:org.mitre.oval:def:216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:306">oval:org.mitre.oval:def:306</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:322">oval:org.mitre.oval:def:322</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:507">oval:org.mitre.oval:def:507</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:515">oval:org.mitre.oval:def:515</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2004-0567" published="2004-12-31" seq="2004-0567" severity="High" type="CVE"><desc><descript source="cve">The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an &quot;unchecked buffer&quot; and possibly triggers a buffer overflow, aka the &quot;Name Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx">MS04-045</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/378160">VU#378160</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-054.shtml">P-054</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18259">wins-memory-pointer-hijack(18259)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11922">11922</ref><ref source="OSVDB" url="http://www.osvdb.org/12370">12370</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012517">1012517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13466">13466</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP3"/><vers num="Server SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0568" published="2005-01-10" seq="2004-0568" severity="High" type="CVE"><desc><descript source="cve">HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11916">Hilgraeve HyperTerminal Session Data Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-043.asp">Vulnerability in HyperTerminal Could Allow Code Execution (873339)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312618614849&amp;w=2">HyperTerminal - Buffer Overflow In .ht File</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1603">OVAL1603</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2545">OVAL2545</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3138">OVAL3138</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3973">OVAL3973</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4508">OVAL4508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4741">OVAL4741</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18336">win-hyperterminal-session-bo(18336)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1603">oval:org.mitre.oval:def:1603</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2545">oval:org.mitre.oval:def:2545</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3138">oval:org.mitre.oval:def:3138</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3973">oval:org.mitre.oval:def:3973</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4508">oval:org.mitre.oval:def:4508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4741">oval:org.mitre.oval:def:4741</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0 alpha"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="R2"/><vers edition="64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Web"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0569" published="2004-11-03" seq="2004-0569" severity="High" type="CVE"><desc><descript source="cve">The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109769394209518&amp;w=2">BindView Advisory: Memory Leak and DoS in NT4 RPC server</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-029.asp">Microsoft Security Bulletin MS04-029</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17646">Microsoft Windows RPC Runtime Library obtain information</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17663">Microsoft Windows MS04-029 patch is not installed</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2505.html">OVAL2505</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5277.html">OVAL5277</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2505">oval:org.mitre.oval:def:2505</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5277">oval:org.mitre.oval:def:5277</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0571" published="2005-01-10" seq="2004-0571" severity="High" type="CVE"><desc><descript source="cve">Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Table Conversion Vulnerability,&quot; a different vulnerability than CVE-2004-0901.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-041.asp">Vulnerability in WordPad Could Allow Code Execution (885836)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11927">Microsoft Word for Windows 6.0 Converter Table Conversion Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1168.html">OVAL1168</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1417.html">OVAL1417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1959.html">OVAL1959</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1976.html">OVAL1976</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3416.html">OVAL3416</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3743.html">OVAL3743</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4328.html">OVAL4328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval685.html">OVAL685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18337">win-converter-table-code-execution(18337)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1168">oval:org.mitre.oval:def:1168</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1417">oval:org.mitre.oval:def:1417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1959">oval:org.mitre.oval:def:1959</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1976">oval:org.mitre.oval:def:1976</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3416">oval:org.mitre.oval:def:3416</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3743">oval:org.mitre.oval:def:3743</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4328">oval:org.mitre.oval:def:4328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:685">oval:org.mitre.oval:def:685</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0572" published="2004-11-03" seq="2004-0572" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="archives.neohapsis.com" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0290.html">Re: [Full-Disclosure] shell:windows command question</ref><ref adv="1" patch="1" source="mocrosoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-037.asp">Vulnerability in Windows Shell Could Allow Remote Code Execution (841356</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/543864">Microsoft Windows Program Group Converter vulnerable to buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10677">Microsoft Windows Program Group Converter Filename Local Buffer Overrun Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16664">Microsoft Windows Program Group Converter buffer overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1279.html">OVAL1279</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1837.html">OVAL1837</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1843.html">OVAL1843</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2753.html">OVAL2753</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3071.html">OVAL3071</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3768.html">OVAL3768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3822.html">OVAL3822</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4244.html">OVAL4244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4493.html">OVAL4493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17662">win-ms04037-patch(17662)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1279">oval:org.mitre.oval:def:1279</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1837">oval:org.mitre.oval:def:1837</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1843">oval:org.mitre.oval:def:1843</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2753">oval:org.mitre.oval:def:2753</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3071">oval:org.mitre.oval:def:3071</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3768">oval:org.mitre.oval:def:3768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3822">oval:org.mitre.oval:def:3822</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4244">oval:org.mitre.oval:def:4244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4493">oval:org.mitre.oval:def:4493</ref></refs><vuln_soft><prod name="grpconv" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0573" published="2004-09-28" seq="2004-0573" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109519646030906&amp;w=2">Microsoft Office WordPerfect Converter Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-027.asp">Microsoft Security Bulletin MS04-027</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17306">Microsoft WordPerfect converter long message buffer overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2670.html">OVAL2670</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3311.html">OVAL3311</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3333.html">OVAL3333</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4005.html">OVAL4005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5021.html">OVAL5021</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/449438">VU#449438</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011249">1011249</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011250">1011250</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011251">1011251</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011252">1011252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12529">12529</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2670">oval:org.mitre.oval:def:2670</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3311">oval:org.mitre.oval:def:3311</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3333">oval:org.mitre.oval:def:3333</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4005">oval:org.mitre.oval:def:4005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5021">oval:org.mitre.oval:def:5021</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000"/><vers edition="Student_Teacher" num="2003"/><vers num="XP"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2001"/><vers num="2002"/><vers num="2003"/><vers num="2004"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0574" published="2004-11-03" seq="2004-0574" severity="High" type="CVE"><desc><descript source="cve">The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an &quot;unchecked buffer,&quot; leading to off-by-one and heap-based buffer overflows.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-036.asp">Vulnerability in NNTP Could Allow Remote Code Execution (883935)</ref><ref adv="1" source="www.ciac.org" url="http://www.ciac.org/ciac/bulletins/p-012.shtml">P-012: Microsoft Vulnerability in NNTP Could Allow Remote Code Execution (883935)</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/203126">Microsoft IIS contains vulnerability in NNTP service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17641">Microsoft Windows NNTP buffer overflow</ref><ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=420&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=420&amp;idxseccion=10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval246.html">OVAL246</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4392.html">OVAL4392</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5070.html">OVAL5070</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5926.html">OVAL5926</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17661">win-ms04036-patch(17661)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761632831563&amp;w=2">20041012 CORE-2004-0802: IIS NNTP Service XPAT Command Vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:246">oval:org.mitre.oval:def:246</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4392">oval:org.mitre.oval:def:4392</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5070">oval:org.mitre.oval:def:5070</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5926">oval:org.mitre.oval:def:5926</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5021">oval:org.mitre.oval:def:5021</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Server 4.0"/></prod><prod name="exchange srv" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0575" published="2004-11-03" seq="2004-0575" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an &quot;unchecked buffer&quot; and improper length validation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-034.asp">Vulnerability in Compressed (zipped) Folders Could Allow Remote Code Execution (873376)</ref><ref adv="1" source="www.ciac.org" url="http://www.ciac.org/ciac/bulletins/p-010.shtml">P-010: Microsoft Compressed (Zipped) Folders Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17624">Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17659">Microsoft Windows MS04-034 patch is not installed</ref><ref source="MISC" url="http://www.eeye.com/html/research/advisories/AD20041012A.html">http://www.eeye.com/html/research/advisories/AD20041012A.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1053.html">OVAL1053</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3913.html">OVAL3913</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4276.html">OVAL4276</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6397.html">OVAL6397</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/649374">VU#649374</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011637">1011637</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109767342326300&amp;w=2">20041013 EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1053">oval:org.mitre.oval:def:1053</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3913">oval:org.mitre.oval:def:3913</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4276">oval:org.mitre.oval:def:4276</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6397">oval:org.mitre.oval:def:6397</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers num="64-bit"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="64-bit"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0576" published="2004-12-06" seq="2004-0576" severity="Medium" type="CVE"><desc><descript source="cve">The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108785242716726&amp;w=2">20040621 [Full-Disclosure] iDEFENSE Security Advisory 06.21.04 - GNU Radius SNMP Invalid OID Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=110&amp;type=vulnerabilities"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16466">radius-snmp-oid-dos(16466)</ref></refs><vuln_soft><prod name="Radius" vendor="GNU"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0577" published="2004-12-06" seq="2004-0577" severity="Medium" type="CVE"><desc><descript source="cve">WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to the wingate-internal directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108872788123695&amp;w=2">20040701 iDEFENSE Security Advisory 07.01.04: WinGate Information Disclosure</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16589">wingate-directory-traversal(16589)</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=113">http://www.idefense.com/application/poi/display?id=113</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num="5.0.5"/><vers num="5.2.3"/><vers num="6.0 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0578" published="2004-12-06" seq="2004-0578" severity="Medium" type="CVE"><desc><descript source="cve">WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108872788123695&amp;w=2">20040701 iDEFENSE Security Advisory 07.01.04: WinGate Information Disclosure</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16589">wingate-directory-traversal(16589)</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=113">http://www.idefense.com/application/poi/display?id=113</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num="5.0.5"/><vers num="5.2.3"/><vers num="6.0 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0579" published="2004-08-06" seq="2004-0579" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16458">super format string attack</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-522">DSA-522-1 super -- format string vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10575/">Super Local Format String Vulnerability</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="super" vendor="William Deich"><vers num="3.12"/><vers num="3.16"/><vers num="3.17"/><vers num="3.18"/><vers num="3.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0580" published="2004-08-06" seq="2004-0580" severity="Medium" type="CVE"><desc><descript source="cve">DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10329">Multiple Linksys Devices DHCP Information Disclosure and Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16142">Linksys EtherFast routers BOOTP packet denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108662876129301&amp;w=2">Linksys BEFSR41 DHCP vulnerability server leaks network data</ref><ref source="OSVDB" url="http://www.osvdb.org/6325">6325</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/May/1010288.html">1010288</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11606">11606</ref><ref source="" url="http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=832&amp;p_%20%5Ccreated=1086294093&amp;p_sid=pU1X1idh&amp;p_lva=&amp;p_sp=cF9zcmNoPSZwX3NvcnRfYnk9JnBfZ3JpZHNvcnQ9%20%5CJnBfcm93X2NudD02NTQmcF9wYWdlPTE*&amp;p_li="></ref></refs><vuln_soft><prod name="EtherFast BEFVP41 Router" vendor="Linksys"><vers num=""/><vers num="1.39.64"/></prod><prod name="RV082" vendor="Linksys"><vers num=""/></prod><prod name="BEFVP41" vendor="Linksys"><vers num="1.40.4"/><vers num="1.40.3f"/><vers num="1.42.7"/></prod><prod name="EtherFast BEFSR81 Router" vendor="Linksys"><vers num=""/><vers num="2.42.7"/><vers num="2.44"/></prod><prod name="BEFN2PS4" vendor="Linksys"><vers num="1.42.7"/></prod><prod name="BEFCMU10" vendor="Linksys"><vers num=""/></prod><prod name="EtherFast BEFN2PS4 Router" vendor="Linksys"><vers num=""/></prod><prod name="BEFSR41W" vendor="Linksys"><vers num=""/></prod><prod name="EtherFast BEFSR11 Router" vendor="Linksys"><vers num="1.40.2"/><vers num="1.41"/><vers num="1.42.3"/><vers num="1.42.7"/><vers num="1.43"/><vers num="1.43.3"/><vers num="1.44"/></prod><prod name="WAP55AG" vendor="Linksys"><vers num="1.0.7"/></prod><prod name="BEFSX41" vendor="Linksys"><vers num="1.42.7"/><vers num="1.43"/><vers num="1.43.3"/><vers num="1.43.4"/><vers num="1.44"/><vers num="1.44.3"/><vers num="1.45.3"/></prod><prod name="BEFSR81" vendor="Linksys"><vers num=""/></prod><prod name="EtherFast BEFSRU31 Router" vendor="Linksys"><vers num="1.40.2"/><vers num="1.41"/><vers num="1.42.3"/><vers num="1.42.7"/><vers num="1.43"/><vers num="1.43.3"/><vers num="1.44"/></prod><prod name="WRT54G" vendor="Linksys"><vers num="1.42.3"/><vers num="2.00.8"/></prod><prod name="EtherFast BEFSR41 Router" vendor="Linksys"><vers num="1.35"/><vers num="1.36"/><vers num="1.37"/><vers num="1.38"/><vers num="1.39"/><vers num="1.40.2"/><vers num="1.41"/><vers num="1.42.3"/><vers num="1.42.7"/><vers num="1.43"/><vers num="1.43.3"/><vers num="1.44"/><vers num="1.45.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0581" published="2004-08-06" seq="2004-0581" severity="Medium" type="CVE"><desc><descript source="cve">ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10516">KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16392">ksymoops-gznm symlink attack</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:060">MDKSA-2004:060</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Ksymoops" vendor="GNU"><vers num="2.4.5"/><vers num="2.4.8"/><vers num="2.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0582" published="2004-08-06" seq="2004-0582" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10522">Webmin Configuration Module Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10474">Webmin Multiple Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16333">Webmin allows security restriction bypass</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108697184602191&amp;w=2">[SNS Advisory No.74] Webmin Access Control Rule Bypass Vulnerability</ref><ref source="MISC" url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/74_e.html">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/74_e.html</ref><ref source="CONFIRM" url="http://www.webmin.com/changes-1.150.html">http://www.webmin.com/changes-1.150.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-526">DSA-526</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-12.xml">GLSA-200406-12</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:074">MDKSA-2004:074</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000848">CLA-2004:848</ref></refs><vuln_soft><prod name="Webmin" vendor="Webmin"><vers num="1.1.40"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0583" published="2004-08-06" seq="2004-0583" severity="Medium" type="CVE"><desc><descript source="cve">The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10523">Webmin And Usermin Account Lockout Bypass Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10474">Webmin Multiple Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16334">Webmin username or password denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108737059313829&amp;w=2">[SNS Advisory No.75] Webmin/Usermin Account Lockout Bypass Vulnerability</ref><ref source="MISC" url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.html">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.html</ref><ref source="CONFIRM" url="http://www.webmin.com/changes-1.150.html">http://www.webmin.com/changes-1.150.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-526">DSA-526</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-12.xml">GLSA-200406-12</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-15.xml">GLSA-200406-15</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:074">MDKSA-2004:074</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="1.070"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.1.40"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0584" published="2004-08-06" seq="2004-0584" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a &quot;security fix,&quot; does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10501">Horde IMP Email Header HTML Injection Vulnerability</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16357">Horde IMP Content-type header cross-site scripting</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-11.xml">Horde-IMP: Input validation vulnerability</ref><ref patch="1" source="MISC" url="http://www.horde.org/imp/3.2/">http://www.horde.org/imp/3.2/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11805">11805</ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="2.0"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.3"/><vers num="3.0"/><vers num="3.1"/><vers num="3.1.2"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0585" published="2004-08-06" reject="1" seq="2004-0585" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0589.  Reason: This candidate is a duplicate of CVE-2004-0589.  Notes: All CVE users should reference CVE-2004-0589 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0586" published="2004-08-06" seq="2004-0586" severity="High" type="CVE"><desc><descript source="cve">acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16429">IBM acpRunner could allow code execution</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108745652205176&amp;w=2">IBM acpRunner Activex Dangerous Methods Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10561">IBM ACPRunner ActiveX Control Dangerous Method Vulnerability</ref><ref source="CONFIRM" url="http://www-306.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-54588">http://www-306.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-54588</ref></refs><vuln_soft><prod name="acpRunner" vendor="IBM"><vers num="1.2.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0587" published="2004-08-06" seq="2004-0587" severity="Low" type="CVE"><desc><descript source="cve">Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10279">Linux Kernel HbaApiNode Improper File Permissions Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16062">SuSE HbaApiNode denial of service</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/May/1010057.html">http://www.securitytracker.com/alerts/2004/May/1010057.html</ref><ref source="FEDORA" url="http://lwn.net/Articles/91155/">FEDORA-2004-186</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066">MDKSA-2004:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">RHSA-2004:413</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-418.html">RHSA-2004:418</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010057">1010057</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="9.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0588" published="2004-08-06" seq="2004-0588" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update:
Usermin, Usermin, 1.080</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10521">Usermin HTML Email Script Code Execution Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16494">Usermin email message cross-site scripting</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108781564518287&amp;w=2">[SNS Advisory No.73] Usermin Cross-site Scripting Vulnerability</ref><ref source="MISC" url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/73_e.html">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/73_e.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-15.xml">GLSA-200406-15</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="1.070"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0589" published="2004-08-06" seq="2004-0589" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16427">Cisco IOS BGP packet denial of service</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/784540">BGP implementations do not adequately handle malformed BGP OPEN and UPDATE messages</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040616-bgp.shtml">20040616 Cisco IOS Malformed BGP Packet Causes Reload</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0590" published="2004-12-06" seq="2004-0590" severity="High" type="CVE"><desc><descript source="cve">FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Openswan" url="http://www.openswan.org/support/vuln/can-2004-0590/"></ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-20.xml">GLSA-200406-20</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:070">MDKSA-2004:070</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16515">ipsec-verifyx509cert-auth-bypass(16515)</ref></refs><vuln_soft><prod name="FreeS_WAN" vendor="FreeS_WAN"><vers num="1"/><vers num="2"/></prod><prod name="openswan" vendor="Openswan"><vers num="1"/><vers num="2"/></prod><prod name="strongSwan" vendor="StrongSwan"><vers num="2.1.2" prev="1"/></prod><prod name="Super FreeS_WAN" vendor="FreeS_WAN"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0591" published="2004-08-06" seq="2004-0591" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a &quot;message/delivery-status&quot; MIME Content-Type.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Inter7, SqWebMail, 4.0.5</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10588">SqWebMail Email Header HTML Injection Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16467">SqWebMail print_header-uc function cross-site scripting</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786212220140&amp;w=2">XSS vulnerability in Sqwebmail 4.0.4</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-533">DSA-533-1 courier -- cross-site scripting</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11918/">11918</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-02.xml">GLSA-200408-02</ref></refs><vuln_soft><prod name="SqWebMail" vendor="Inter7"><vers num="4.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2004-0592" published="2004-12-31" seq="2004-0592" severity="Medium" type="CVE"><desc><descript source="cve">The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023408.html">20040703 Re: SUSE Security Announcement: kernel (SUSE-SA:2004:020)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43137">linux-kernel-tcpfindoption-dos(43137)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="2.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-0593" published="2004-09-28" seq="2004-0593" severity="High" type="CVE"><desc><descript source="cve">Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="corsaire" url="http://www.corsaire.com/advisories/c031120-003.txt">Sygate Enforcer unauthenticated broadcast issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16948">Sygate Enforcer broadcast traffic bypass filter</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10908">Sygate Secure Enterprise Enforcer Unauthenticated Broadcast Request Bypass Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215731626998&amp;w=2">20040810 Corsaire Security Advisory - Sygate Enforcer unauthenticated broadcast issue</ref></refs><vuln_soft><prod name="Enforcer" vendor="Sygate Technologies"><vers num="3.5MR1" prev="1"/></prod><prod name="Secure Enterprise" vendor="Sygate Technologies"><vers num="3.0"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0594" published="2004-07-27" seq="2004-0594" severity="Medium" type="CVE"><desc><descript source="cve">The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10725/info/">BID:10725</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16693">php-memorylimit-code-execution(16693)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981780109154&amp;w=2">20040713 Advisory 11/2004: PHP memory_limit remote vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023908.html">20040714 Advisory 11/2004: PHP memory_limit remote vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-531">DSA-531</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-669">DSA-669</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml">GLSA-200407-13</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068">MDKSA-2004:068</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-392.html">RHSA-2004:392</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-395.html">RHSA-2004:395</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">RHSA-2004:405</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_21_php4.html">SUSE-SA:2004:021</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0039/">2004-0039</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml">GLSA-200407-13</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108982983426031&amp;w=2">20040714 TSSA-2004-013 - php</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000847">CLA-2004:847</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2">SSRT4777</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051444105182&amp;w=2">20040722 [OpenPKG-SA-2004.034] OpenPKG Security Advisory (php)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="BID" url="http://www.securityfocus.com/bid/10725">10725</ref></refs><vuln_soft><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="4.0"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/></prod><prod name="Integrated Management" vendor="Avaya"><vers num=""/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0595" published="2004-07-27" seq="2004-0595" severity="Medium" type="CVE"><desc><descript source="cve">The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10724">BID:10724</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981780109154&amp;w=2">20040713 Advisory 11/2004: PHP memory_limit remote vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-531">DSA-531</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16692">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023909.html">20040714 Advisory 12/2004: PHP strip_tags() bypass vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-669">DSA-669</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml">GLSA-200407-13</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068">MDKSA-2004:068</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-392.html">RHSA-2004:392</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-395.html">RHSA-2004:395</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">RHSA-2004:405</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_21_php4.html">SUSE-SA:2004:021</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml">GLSA-200407-13</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108982983426031&amp;w=2">20040714 TSSA-2004-013 - php</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000847">CLA-2004:847</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2">SSRT4777</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051444105182&amp;w=2">20040722 [OpenPKG-SA-2004.034] OpenPKG Security Advisory (php)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref></refs><vuln_soft><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/></prod><prod name="Integrated Management" vendor="Avaya"><vers num=""/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0596" published="2004-08-06" seq="2004-0596" severity="Low" type="CVE"><desc><descript source="cve">The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10730">Linux Kernel Equalizer Load Balancer Device Driver Local Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16694">Linux kernel eql.c driver denial of service</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@40d4aa72hPLWy-jMLr0eJAXMxHcNZg">http://linux.bkbits.net:8080/linux-2.6/cset@40d4aa72hPLWy-jMLr0eJAXMxHcNZg</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0597" published="2004-11-23" seq="2004-0597" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16894">libpng png_handle_sBIT and png_handle_tRNS buffer overflow</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html">Multiple Vulnerabilities in libpng</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-536">Debian Security Advisory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10857">LibPNG Graphics Library Multiple Remote Vulnerabilities</ref><ref adv="1" source="MISC" url="http://scary.beasts.org/security/CESA-2004-001.txt">http://scary.beasts.org/security/CESA-2004-001.txt</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1943">FLSA:1943</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml">GLSA-200408-03</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml">GLSA-200408-22</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-009.mspx">MS05-009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-402.html">RHSA-2004:402</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-429.html">RHSA-2004:429</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html">SuSE-SA:2004:023</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0040/">2004-0040</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref patch="1" source="CONFIRM" url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388984">VU#388984</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/817368">VU#817368</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2274.html">OVAL2274</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2378.html">OVAL2378</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval594.html">OVAL594</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4492.html">OVAL4492</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=421&amp;idxseccion=10"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796779903455&amp;w=2">20050209 MSN Messenger PNG Image Buffer Overflow Download Shellcoded Exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856">CLA-2004:856</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2">SSRT4778</ref><ref source="SCO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2">SCOSA-2004.16</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2274">oval:org.mitre.oval:def:2274</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2378">oval:org.mitre.oval:def:2378</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:594">oval:org.mitre.oval:def:594</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4492">oval:org.mitre.oval:def:4492</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22958">22958</ref><ref source="" url="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079">MDKSA-2004:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1">200663</ref></refs><vuln_soft><prod name="libpng" vendor="Greg Roelofs"><vers num="1.2.5" prev="1"/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/></prod><prod name="Windows Messenger" vendor="Microsoft"><vers num="5.0"/></prod><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="6.1"/><vers num="6.2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="SE"/></prod><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0598" published="2004-11-23" seq="2004-0598" severity="Medium" type="CVE"><desc><descript source="cve">The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16895">libpng png_handle_iCCP denial of service</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html">Multiple Vulnerabilities in libpng</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10857">LibPNG Graphics Library Multiple Remote Vulnerabilities</ref><ref adv="1" source="MISC" url="http://scary.beasts.org/security/CESA-2004-001.txt">http://scary.beasts.org/security/CESA-2004-001.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856">CLA-2004:856</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-536">DSA-536</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1943">FLSA:1943</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml">GLSA-200408-03</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml">GLSA-200408-22</ref><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2">SSRT4778</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-402.html">RHSA-2004:402</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-429.html">RHSA-2004:429</ref><ref adv="1" patch="1" source="SCO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2">SCOSA-2004.16</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html">SuSE-SA:2004:023</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0040/">2004-0040</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/236656">VU#236656</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2572.html">OVAL2572</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2572">oval:org.mitre.oval:def:2572</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22958">22958</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079">MDKSA-2004:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1">200663</ref></refs><vuln_soft><prod name="libpng" vendor="Greg Roelofs"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0599" published="2004-11-23" seq="2004-0599" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856">CLA-2004:856</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-536">DSA-536</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-570">DSA-570</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-571">DSA-571</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1943">FLSA:1943</ref><ref adv="1" patch="1" source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml">GLSA-200408-03</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml">GLSA-200408-22</ref><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2">SSRT4778</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-402.html">RHSA-2004:402</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-429.html">RHSA-2004:429</ref><ref adv="1" patch="1" source="SCO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2">SCOSA-2004.16</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html">SuSE-SA:2004:023</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0040/">2004-0040</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/160448">VU#160448</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/286464">VU#286464</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/477512">VU#477512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1479.html">OVAL1479</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1479">oval:org.mitre.oval:def:1479</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22958">22958</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079">MDKSA-2004:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212">MDKSA-2006:212</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213">MDKSA-2006:213</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10857">LibPNG Graphics Library Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16896">libpng integer buffer overflow</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html">Multiple Vulnerabilities in libpng</ref><ref adv="1" source="MISC" url="http://scary.beasts.org/security/CESA-2004-001.txt">http://scary.beasts.org/security/CESA-2004-001.txt</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00056.html">APPLE-SA-2004-09-09</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1">200663</ref></refs><vuln_soft><prod name="libpng" vendor="Greg Roelofs"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0600" published="2004-07-27" seq="2004-0600" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10780/">BID:10780</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052647928375&amp;w=2">20040722 Samba 3.x swat preauthentication buffer overflow</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-259.html">RHSA-2004:259</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16785">Samba SWAT invalid base64 character causes buffer overflow</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-21.xml">GLSA-200407-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071">MDKSA-2004:071</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_22_samba.html">SUSE-SA:2004:022</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0039/">2004-0039</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109053195818351&amp;w=2">20040722 SWAT PreAuthorization PoC</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051340810458&amp;w=2">20040722 Security Release - Samba 3.0.5 and 2.2.10</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000851">CLA-2004:851</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000854">CLA-2004:854</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051533021376&amp;w=2">20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052891507263&amp;w=2">20040722 TSSA-2004-014 - samba</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0601" published="2004-12-23" seq="2004-0601" severity="High" type="CVE"><desc><descript source="cve">distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Samba.org" url="http://distcc.samba.org/ftp/distcc/distcc-2.17.NEWS"></ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/12711/">distcc IP-based Access Control Rules Security Bypass</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11319">bid 11319</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17581">distcc IP gain privileges</ref></refs><vuln_soft><prod name="distcc" vendor="distcc"><vers num="2.7"/><vers num="2.9"/><vers num="2.10"/><vers num="2.11"/><vers num="2.12"/><vers num="2.13"/><vers num="2.14"/><vers num="2.15"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0602" published="2004-12-06" seq="2004-0602" severity="Low" type="CVE"><desc><descript source="cve">The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system panic.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:13.linux.asc">FreeBSD-SA-04:13</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16558">freebsd-binary-information-disclosure(16558)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10643">bugtraq id 10643</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0603" published="2004-12-06" seq="2004-0603" severity="High" type="CVE"><desc><descript source="cve">gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-18.xml">GLSA-200406-18</ref><ref adv="1" source="Gentoo" url="http://bugs.gentoo.org/show_bug.cgi?id=54890"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10603">bugtraq id 10603</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16506">gzip-gzexe-tmpfile(16506)</ref></refs><vuln_soft><prod name="gzip" vendor="GNU"><vers num="1.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0604" published="2004-12-06" seq="2004-0604" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200406-19.xml">GLSA-200406-19</ref><ref source="berliOS" url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=1573&amp;group_id=809"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16508">gift-fasttrack-daemon-dos(16508)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10604">bugtraq id 10604</ref><ref source="CONFIRM" url="http://gift-fasttrack.berlios.de/">http://gift-fasttrack.berlios.de/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11941/">11941</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="giFT-FastTrack" vendor="giFT-FastTrack"><vers num="0.8.0"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.8.3"/><vers num="0.8.4"/><vers num="0.8.5"/><vers num="0.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0605" published="2004-12-06" seq="2004-0605" severity="Medium" type="CVE"><desc><descript source="cve">Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108766803817406&amp;w=2">20040618 ircd-hybrid-7 / ircd-ratbox low-bandwidth DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10572">bugtraq id 10572</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16457">ircd-parseclientqueued-dos(16457)</ref></refs><vuln_soft><prod name="ircd-ratbox" vendor="ircd-ratbox"><vers num="1.5.1" prev="1"/><vers num="2.0 rc6" prev="1"/></prod><prod name="ircd-hybrid" vendor="IRCD-Hybrid"><vers num="7.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0606" published="2004-12-06" seq="2004-0606" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108769996925349&amp;w=2">20040619 Script injection in DNSONE appliance</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10573">bugtraq id 10573</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16456">dnsone-dhcp-report-xss(16456)</ref></refs><vuln_soft><prod name="DNS One Appliance" vendor="Infoblox"><vers num="2.4.0.8A"/><vers num="2.4.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0607" published="2004-12-06" seq="2004-0607" severity="High" type="CVE"><desc><descript source="cve">The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108726102304507&amp;w=2">20040614 authentication bug in KAME&apos;s racoon</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731967126033&amp;w=2">20040615 Re: authentication bug in KAME&apos;s racoon</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200406-17.xml">GLSA-200406-17</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10546">bugtraq id 10546</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16414">racoon-eaycheckx509cert-auth-bypass(16414)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-308.html">RHSA-2004:308</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt">SCOSA-2005.10</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=245982"></ref><ref source="OSVDB" url="http://www.osvdb.org/7113">7113</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010495">1010495</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11863">11863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11877">11877</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Racoon" vendor="KAME"><vers num="2004-05-03"/><vers num="2004-04-07b"/><vers num="2004-04-05"/><vers num="2003-07-11"/><vers num=""/></prod><prod name="IPsec-Tools" vendor="IPsec-Tools"><vers num="0.3 rc5"/><vers num="0.3 rc4"/><vers num="0.3 rc3"/><vers num="0.3 rc2"/><vers num="0.3 rc1"/><vers num="0.3"/><vers num="0.3.1"/><vers num="0.3.2"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0608" published="2004-12-06" seq="2004-0608" severity="High" type="CVE"><desc><descript source="cve">The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/unsecure-adv.txt"></ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-14.xml">GLSA-200407-14</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10570">bugtraq id 10570</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16451">unreal-secure-query-command-execute(16451)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787105023304&amp;w=2">20040618 Code execution in the Unreal Engine through \secure\ packet</ref></refs><vuln_soft><prod name="Unreal Tournament 2003" vendor="Epic Games"><vers num="2225 win32"/><vers num="2225 macOS"/><vers num="2199 win32"/><vers num="2199 macOS"/><vers num="2199 linux"/></prod><prod name="Nerf Arena Blast" vendor="Nerf Arena Blast"><vers num="1.2"/></prod><prod name="DeusEx" vendor="Ion Storm"><vers num="1.112 fm"/></prod><prod name="Unreal Tournament" vendor="Epic Games"><vers num="451b"/></prod><prod name="Unreal Engine" vendor="Epic Games"><vers num="436"/><vers num="433"/><vers num="226f"/></prod><prod name="Unreal Tournament 2004" vendor="Epic Games"><vers num="win32"/><vers num="macOS"/></prod><prod name="Devastation" vendor="ARUSH"><vers num="390.0"/></prod><prod name="X-com Enforcer" vendor="Infogrames"><vers num=""/></prod><prod name="Postal 2" vendor="Running With Scissors"><vers num="1337"/></prod><prod name="TacticalOps" vendor="Infogrames"><vers num="3.4"/></prod><prod name="TNN Outdoors Pro Hunter" vendor="DreamForge"><vers num=""/></prod><prod name="Mobile Forces" vendor="Rage Software"><vers num="20000.0"/></prod><prod name="Wheel of Time" vendor="Robert Jordan"><vers num="333.0b"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0609" published="2004-12-06" seq="2004-0609" severity="Medium" type="CVE"><desc><descript source="cve">rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787373022844&amp;w=2">20040619 Security flaw in rssh</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10574">bugtraq id 10574</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16470">rssh-jail-obtain-info(16470)</ref></refs><vuln_soft><prod name="rssh" vendor="rssh"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0610" published="2004-12-06" seq="2004-0610" severity="Medium" type="CVE"><desc><descript source="cve">The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108796481501258&amp;w=2">20040621 Microsoft MN-500 Wireless Router Web-Based Administration DoS</ref><ref adv="1" source="kurczaba" url="http://www.kurczaba.com/securityadvisories/0406213.htm"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16448">mn500-web-admin-dos(16448)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10585">bugtraq id 10585</ref></refs><vuln_soft><prod name="MN-500" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0611" published="2004-12-06" seq="2004-0611" severity="Medium" type="CVE"><desc><descript source="cve">Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787199201059&amp;w=2">20040621 NETGEAR FVS318 Web-Based Administration DoS</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16462">netgear-fvs318-dos(16462)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10585">bugtraq id 10585</ref></refs><vuln_soft><prod name="FVS318" vendor="NetGear"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0612" published="2004-12-06" seq="2004-0612" severity="Medium" type="CVE"><desc><descript source="cve">The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering.  NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786444608208&amp;w=2">20040621 ZoneAlarm Pro &apos;Mobile Code&apos; Bypass Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0420.html">20040625 Zone Labs response to &quot;ZoneAlarm Pro &apos;Mobile Code&apos; Bypass Vulnerability&quot;</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16471">zonealarm-mobile-code-bypass(16471)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10584">10584</ref></refs><vuln_soft><prod name="ZoneAlarm Pro" vendor="Zone Labs"><vers num="5.0.590.015"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0613" published="2004-12-06" seq="2004-0613" severity="High" type="CVE"><desc><descript source="cve">osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786779500957&amp;w=2">20040621 Multiple osTicket exploits!</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16477">osticket-php-file-upload(16477)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16478">osticket-view-attachments(16478)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10586">bugtraq id 10586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16477">osticket-php-file-upload(16477)</ref></refs><vuln_soft><prod name="osTicket STS" vendor="osTicket"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0614" published="2004-12-06" seq="2004-0614" severity="Medium" type="CVE"><desc><descript source="cve">osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786779500957&amp;w=2">20040621 Multiple osTicket exploits!</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16477">osticket-php-file-upload(16477)</ref></refs><vuln_soft><prod name="osTicket STS" vendor="osTicket"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0615" published="2004-12-06" seq="2004-0615" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16468">dlink614-dhcp-xss(16468)</ref><ref adv="1" source="Security Tracker" url="http://www.securitytracker.com/alerts/2004/Jun/1010562.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010562">1010562</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-07/0014.html">20040701 DLINK 624, script injection vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/10587">10587</ref><ref source="OSVDB" url="http://www.osvdb.org/7211">7211</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11919">11919</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108797273127182&amp;w=2">20040621 DLINK 704, script injection vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786257609932&amp;w=2">20040621 DLINK 614+, script injection vulnerability</ref></refs><vuln_soft><prod name="DI-624" vendor="D-Link"><vers num="1.28" prev="1"/></prod><prod name="DI-614+" vendor="D-Link"><vers num="2.30"/></prod><prod name="DI-704p" vendor="D-Link"><vers num="2.60b2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0616" published="2004-12-06" seq="2004-0616" severity="Medium" type="CVE"><desc><descript source="cve">The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108794963119034&amp;w=2">20040622 Wireless Modem (BT Voyager 2000 Wireless ADSL Router cleartext password)</ref><ref adv="1" patch="1" source="Full-Disclosure" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0710.html">20040622 Wireless Modem (BT Voyager 2000 Wireless ADSL Router cleartext password)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16472">bt-voyager-password-plaintext(16472)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10589">bugtraq id 10589</ref></refs><vuln_soft><prod name="Voyager 2000 Wireless ADSL Router" vendor="BT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0617" published="2004-12-06" seq="2004-0617" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108794392303244&amp;w=2">20040622 ArbitroWeb v0.6 Javascript injection vulnerability</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/10592">bugtraq id 10592</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16481">arbitroweb-rawurl-xss(16481)</ref></refs><vuln_soft><prod name="ArbitroWeb" vendor="ArbitroWeb"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0618" published="2004-12-06" seq="2004-0618" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108816603102865&amp;w=2">20040623 Security Advisory : FreeBSD local DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10596">bugtraq id 10596</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16499">freebsd-execve-dos(16499)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.10 Release"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2.1 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0619" published="2004-12-06" seq="2004-0619" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108802653409053&amp;w=2">20040623 Linux Broadcom 5820 Cryptonet Driver Integer Overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10599">bugtraq id 10599</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16459">bcm5820-adddsabufbytes-integer-bo(16459)</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">Updated kernel packages fix security vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-283.html">RHSA-2005:283</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-047.shtml">P-047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11936">11936</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="8.0"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="kernel" vendor="Red Hat"><vers edition="Athlon" num="2.4.20.8"/><vers edition="i386" num="2.4.20.8"/><vers edition="i586" num="2.4.20.8"/><vers edition="i686" num="2.4.20.8"/><vers edition="athlon smp" num="2.4.20.8"/><vers edition="i586 smp" num="2.4.20.8"/><vers edition="i686 smp" num="2.4.20.8"/><vers edition="i386 src" num="2.4.20.8"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0620" published="2004-12-06" seq="2004-0620" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16502">vbulletin-newreply-newthread-xss(16502)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10602">bugtraq id 10602</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108809720026642&amp;w=2">20040624 vBulletin HTML Injection Vuln</ref></refs><vuln_soft><prod name="VBulletin" vendor="Jelsoft"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0621" published="2004-12-06" seq="2004-0621" severity="High" type="CVE"><desc><descript source="cve">admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><env/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108811585025216&amp;w=2">20040624 ZWS Newsletter &amp; Mailing List Manager</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16507">zws-gain-admin-access(16507)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10605">bugtraq id 10605</ref></refs><vuln_soft><prod name="Newsletter ZWS" vendor="ZaireWeb Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0622" published="2004-12-06" seq="2004-0622" severity="Low" type="CVE"><desc><descript source="cve">Mac OS X 10.3.4 does not properly clear memory for user login, Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108819559925981&amp;w=2">20040625 Mac OS X stores login/Keychain/FileVault passwords on disk</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16557">macos-memory-view-passwords(16557)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0623" published="2004-12-06" seq="2004-0623" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108820000823191&amp;w=2">20040625 format string vulnerability in Gnats</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/bid/10609">bugtraq id 10609</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16517">gnats-format-string(16517)</ref></refs><vuln_soft><prod name="GNATS" vendor="GNU"><vers num="3.0 02"/><vers num="3.2"/><vers num="3.14b"/><vers num="3.113.1.6"/><vers num="3.113"/><vers num="3.113.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0624" published="2004-12-06" seq="2004-0624" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108820257812904&amp;w=2">20040625 artmedic_links5 PHP Script (include path) vuln</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16518">artmedic-url-file-disclosure(16518)</ref></refs><vuln_soft><prod name="Artmedic Links" vendor="Artmedic Webdesign"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0625" published="2004-12-06" seq="2004-0625" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844087931959&amp;w=2">20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB</ref><ref adv="1" patch="1" source="Full-Disclosure" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0893.html">20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB</ref><ref adv="1" patch="1" source="Zone-h" url="http://www.zone-h.org/en/advisories/read/id=4892/">ZH2004-14SA</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/bid/10614">bugtraq id 10614</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16513">infinity-web-sql-injection(16513)</ref></refs><vuln_soft><prod name="Infinity WEB" vendor="WebSoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0626" published="2004-12-06" seq="2004-0626" severity="Medium" type="CVE"><desc><descript source="cve">The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108861141304495&amp;w=2">20040630 Remote DoS vulnerability in Linux kernel 2.6.x</ref><ref adv="1" patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref adv="1" patch="1" source="Fedora" url="http://lwn.net/Articles/91964/">FEDORA-2004-202</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-12.xml">GLSA-200407-12</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16554">linux-tcpfindoption-dos(16554)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html">SUSE-SA:2004:020</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0627" published="2004-12-06" seq="2004-0627" severity="High" type="CVE"><desc><descript source="cve">The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html">20040705 MySQL Authentication Bypass</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2">20040705 MySQL Authentication Bypass</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/184030">VU#184030</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2">20040705 MySQL Authentication Bypass</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0628" published="2004-12-06" seq="2004-0628" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Vulnwatch" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html">20040705 MySQL Authentication Bypass</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2">20040705 MySQL Authentication Bypass</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16612">mysql-myrnd-bo(16612)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/645326">VU#645326</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2">20040705 MySQL Authentication Bypass</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0629" published="2004-09-28" seq="2004-0629" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200408-14.xml">acroread: UUDecode filename buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10947">Adobe Acrobat/Acrobat Reader ActiveX Control URI Request Heap Buffer Overflow Vulnerability</ref><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/330527.html">http://www.adobe.com/support/techdocs/330527.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16998">acrobat-reader-activex-bo(16998)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=126&amp;type=vulnerabilities">20040813 Adobe Acrobat/Acrobat Reader ActiveX Control Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="5.0"/><vers num="5.0.5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.0"/><vers num="5.0.5"/><vers num="5.1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0630" published="2004-08-18" seq="2004-0630" severity="High" type="CVE"><desc><descript source="cve">The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters (&quot;`&quot; or backtick) in the filename of the PDF file that is provided to the uudecode command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16973">Adobe Acrobat Reader allows code execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10931">Adobe Acrobat Reader Shell Metacharacter Remote Arbitrary Code Execution Vulnerability</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200408-14.xml">acroread: UUDecode filename buffer overflow</ref><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/322914.html">http://www.adobe.com/support/techdocs/322914.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-432.html">RHSA-2004:432</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=124&amp;type=vulnerabilities">20040812 Adobe Acrobat Reader (Unix) Shell Metacharacter Code Execution Vulnerability</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0631" published="2004-08-18" seq="2004-0631" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10932">Adobe Acrobat Reader For Unix UUDecode Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16972">Adobe Acrobat Reader uudecode filename buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200408-14.xml">acroread: UUDecode filename buffer overflow</ref><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/322914.html">http://www.adobe.com/support/techdocs/322914.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-432.html">RHSA-2004:432</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=125&amp;type=vulnerabilities">20040812 Adobe Acrobat Reader (Unix) 5.0 Uudecode Filename Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0632" published="2004-07-27" seq="2004-0632" severity="High" type="CVE"><desc><descript source="cve">Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10696/">BID:10696</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16667">adobe-acrobat-null-bo(16667)</ref><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/330527.html">http://www.adobe.com/support/techdocs/330527.html</ref><ref source="MISC" url="http://www.adobe.com/support/techdocs/34222.htm">http://www.adobe.com/support/techdocs/34222.htm</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=116&amp;type=vulnerabilities">20040712 Adobe Reader 6.0 Filename Handler Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="6.0"/><vers num="6.0.1"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0"/><vers num="6.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0633" published="2004-12-06" seq="2004-0633" severity="Medium" type="CVE"><desc><descript source="cve">The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html">FEDORA-2004-219</ref><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html">FEDORA-2004-220</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml">GLSA-200407-08</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067">MDKSA-2004:067</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16630">ethereal-isns-dos(16630)</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00015.html">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-378.html">RHSA-2004:378</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/829422">VU#829422</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010655">1010655</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12024">12024</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.2"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.3"/><vers num="0.10.4"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="AS" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0634" published="2004-12-06" seq="2004-0634" severity="Medium" type="CVE"><desc><descript source="cve">The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html">FEDORA-2004-219</ref><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html">FEDORA-2004-220</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml">GLSA-200407-08</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067">MDKSA-2004:067</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16631">ethereal-smb-sid-dos(16631)</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00015.html">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-378.html">RHSA-2004:378</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/518782">VU#518782</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010655">1010655</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12024">12024</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.2"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.15"/><vers num="0.10.4"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="AS" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0635" published="2004-12-06" seq="2004-0635" severity="Medium" type="CVE"><desc><descript source="cve">The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html">FEDORA-2004-219</ref><ref adv="1" patch="1" source="Fedora" url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html">FEDORA-2004-220</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml">GLSA-200407-08</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067">MDKSA-2004:067</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00015.html">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-528">DSA-528</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-378.html">RHSA-2004:378</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16632">ethereal-snmp-community-dos(16632)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/835846">VU#835846</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010655">1010655</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12024">12024</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers num="9.2"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.15"/><vers num="0.8.16"/><vers num="0.8.17"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="AS" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0636" published="2004-11-23" seq="2004-0636" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10889/">AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=121&amp;type=vulnerabilities">AOL Instant Messenger aim:goaway URI Handler Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/12198/">AOL Instant Messenger &quot;Away&quot; Message Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/735966">VU#735966</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16926">aim-away-bo(16926)</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="5.5"/><vers num="5.5.3415 Beta"/><vers num="5.5.3595"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-0637" published="2004-09-02" seq="2004-0637" severity="Medium" type="CVE"><desc><descript source="cve">Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=136&amp;type=vulnerabilities&amp;flashstatus=true">20040902 Oracle Database Server ctxsys.driload Access Validation Vulnerability</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref adv="1" patch="1" source="BID" url="http://securityfocus.com/bid/11099">11099</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12409/">12409</ref><ref source="BID" url="http://www.securityfocus.com/bid/11099">11099</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Enterprise 8.1.7 .4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.4"/><vers num="Standard 9.0.1.3"/><vers num="Personal 9.2.0.4"/><vers num="Enterprise 9.2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-2004-0638" published="2004-12-31" seq="2004-0638" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=135&amp;type=vulnerabilities&amp;flashstatus=false">20040902 Oracle Database Server dbms_system.ksdwrt Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0178.html">20040905 Buffer Overflow in DBMS_SYSTEM.KSDWRT() in Oracle8i - 9i</ref><ref adv="1" patch="1" source="MISC" url="http://www.red-database-security.com/advisory/advisory_20040903_3.htm">http://www.red-database-security.com/advisory/advisory_20040903_3.htm</ref><ref adv="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11100">11100</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17254">oracle-dbmssystem-bo(17254)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7.4"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0639" published="2004-08-06" seq="2004-0639" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16285">SquirrelMail From header cross-site scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10439">SquirrelMail Email Header HTML Injection Vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-535">DSA-535-1 squirrelmail -- several vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt">http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=257973">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=257973</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858">CLA-2004:858</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10450">10450</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611554415078&amp;w=2">20040530 RS-2004-1: SquirrelMail </ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3 RC1"/><vers num="1.5 dev"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Open Webmail" vendor="Open Webmail"><vers num="2.30"/><vers num="2.31"/><vers num="2.32"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0640" published="2004-08-06" seq="2004-0640" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16653">SSLtelnetd format string</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-529">DSA-529-1 netkit-telnet-ssl -- format string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10684">SSLTelnetd Remote Syslog Format String Vulnerability</ref><ref source="" url="http://www.idefense.com/application/poi/display?id=114&amp;type=vulnerabilities"></ref></refs><vuln_soft><prod name="Linux Netkit" vendor="Netkit"><vers num="0.17"/><vers num="0.17.17"/></prod><prod name="Secure Telnet" vendor="SSLtelnetd"><vers num="0.13.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0641" published="2004-08-05" seq="2004-0641" severity="High" type="CVE"><desc><descript source="cve">Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=120&amp;type=vulnerabilities&amp;flashstatus=true">20040805 Thompson SpeedTouch Home ADSL Modem Predictable TCP ISN Generation</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4299">ESB-2004.0504</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10881">10881</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12238/">12238</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16919">speedtouch-hijack-connection(16919)</ref></refs><vuln_soft><prod name="SpeedTouch" vendor="Thomson"><vers num="510 ADSL Router"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0642" published="2004-09-28" seq="2004-0642" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml">MIT krb5: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17157">Kerberos KDC double-free</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html">TA04-247A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/795632">VU#795632</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860">CLA-2004:860</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-543">DSA-543</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-350.html">RHSA-2004:350</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0045/">2004-0045</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11078">11078</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4936.html">OVAL4936</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4936">oval:org.mitre.oval:def:4936</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0643" published="2004-09-28" seq="2004-0643" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml">MIT krb5: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="trustix" url="http://www.trustix.net/errata/2004/0045/">Trustix Secure Linux Bugfix Advisory #2004-0045</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17159">Kerberos krb5_rd_cred double-free</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html">TA04-247A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/866472">VU#866472</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-543">DSA-543</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-350.html">RHSA-2004:350</ref><ref source="BID" url="http://www.securityfocus.com/bid/11078">11078</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3322.html">OVAL3322</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860">CLA-2004:860</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3322">oval:org.mitre.oval:def:3322</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0644" published="2004-09-28" seq="2004-0644" severity="Medium" type="CVE"><desc><descript source="cve">The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml">MIT krb5: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="trustix" url="http://www.trustix.net/errata/2004/0045/">Trustix Secure Linux Bugfix Advisory #2004-0045</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17160">Kerberos ASN.1 decoder library denial of service</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-003-asn1.txt">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-003-asn1.txt</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html">TA04-247A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/550464">VU#550464</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860">CLA-2004:860</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-543">DSA-543</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-350.html">RHSA-2004:350</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11079">11079</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2139.html">OVAL2139</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2139">oval:org.mitre.oval:def:2139</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3 alpha1"/><vers num="1.3"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0645" published="2004-08-06" seq="2004-0645" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10699/">wvWare Library Field.c WVHANDLEDATETIMEPICTURE Function Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16660">wvWare wvHandleDateTimePicture function buffer overflow</ref><ref adv="1" patch="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=115&amp;type=vulnerabilities">wvWare Library Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-11.xml">wv: Buffer overflow vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-579">DSA-579</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1906">FLSA:1906</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:077">MDKSA-2004:077</ref><ref source="CONFIRM" url="http://www.freebsd.org/ports/portaudit/7a5430df-d562-11d8-b479-02e0185c0b53.html">http://www.freebsd.org/ports/portaudit/7a5430df-d562-11d8-b479-02e0185c0b53.html</ref><ref source="CONFIRM" url="http://cpan.cybercomm.nl/pub/gentoo-portage/app-text/wv/files/wv-1.0.0-fix_overflow.patch">http://cpan.cybercomm.nl/pub/gentoo-portage/app-text/wv/files/wv-1.0.0-fix_overflow.patch</ref><ref source="OSVDB" url="http://www.osvdb.org/7761">7761</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000863">CLA-2004:863</ref></refs><vuln_soft><prod name="Community AbiWord" vendor="AbiSource"><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/></prod><prod name="wvWare" vendor="wvWare"><vers num="0.7.4"/><vers num="0.7.5"/><vers num="0.7.6"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0646" published="2004-12-23" seq="2004-0646" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Macromedia.com" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html">Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11245">bid 11245</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17485">Macromedia ColdFusion MX and JRun verbose mode buffer overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/377194">20040929 iDEFENSE Security Advisory 09.29.04 - Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability</ref><ref source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/990200">VU#990200</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12647/">12647</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="6.0"/><vers num="6.1"/><vers num="J2EE 6.1"/></prod><prod name="JRun" vendor="Macromedia"><vers num="3.0"/><vers num="3.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0647" published="2004-08-06" seq="2004-0647" severity="Medium" type="CVE"><desc><descript source="cve">shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10682">Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16651">Shorewall symlink attack</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-07.xml">Shorewall : Insecure temp file handling</ref><ref source="MLIST" url="http://lists.shorewall.net/pipermail/shorewall-announce/2004-June/000385.html">[Shorewall-announce] 20040628 URGENT: Shorewall Security Vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:080">MDKSA-2004:080</ref></refs><vuln_soft><prod name="Shorewall" vendor="Shorewall"><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.4"/><vers num="1.4.5"/><vers num="1.4.6"/><vers num="1.4.7"/><vers num="1.4.8"/><vers num="1.4.9"/><vers num="1.4.10"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0648" published="2004-08-06" seq="2004-0648" severity="High" type="CVE"><desc><descript source="cve">Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16655">Mozilla shell: command program execution</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938712815719&amp;w=2">Mozilla Security Advisory 2004-07-08</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/927014">Mozilla fails to restrict access to the &quot;shell:&quot; URI handler</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023573.html">20040707 shell:windows command question</ref><ref source="CONFIRM" url="http://www.mozilla.org/security/shell.html">http://www.mozilla.org/security/shell.html</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-175.shtml">O-175</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12027">12027</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.1" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7.2" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0649" published="2004-08-06" seq="2004-0649" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10466">L2TPD Write_Packet Block BSS based Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16326">l2tpd write_packet buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108640917925735&amp;w=2"> bss-based buffer overflow in l2tpd</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-530">DSA-530-1 l2tpd -- buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-17.xml">l2tpd: Buffer overflow</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="l2tpd" vendor="l2tpd"><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0650" published="2004-08-06" seq="2004-0650" severity="High" type="CVE"><desc><descript source="cve">UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10639">New Atlanta ServletExec Unauthorized Access Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16553">Cisco Collaboration Server ServletExec allows elevated privileges</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/718896">Cisco Collaboration Server (CCS) ServletExec allows arbitrary file uploading</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040630-CCS.shtml">20040630 Cisco Collaboration Server Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11979/">11979</ref></refs><vuln_soft><prod name="ServletExec" vendor="NewAtlanta"><vers num="2.2"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0651" published="2004-08-06" seq="2004-0651" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10301">Sun Java Runtime Environment Unspecified Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16085">Sun Java Virtual Machine denial of service</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/118558">Sun Java Runtime Environment vulnerable to DoS</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57555">57555</ref><ref source="HP" url="http://www.securityfocus.com/advisories/6773">SSRT4749</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108559041910233&amp;w=2">HPSBUX01044</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="1.4.2 _03"/><vers num="1.4.2"/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.2_03"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0652" published="2004-08-06" seq="2004-0652" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10133">BEA WebLogic Local Password Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15865">BEA WebLogic Server and Express allows administrator or operator privileges</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/352110">BEA WebLogic Server internal methods may disclose sensitive information</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_55.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_55.00.jsp</ref><ref source="OSVDB" url="http://www.osvdb.org/5296">5296</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009766">1009766</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11359">11359</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0.0.1 SP4"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0.0.1 SP4"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0653" published="2004-08-06" seq="2004-0653" severity="Low" type="CVE"><desc><descript source="cve">Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an &quot;auth&quot; module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user&apos;s passwords by reading log files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16450">Sun Solaris configured as Kerberos logs passwords in plain text</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/523710">Sun Solaris patches may cause passwords to be logged in clear text</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-172.shtml">O-172: Sun Solaris 9 Patches</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10606/info/">Sun Solaris Patches 112908-12 And 115168-03 Clear Text Password Logging Vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57587">57587</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2065.html">OVAL2065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11940/">11940</ref><ref source="BID" url="http://www.securityfocus.com/bid/10606">10606</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101519-1">101519</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2065">oval:org.mitre.oval:def:2065</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:255">oval:org.mitre.oval:def:255</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0654" published="2004-08-06" seq="2004-0654" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</descript></desc><loss_types><avail/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/901582">Sun Solaris vulnerable to DoS when the Basic Security Module (BSM) is configured to perform auditing of specific classes</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10594/solution/">Sun Solaris Basic Security Module Auditing Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16483"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57497">57497</ref><ref source="BID" url="http://www.securityfocus.com/bid/10594">10594</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2426.html">OVAL2426</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11930/">11930</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2426">oval:org.mitre.oval:def:2426</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0655" published="2004-08-06" seq="2004-0655" severity="High" type="CVE"><desc><descript source="cve">eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10644">Esearch eupdatedb Symbolic Link Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16584">esearch eupdatedb symlink attack</ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-01.xml">Esearch: Insecure temp file handling</ref></refs><vuln_soft><prod name="emerge search tool" vendor="esearch"><vers num="0.3.1"/><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.5.2"/><vers num="0.5.3"/><vers num="0.6"/><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0656" published="2004-08-06" seq="2004-0656" severity="Medium" type="CVE"><desc><descript source="cve">The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10664">PureFTPd Accept_Client Remote Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16611">Pure-FTPd accept_client denial of service</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-04.xml">Pure-FTPd: Potential DoS when maximum connections is reached</ref><ref source="CONFIRM" url="http://www.pureftpd.org/">http://www.pureftpd.org/</ref></refs><vuln_soft><prod name="PureFTPd" vendor="PureFTPd"><vers num="0.96"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.11"/><vers num="1.0.12"/><vers num="1.0.13a"/><vers num="1.0.14"/><vers num="1.0.15"/><vers num="1.0.16c"/><vers num="1.0.16b"/><vers num="1.0.16a"/><vers num="1.0.16"/><vers num="1.0.17a"/><vers num="1.0.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0657" published="2004-08-06" seq="2004-0657" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server&apos;s time.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15406">NTP integer buffer overflow</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/584606">NTP service vulnerable to internal overflow if date / time offset is greater than 34 years</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922292425219&amp;w=2">SSRT4718</ref></refs><vuln_soft><prod name="NTP" vendor="NTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0658" published="2004-08-06" seq="2004-0658" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the hpsb_alloc_packet function (incorrectly reported as alloc_hpsb_packet) in IEEE 1394 (Firewire) driver 2.4 and 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via the functions (1) raw1394_write, (2) state_connected, (3) handle_remote_request, or (4) hpsb_make_writebpacket.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10593">Linux Kernel IEEE 1394 Integer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16480">Linux kernel IEEE 1394 driver integer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108793792820740">linux kernel IEEE1394(Firewire) driver integer overflow</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.5 .0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="2.5.5"/><vers num="2.5.6"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0659" published="2004-08-06" seq="2004-0659" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10615">MPlayer GUI File Name Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16532">MPlayer common.c buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844316930791&amp;w=2">MPlayer MeMPlayer.c</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-01.xml">GLSA-200408-01</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="HEAD CVS"/><vers num="0.92 cvs"/><vers num="0.90 rc4"/><vers num="0.90 rc"/><vers num="0.90 pre"/><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.92.1"/><vers num="1.0 pre4"/><vers num="1.0 pre3try2"/><vers num="1.0 pre3"/><vers num="1.0 pre2"/><vers num="1.0 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-0660" published="2004-08-06" seq="2004-0660" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10620/solution/">CuteNews Multiple Cross-site Scripting Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16525">CuteNews id variable cross-site scripting</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844000409449&amp;w=2">20040628 Cross-Site Scripting CuteNews</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="0.88"/><vers num="1.3"/><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0661" published="2004-08-06" seq="2004-0661" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10621">D-Link AirPlus DI-614+, DI-624, and DI-604 DHCP Server Flooding Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16531">D-Link DHCP REQUEST packet denial of service</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/367485">20040629 Re: DLINK 614+ - SOHO routers, system DOS</ref><ref source="OSVDB" url="http://www.osvdb.org/7294">7294</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12018">12018</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844250013785&amp;w=2">20040628 DLINK 614+ - SOHO routers, DHCP service DOS</ref></refs><vuln_soft><prod name="DI-604" vendor="D-Link"><vers num=""/></prod><prod name="DI-624" vendor="D-Link"><vers num="1.28"/></prod><prod name="DI-614+" vendor="D-Link"><vers num="2.30"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0662" published="2004-08-06" seq="2004-0662" severity="Medium" type="CVE"><desc><descript source="cve">PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10622">PowerPortal Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16529">PowerPortal path disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2">Multiple vulnerabilities PowerPortal</ref><ref source="MISC" url="http://www.swp-zone.org/archivos/advisory-07.txt">http://www.swp-zone.org/archivos/advisory-07.txt</ref></refs><vuln_soft><prod name="PowerPortal" vendor="PowerPortal"><vers num="1.1b"/><vers num="1.3b"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-0663" published="2004-08-06" seq="2004-0663" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16528">PowerPortal multiple cross-site scripting</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2">Multiple vulnerabilities PowerPortal</ref></refs><vuln_soft><prod name="PowerPortal" vendor="PowerPortal"><vers num="1.1b"/><vers num="1.3b"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0664" published="2004-08-06" seq="2004-0664" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10622">PowerPortal Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16530">PowerPortal &quot;dot dot&quot; directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2">Multiple vulnerabilities PowerPortal</ref><ref source="MISC" url="http://www.swp-zone.org/archivos/advisory-07.txt">http://www.swp-zone.org/archivos/advisory-07.txt</ref></refs><vuln_soft><prod name="PowerPortal" vendor="PowerPortal"><vers num="1.1b"/><vers num="1.3b"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0665" published="2004-08-06" seq="2004-0665" severity="Medium" type="CVE"><desc><descript source="cve">csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10618">CGIScript.net CSFAQ Script Path Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16526">csFAQ path disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844203121238&amp;w=2">Full path disclosure csFAQ</ref><ref source="MISC" url="http://www.swp-zone.org/archivos/advisory-08.txt">http://www.swp-zone.org/archivos/advisory-08.txt</ref></refs><vuln_soft><prod name="csFAQ" vendor="CGISCRIPT.NET"><vers num=""/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0666" published="2004-08-06" seq="2004-0666" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the POP3_readmsg function in popclient 3.0b6 allows remote attackers to cause a denial of service (application crash) via an e-mail message with a certain line length, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10625">Popclient Email Message Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16538">popclient POP3_readmsg off-by-one buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108852915403293&amp;w=2">DoS in popclient 3.0b6</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023147.html">20040629 DoS in popclient 3.0b6</ref><ref source="MISC" url="http://www.grok.org.uk/advisories/popclient.html">http://www.grok.org.uk/advisories/popclient.html</ref></refs><vuln_soft><prod name="popclient" vendor="popclient"><vers num="3.0 b6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0667" published="2004-08-06" seq="2004-0667" severity="High" type="CVE"><desc><descript source="cve">Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10640">RSBAC Jail SUID And SGID File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16552">RSBAC JAIL module CREATE check gain privileges</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108879977120430&amp;w=2"> Announce: RSBAC v1.2.3 released</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108861182906067&amp;w=2">rsbac 1.2.3 jail security problems</ref><ref source="CONFIRM" url="http://www.rsbac.org/download/bugfixes/">http://www.rsbac.org/download/bugfixes/</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16552">rsbac-jail-gain-privileges(16552)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="RSBAC" vendor="RSBAC"><vers num="1.2.2"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0668" published="2004-08-06" seq="2004-0668" severity="Medium" type="CVE"><desc><descript source="cve">Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10641">IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16596">Lotus Domino Web Access denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108871093704307&amp;w=2">DoS against Domino 6.5.1</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0669" published="2004-08-06" seq="2004-0669" severity="High" type="CVE"><desc><descript source="cve">Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10642">IBM Lotus Domino IMAP Quota Changing Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16575">Lotus Domino allows change of quota</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108869022708571&amp;w=2">Unprevileged user can change quota on Domino</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.0"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0670" published="2004-08-06" seq="2004-0670" severity="Medium" type="CVE"><desc><descript source="cve">Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10638">ZyXEL Prestige Router Authentication Password Field Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16547">ZyXEL Prestige 650HW-31 long password denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108862133005952&amp;w=2">DSL router Prestige 650HW-31</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023196.html">20040630 DSL router Prestige 650HW-31</ref></refs><vuln_soft><prod name="Prestige" vendor="ZyXEL"><vers num="650HW_31"/><vers num="650R_11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0671" published="2004-08-06" seq="2004-0671" severity="Medium" type="CVE"><desc><descript source="cve">Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10657">Symantec Brightmail Anti-Spam 6.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16609">Symantec Brightmail Anti-Spam view mail</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108880205115802&amp;w=2">20040701 Brightmail leaks other user&apos;s spam</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981452101353&amp;w=2">20040714 Ref: http://www.securityfocus.com/archive/1/367866, Jul 1 2004 1:19PM, Subj:  Brightmail</ref></refs><vuln_soft><prod name="Brightmail AntiSpam" vendor="Symantec"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-0672" published="2004-08-06" seq="2004-0672" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10645">Netegrity IdentityMinder Multiple Cross-Site Scripting Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16618">Netegrity IdentityMinder cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108881203114336&amp;w=2">XSS in Netegrity IdentityMinder</ref></refs><vuln_soft><prod name="Policy Server" vendor="Netegrity"><vers num="5.5"/></prod><prod name="IdentityMinder" vendor="Netegrity"><vers num="Web 5.6 SP2"/><vers num="Web 5.6 SP1"/><vers num="Web 5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0673" published="2004-08-06" seq="2004-0673" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10648">SCI Photo Chat Server Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16602">SCI Photo Chat Server cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108880460730833&amp;w=2"> XSS in SCI Photo Chat Server 3.4.9</ref></refs><vuln_soft><prod name="SCI Photo Chat" vendor="SIMM-Comm"><vers num="3.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0674" published="2004-08-06" seq="2004-0674" severity="Medium" type="CVE"><desc><descript source="cve">Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10653">Enterasys XSR Security Router Record Route Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16616">Enterasys Networks XSR Security Router</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108886995627906&amp;w=2">Enterasys XSR Security Routers DoS</ref><ref source="CONFIRM" url="http://www.enterasys.com/support/security/incidents/2004/07/11036.html">http://www.enterasys.com/support/security/incidents/2004/07/11036.html</ref></refs><vuln_soft><prod name="XSR-1805" vendor="Enterasys"><vers num="7.0.0.0"/></prod><prod name="XSR-1850" vendor="Enterasys"><vers num="7.0.0.0"/></prod><prod name="XSR-3000" vendor="Enterasys"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0675" published="2004-08-06" seq="2004-0675" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10617">McMurtrey/Whitaker &amp; Associates Cart32 GetLatestBuilds Script Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16535">Cart32 GetLatestBuilds script cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108887778628398&amp;w=2">Cart32 Input Validation Flaw in &apos;GetLatestBuilds?cart32=&apos; Permits</ref></refs><vuln_soft><prod name="Cart32" vendor="McMurtrey Whitaker and Associates"><vers num="2.5a"/><vers num="2.6"/><vers num="3.0"/><vers num="3.1"/><vers num="3.5a Build710"/><vers num="3.5a"/><vers num="3.5 Build619"/><vers num="3.5"/><vers num="4.4"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0676" published="2004-08-06" seq="2004-0676" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10658">Fastream NetFile FTP/Web Server Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16613">Fastream NETFile Server mkdir file upload</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904874104880&amp;w=2">Fastream NETFile FTP/Web Server Input validation Errors</ref><ref source="MISC" url="http://www.haxorcitos.com/Fastream_advisory.txt">http://www.haxorcitos.com/Fastream_advisory.txt</ref></refs><vuln_soft><prod name="NetFILE FTP_Web Server" vendor="Fastream"><vers num="6.5.1.981"/><vers num="6.5.1.980"/><vers num="6.7.2.1085"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0677" published="2004-08-06" seq="2004-0677" severity="Medium" type="CVE"><desc><descript source="cve">Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive (&quot;A&quot;).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16615">Fastream NETFile Server CD command denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904874104880&amp;w=2">20040704 Fastream NETFile FTP/Web Server Input validation Errors</ref></refs><vuln_soft><prod name="NetFILE FTP_Web Server" vendor="Fastream"><vers num="6.7.2.1085" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0678" published="2004-08-06" seq="2004-0678" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbirary script as other users via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10659">12Planet Chat Server Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16605">12Planet Chat Server cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904648728706&amp;w=2">XSS in 12Planet Chat Server 2.9</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/12PlanetChatServer2.9-adv.txt">http://www.autistici.org/fdonato/advisory/12PlanetChatServer2.9-adv.txt</ref></refs><vuln_soft><prod name="Chat Server" vendor="12Planet"><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0679" published="2004-08-06" seq="2004-0679" severity="Medium" type="CVE"><desc><descript source="cve">The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user&apos;s IP addresses.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10663">Unreal IRCD Cloak.C IP Address Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16610">Unreal IRCd information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904813003166&amp;w=2">unreal ircd ip cloaking subsystem vulnerability</ref><ref source="CONFIRM" url="http://www.unrealircd.com/">http://www.unrealircd.com/</ref><ref source="MISC" url="http://www.bandecon.com/advisory/unreal.txt">http://www.bandecon.com/advisory/unreal.txt</ref><ref source="SREASON" url="http://securityreason.com/securityalert/560">560</ref></refs><vuln_soft><prod name="UnrealIRCd" vendor="Unreal"><vers num="3.1.1"/><vers num="3.1.3"/><vers num="3.2 .0 beta 10"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0680" published="2004-08-06" seq="2004-0680" severity="High" type="CVE"><desc><descript source="cve">Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10669">Zoom Model 5560 X3 ETHERNET ADSL Modem Default Backdoor Account Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16639">Conexant chipsets may allow attacker to restore factory default settings</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108915255520924&amp;w=2">backdoor menu on conexant chipset dsl router (Zoom X3)</ref></refs><vuln_soft><prod name="Model 5560 X3 ETHERNET ADSL Modem" vendor="Zoom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0681" published="2004-08-06" seq="2004-0681" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update:
Comersus Open Technologies, Comersus Cart, 5.098</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10674">Comersus Open Technologies Comersus Cart Multiple Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16646">Comersus Cart cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922169327403&amp;w=2">Comersus Cart Cross-Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num="5.09"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0682" published="2004-08-06" seq="2004-0682" severity="High" type="CVE"><desc><descript source="cve">comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10674">Comersus Open Technologies Comersus Cart Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16645">Comersus Cart could allow price modification</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922336529987&amp;w=2">Comersus Cart Improper Request Handling</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num="5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0683" published="2004-08-06" seq="2004-0683" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10686/">Symantec Norton Antivirus Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16658">Norton AntiVirus compressed archive file denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938579712894&amp;w=2">20040709 Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]</ref></refs><vuln_soft><prod name="Norton AntiVirus Pro" vendor="Symantec"><vers num="2003"/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0684" published="2004-08-06" seq="2004-0684" severity="Medium" type="CVE"><desc><descript source="cve">WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10651/">IBM Websphere Edge Server Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16607">IBM Edge Server Caching Proxy component denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938997528245&amp;w=2">  CYBSEC - Security Advisory: Denial of Service in IBM WebSphere</ref><ref source="MISC" url="http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf">http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf</ref></refs><vuln_soft><prod name="WebSphere Caching Proxy Server" vendor="IBM"><vers num="5.0.2"/></prod><prod name="Websphere Edge server Caching proxy" vendor="IBM"><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2004-0685" published="2004-12-23" seq="2004-0685" severity="Medium" type="CVE"><desc><descript source="cve">Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/981134">Linux kernel USB drivers do not initialize kernel memory properly</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10892">bid 10892</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16931">Linux kernel USB allows elevated privileges</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml">Linux Kernel: Multiple information leaks</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0041/">2004-0041</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921</ref><ref source="MISC" url="http://www.securityspace.com/smysecure/catid.html?id=14580">http://www.securityspace.com/smysecure/catid.html?id=14580</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.2.25"/><vers num="2.3"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="2.5.5"/><vers num="2.5.6"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0686" published="2004-07-27" seq="2004-0686" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the &quot;mangling method = hash&quot; option is enabled in smb.conf, has unknown impact and attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10781/">BID:10781</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051340810458&amp;w=2">20040722 Security Release - Samba 3.0.5 and 2.2.10</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-259.html">RHSA-2004:259</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16786">Samba mangling method buffer overflow</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-21.xml">GLSA-200407-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071">MDKSA-2004:071</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_22_samba.html">SUSE-SA:2004:022</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0039/">2004-0039</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000851">CLA-2004:851</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000854">CLA-2004:854</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109785827607823&amp;w=2">FLSA:2102</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109094272328981&amp;w=2">SSRT4782</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051533021376&amp;w=2">20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052891507263&amp;w=2">20040722 TSSA-2004-014 - samba</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1">101584</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1">57664</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0687" published="2004-10-20" seq="2004-0687" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109530851323415&amp;w=2">libXpm</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:098">Updated libxpm4 packages fix libXpm overflow vulnerabilities</ref><ref adv="1" patch="1" source="Suse.com" url="http://www.suse.com/de/security/2004_34_xfree86_libs_xshared.html">XFree86-libs, xshared</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11196">bid 11196</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17414">libXpm xpmParseColors, ParseAndPutPixels, and ParsePixels functions stack-based buffer overflows</ref><ref source="MISC" url="http://scary.beasts.org/security/CESA-2004-003.txt">http://scary.beasts.org/security/CESA-2004-003.txt</ref><ref source="CONFIRM" url="http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch">http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-560">DSA-560</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-34.xml">GLSA-200409-34</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml">GLSA-200502-07</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">RHSA-2004:537</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-004.html">RHSA-2005:004</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html">SUSE-SA:2004:034</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/882750">VU#882750</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-27-1">USN-27-1</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html">FLSA-2006:152803</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000924">CLA-2005:924</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57653-1">57653</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded">HPSBUX02119</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1914">ADV-2006-1914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20235">20235</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:098">MDKSA-2004:098</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.7.0"/><vers num="6.8"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4"/><vers num="3.5"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="3.3.6"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2.11"/><vers num="4.0.3"/><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0688" published="2004-10-20" seq="2004-0688" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109530851323415&amp;w=2">libXpm</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:098">Updated libxpm4 packages fix libXpm overflow vulnerabilities</ref><ref adv="1" patch="1" source="Suse.com" url="http://www.suse.com/de/security/2004_34_xfree86_libs_xshared.html">XFree86-libs, xshared</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11196">bid 11196</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17416">libXpm XPM file integer overflow</ref><ref source="MISC" url="http://scary.beasts.org/security/CESA-2004-003.txt">http://scary.beasts.org/security/CESA-2004-003.txt</ref><ref source="CONFIRM" url="http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch">http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-560">DSA-560</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-34.xml">GLSA-200409-34</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml">GLSA-200502-07</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">RHSA-2004:537</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-004.html">RHSA-2005:004</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html">SUSE-SA:2004:034</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/537878">VU#537878</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-27-1">USN-27-1</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html">FLSA-2006:152803</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000924">CLA-2005:924</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57653-1">57653</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded">HPSBUX02119</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1914">ADV-2006-1914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20235">20235</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:098">MDKSA-2004:098</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.7.0"/><vers num="6.8"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4"/><vers num="3.5"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="3.3.6"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2.11"/><vers num="4.0.3"/><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0689" published="2004-09-28" seq="2004-0689" severity="Medium" type="CVE"><desc><descript source="cve">KDE before 3.3.0 does not properly handle when certain symbolic links point to &quot;stale&quot; locations, which could allow local users to create or truncate arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="kde" url="http://www.kde.org/info/security/advisory-20040811-1.txt">Temporary Directory Vulnerability</ref><ref adv="1" patch="1" source="debian" url="http://www.debian.org/security/2004/dsa-539">DSA-539-1 kdelibs -- temporary directory vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16963">KDE application symlink</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-13.xml">200408-13</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12276/">12276</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864">CLA-2004:864</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0690" published="2004-09-28" seq="2004-0690" severity="Medium" type="CVE"><desc><descript source="cve">The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="kde" url="http://www.kde.org/info/security/advisory-20040811-2.txt">DCOPServer Temporary Filename Vulnerability</ref><ref adv="1" patch="1" source="debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261386">Debian Bug report logs - #261386</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16962">KDE DCOPserver symlink attack</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-13.xml">200408-13</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:086">MDKSA-2004:086</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/330638">VU#330638</ref><ref source="BID" url="http://www.securityfocus.com/bid/10924">10924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12276">12276</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864">CLA-2004:864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:086">MDKSA-2004:086</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0691" published="2004-09-28" seq="2004-0691" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17040">Qt BMP image buffer overflow</ref><ref adv="1" patch="1" source="redhat" url="http://www.redhat.com/support/errata/RHSA-2004-414.html">Updated qt packages fix security issues</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109295309008309&amp;w=2">20040818 CESA-2004-004: qt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-20.xml">GLSA-200408-20</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref></refs><vuln_soft><prod name="Qt" vendor="Trolltech"><vers num="3.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0692" published="2004-09-28" seq="2004-0692" severity="Medium" type="CVE"><desc><descript source="cve">The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="mandrakesoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref><ref adv="1" patch="1" source="gentoo" url="http://security.gentoo.org/glsa/glsa-200408-20.xml">Qt: Image loader overflows</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17041">Qt XPM file denial of service</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-414.html">RHSA-2004:414</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref></refs><vuln_soft><prod name="Qt" vendor="Trolltech"><vers num="3.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0693" published="2004-09-28" seq="2004-0693" severity="Medium" type="CVE"><desc><descript source="cve">The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17042">Qt GIF file denial of service</ref><ref adv="1" patch="1" source="gentoo" url="http://security.gentoo.org/glsa/glsa-200408-20.xml">Qt: Image loader overflows</ref><ref adv="1" patch="1" source="mandraksoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-414.html">RHSA-2004:414</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref></refs><vuln_soft><prod name="Qt" vendor="Trolltech"><vers num="3.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0695" published="2004-07-27" seq="2004-0695" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16686">4D WebSTAR Server V long FTP command buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10720/">BID:10720</ref><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a071304-1.txt">A071304-1</ref><ref source="4D, Inc." url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref></refs><vuln_soft><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/><vers num="5.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0696" published="2004-07-27" seq="2004-0696" severity="Medium" type="CVE"><desc><descript source="cve">The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a &quot;*&quot; (asterisk) character.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10721/">BID:10721</ref><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a071304-1.txt">A071304-1</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16687">4dwebstar-view-directory-listing(16687)</ref><ref source="4D, Inc." url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/10721">
10721</ref></refs><vuln_soft><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/><vers num="5.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0697" published="2004-07-27" seq="2004-0697" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a071304-1.txt">A071304-1</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16688">4dwebstar-view-phpini-files(16688)</ref><ref source="4D, Inc." url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref></refs><vuln_soft><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/><vers num="5.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0698" published="2004-07-27" seq="2004-0698" severity="Low" type="CVE"><desc><descript source="cve">4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a071304-1.txt">A071304-1</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16689">4dwebstar-symlink(16689)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10714/">BID:10714</ref><ref source="4D, Inc." url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref></refs><vuln_soft><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/><vers num="5.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0699" published="2004-09-28" seq="2004-0699" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/178">Check Point VPN-1 ASN.1 Decoding Remote Compromise</ref><ref adv="1" patch="1" source="checkpoint" url="http://www.checkpoint.com/techsupport/alerts/asn1.html">ASN.1 Alert</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16824">Check Point VPN-1/FireWall-1 ASN1 decoding buffer overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435358">VU#435358</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-190.shtml">O-190</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12177/">12177</ref><ref source="BID" url="http://www.securityfocus.com/bid/10820">10820</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=8290">8290</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Jul/1010799.html">1010799</ref></refs><vuln_soft><prod name="Check Point VPN-1" vendor="Checkpoint"><vers num=""/></prod><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0700" published="2004-07-27" seq="2004-0700" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10736/">BID:10736</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=apache-modssl&amp;m=109001100906749&amp;w=2">20040716 [OpenPKG-SA-2004.032] OpenPKG Security Advisory (apache)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16705">apache-modssl-format-string(16705)</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/303448">mod_ssl contains a format string vulnerability in the ssl_log() function</ref><ref source="MISC" url="http://packetstormsecurity.org/0407-advisories/modsslFormat.txt">http://packetstormsecurity.org/0407-advisories/modsslFormat.txt</ref><ref source="MISC" url="http://virulent.siyahsapka.org/">http://virulent.siyahsapka.org/</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-532">DSA-532</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1888">FLSA:1888</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:075">MDKSA-2004:075</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">RHSA-2004:405</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-408.html">RHSA-2004:408</ref><ref source="BID" url="http://www.securityfocus.com/bid/10736">10736</ref><ref source="OSVDB" url="http://www.osvdb.org/7929">7929</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-177-1">USN-177-1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109005001205991&amp;w=2">20040716 [OpenPKG-SA-2004.032] OpenPKG Security Advisory (apache)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000857">CLA-2004:857</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="mod_ssl" vendor="mod_ssl"><vers num="2.3.11"/><vers num="2.4.10"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.7.0"/><vers num="2.7.1"/><vers num="2.8.0"/><vers num="2.8.1.2"/><vers num="2.8.1"/><vers num="2.8.2"/><vers num="2.8.3"/><vers num="2.8.4"/><vers num="2.8.5.2"/><vers num="2.8.5.1"/><vers num="2.8.5"/><vers num="2.8.6"/><vers num="2.8.7"/><vers num="2.8.8"/><vers num="2.8.9"/><vers num="2.8.10"/><vers num="2.8.12"/><vers num="2.8.14"/><vers num="2.8.15"/><vers num="2.8.16"/><vers num="2.8.17"/><vers num="2.8.18"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-0701" published="2004-07-27" seq="2004-0701" severity="Medium" type="CVE"><desc><descript source="cve">Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7457">BID:7457</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/11905">sun-ray-session-access(11905)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F53922">53922</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/100780">VU#100780</ref></refs><vuln_soft><prod name="Sun Ray Server Software" vendor="Sun"><vers num="1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0702" published="2004-07-27" seq="2004-0702" severity="Medium" type="CVE"><desc><descript source="cve">DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16673">bugzilla-database-password-disclosure(16673)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0703" published="2004-07-27" seq="2004-0703" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with &quot;grant membership&quot; privileges to grant memberships to groups that the user does not control.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16672">bugzilla-editusers-gain-privileges(16672)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0704" published="2004-07-27" seq="2004-0704" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16671">bugzilla-product-name-disclosure(16671)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0705" published="2004-07-27" seq="2004-0705" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16670">bugzilla-edit-xss(16670)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=235265">http://bugzilla.mozilla.org/show_bug.cgi?id=235265</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0706" published="2004-07-27" seq="2004-0706" severity="Low" type="CVE"><desc><descript source="cve">Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16669">bugzilla-chart-view-password(16669)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=235510">http://bugzilla.mozilla.org/show_bug.cgi?id=235510</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0707" published="2004-07-27" seq="2004-0707" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10698">BID:10698</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16668">bugzilla-editusers-sql-injection(16668)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=244272">http://bugzilla.mozilla.org/show_bug.cgi?id=244272</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.4"/><vers num="2.6"/><vers num="2.8"/><vers num="2.10"/><vers num="2.12"/><vers num="2.14"/><vers num="2.14.1"/><vers num="2.14.2"/><vers num="2.14.3"/><vers num="2.14.4"/><vers num="2.14.5"/><vers num="2.16"/><vers num="2.16.1"/><vers num="2.16.2"/><vers num="2.16.3"/><vers num="2.16.4"/><vers num="2.16.5"/><vers num="2.17"/><vers num="2.17.1"/><vers num="2.17.3"/><vers num="2.17.4"/><vers num="2.17.5"/><vers num="2.17.6"/><vers num="2.17.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0708" published="2004-07-27" seq="2004-0708" severity="High" type="CVE"><desc><descript source="cve">MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10568">BID:10568</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16465">moinmoin-gain-admin-access(16465)</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml">GLSA-200407-09</ref><ref source="MISC" url="http://www.osvdb.org/6704">http://www.osvdb.org/6704</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11807">11807</ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=948103&amp;group_id=8482&amp;atid=108482"></ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0709" published="2004-07-27" seq="2004-0709" severity="High" type="CVE"><desc><descript source="cve">HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10414">BID:10414</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/205766">VU#205766</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16247">openview-select-gain-access(16247)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/6774">SSRT4719</ref></refs><vuln_soft><prod name="OpenView Select Access" vendor="HP"><vers num="5.0 Patch 4"/><vers num="5.1 Patch 1"/><vers num="5.2"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0710" published="2004-07-27" seq="2004-0710" severity="Medium" type="CVE"><desc><descript source="cve">IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10083">BID:10083</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/904310">VU#904310</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040408-vpnsm.shtml">20040408 Cisco IPSec VPN Services Module Malformed IKE Packet Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15797">cisco-vpnsm-ike-dos(15797)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 SXB"/><vers num="12.2 SXA"/><vers num="12.2 (17a)SXA"/><vers num="12.2 (14)ZA2"/><vers num="12.2 (14)ZA"/><vers num="12.2 (14)SY"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0711" published="2004-07-27" seq="2004-0711" severity="High" type="CVE"><desc><descript source="cve">The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in &quot;*&quot; as wildcards as if they were the legal &quot;/*&quot; pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10184">BID:10184</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/184558">VU#184558</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15927">weblogic-urlpattern-obtain-information(15927)</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0712" published="2004-07-27" seq="2004-0712" severity="Medium" type="CVE"><desc><descript source="cve">The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10188">BID:10188</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15926">weblogic-admin-password-plaintext(15926)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/574222">VU#574222</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_58.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_58.00.jsp</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0713" published="2004-07-27" seq="2004-0713" severity="Medium" type="CVE"><desc><descript source="cve">The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10185">BID:10185</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15928">weblogic-ejb-object-deletion(15928)</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/658878">VU#658878</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0714" published="2004-07-27" seq="2004-0714" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corruption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10186">BID:10186</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-111B.html">TA04-111B</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/162451">VU#162451</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-snmp.shtml">20040420 Vulnerabilities in SNMP Message Processing</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15921">cisco-ios-snmp-udp-dos(15921)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1(20)EO"/><vers num="12.0 SV"/><vers num="12.0 S"/><vers num="12.0 (27)SV1"/><vers num="12.0 (27)SV"/><vers num="12.0 (27)S"/><vers num="12.0 (26)S1"/><vers num="12.0 (24)S5"/><vers num="12.0 (24)S4"/><vers num="12.0 (23)S5"/><vers num="12.0 (23)S4"/><vers num="12.1 EW"/><vers num="12.1 EU"/><vers num="12.1 EO"/><vers num="12.1 EC"/><vers num="12.1 EB"/><vers num="12.1 EA"/><vers num="12.1 E"/><vers num="12.1 (20)EW1"/><vers num="12.1 (20)EW"/><vers num="12.1 (20)EC1"/><vers num="12.1 (20)EC"/><vers num="12.1 (20)EA1"/><vers num="12.1 (20)E2"/><vers num="12.1 (20)E1"/><vers num="12.1 (20)E"/><vers num="12.2 ZQ"/><vers num="12.2 SW"/><vers num="12.2 S"/><vers num="12.2 (23)"/><vers num="12.2 (21a)"/><vers num="12.2 (21)"/><vers num="12.2 (20)S1"/><vers num="12.2 (20)S"/><vers num="12.2 (12h)"/><vers num="12.2 (12g)"/><vers num="12.2"/><vers num="12.3 XQ"/><vers num="12.3 XK"/><vers num="12.3 XH"/><vers num="12.3 XG"/><vers num="12.3 XF"/><vers num="12.3 XE"/><vers num="12.3 XD"/><vers num="12.3 XC"/><vers num="12.3 T"/><vers num="12.3 B"/><vers num="12.3 (6)"/><vers num="12.3 (5b)"/><vers num="12.3 (5a)b"/><vers num="12.3 (5a)"/><vers num="12.3 (5)"/><vers num="12.3 (4)XD1"/><vers num="12.3 (4)XD"/><vers num="12.3 (4)T3"/><vers num="12.3 (4)T2"/><vers num="12.3 (4)T1"/><vers num="12.3 (4)T"/><vers num="12.3 (2)XC2"/><vers num="12.3 (2)XC1"/><vers num="12.3 (2)T3"/><vers num="12.3"/></prod><prod name="ONS 15454E Optical Transport Platform" vendor="Cisco"><vers num=""/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="3.0"/><vers num="3.1 .0"/><vers num="3.2 .0"/><vers num="3.3"/><vers num="3.4"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0715" published="2004-07-27" seq="2004-0715" severity="Medium" type="CVE"><desc><descript source="cve">The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10130">BID:10130</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15861">weblogic-authentication-gain-privileges(15861)</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/470470">VU#470470</ref><ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_52.01.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_52.01.jsp</ref><ref source="OSVDB" url="http://www.osvdb.org/5299">5299</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009763">1009763</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11356">11356</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0716" published="2004-08-06" seq="2004-0716" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Entegrity" url="http://support.entegrity.com/private/patches/dce/ssrt4741.asp">Entegrity DCE Security Patch (24-May-2004)</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a072204-1.txt">A072204-1</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a072204-1.txt">A072204-1</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a072204-1.txt">A072204-1</ref><ref source="ATSTAKE" url="http://http://www.atstake.com/research/advisories/2004/a072204-1.txt">A072204-1</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0717" published="2004-07-27" seq="2004-0717" severity="High" type="CVE"><desc><descript source="cve">Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10763/">BID:10763</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">Multiple Browsers Frame Injection Vulnerability Test</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/11978">Multiple Browsers Frame Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/1598">Web browser frame spoof</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.50"/><vers num="7.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0718" published="2004-07-27" seq="2004-0718" severity="High" type="CVE"><desc><descript source="cve">The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/1598">Web browser frame spoof</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/11978">Multiple Browsers Frame Injection Vulnerability Test</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">Multiple Browsers Frame Injection Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4756.html">OVAL4756</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=246448">http://bugzilla.mozilla.org/show_bug.cgi?id=246448</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:082">MDKSA-2004:082</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-777">DSA-777</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4756">oval:org.mitre.oval:def:4756</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:082">MDKSA-2004:082</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num="7.1"/></prod><prod name="Firebird" vendor="Firebird"><vers num="0.7"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0719" published="2004-07-27" seq="2004-0719" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10627">BID:10627</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/11978">11978</ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/11966">11966</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">Multiple Browsers Frame Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/1598">Web browser frame spoof</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0720" published="2004-07-27" seq="2004-0720" severity="High" type="CVE"><desc><descript source="cve">Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/1598">Web browser frame spoof</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/11978">Multiple Browsers Frame Injection Vulnerability Test</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">Multiple Browsers Frame Injection Vulnerability Test</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0721" published="2004-07-27" seq="2004-0721" severity="High" type="CVE"><desc><descript source="cve">Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Secunia" url="http://secunia.com/advisories/11978">Multiple Browsers Frame Injection Vulnerability</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">Multiple Browsers Frame Injection Vulnerability Test</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/1598">Web browser frame spoof</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20040811-3.txt">http://www.kde.org/info/security/advisory-20040811-3.txt</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-13.xml">200408-13</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864">CLA-2004:864</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.1.3"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0722" published="2004-08-18" seq="2004-0722" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=236618">http://bugzilla.mozilla.org/show_bug.cgi?id=236618</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4629.html">OVAL4629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16862">mozilla-netscape-soapparameter-bo(16862)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="" url="http://www.idefense.com/application/poi/display?id=117&amp;type=vulnerabilities"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4629">oval:org.mitre.oval:def:4629</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.6"/></prod><prod name="Netscape" vendor="Netscape"><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0723" published="2004-07-27" seq="2004-0723" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the &quot;GET/Key&quot; and &quot;PUT/Key/Value&quot; commands, aka &quot;cross-site Java.&quot;</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108948405808522&amp;w=2">20040710 Covert Channels allow Cross-Site-Java in Microsoft VM</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10688">Microsoft JVM Cross-Domain Applet Unauthorized Communication Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16666">msjvm-sandbox-bypass(16666)</ref></refs><vuln_soft><prod name="JVM" vendor="Microsoft"><vers num="5.0.0.3810"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0724" published="2004-07-27" seq="2004-0724" severity="Medium" type="CVE"><desc><descript source="cve">The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/10700">BID:10700</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108966465302107&amp;w=2">20040712 Remote crash of Half-Life servers and clients (versions before the 07 July 2004)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16674">Half-Life packet denial of service</ref></refs><vuln_soft><prod name="Half-Life" vendor="Valve Software"><vers num="1.1.0.9"/><vers num="1.1.0.8"/><vers edition="Windows" num="1.1.0.4"/><vers edition="Linux" num="1.1.0.4"/><vers num="1.1.1.0"/></prod><prod name="Half-Life Dedicated Server" vendor="Valve Software"><vers edition="Linux" num="3.1.0.9"/><vers edition="Linux" num="3.1.0.8"/><vers edition="Linux" num="3.1.0.7"/><vers edition="Linux" num="3.1.0.6"/><vers edition="Linux" num="3.1.0.5"/><vers edition="Linux" num="3.1.0.4"/><vers num="3.1"/><vers edition="Win32" num="3.1.1.1e"/><vers edition="Linux" num="3.1.1.1e"/><vers edition="Linux" num="3.1.1.1d"/><vers edition="Linux" num="3.1.1.1c1"/><vers edition="Linux" num="3.1.1.0"/><vers num="3.1.3"/><vers edition="Win32" num="4.1.0.9"/><vers edition="Win32" num="4.1.0.8"/><vers edition="Win32" num="4.1.0.7"/><vers edition="Win32" num="4.1.0.6"/><vers edition="Win32" num="4.1.0.4"/><vers edition="Win32" num="4.1.1.1e"/><vers edition="Linux" num="4.1.1.1e"/><vers edition="Win32" num="4.1.1.1d Beta"/><vers edition="Win32" num="4.1.1.1c1"/><vers edition="Win32" num="4.1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0725" published="2004-07-27" seq="2004-0725" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10718">BID:10718</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16684">moodle-help-file-xss(16684)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108973588000027&amp;w=2">20040713 Moodle XSS Vulnerability</ref><ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php">http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0726" published="2004-07-27" seq="2004-0726" severity="High" type="CVE"><desc><descript source="cve">The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10693">BID:10693</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965512912175&amp;w=2">20040711 Media Preview Script Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16704">Microsoft Windows 2000 Media Player control code execution</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0727" published="2004-07-27" seq="2004-0727" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the &quot;Similar Method Name Redirection Cross Domain Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108966512815373&amp;w=2">20040711 MSIE Similar Method Name Redirection Cross Site/Zone Scripting</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16681">Microsoft Internet Explorer function redirect cross-site scripting</ref><ref source="MISC" url="http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm">http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp">MS04-038</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">TA04-293A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/207264">VU#207264</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4702.html">OVAL4702</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6829.html">OVAL6829</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7084.html">OVAL7084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7496.html">OVAL7496</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7906.html">OVAL7906</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12048">12048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7448.html">OVAL7448</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4702">oval:org.mitre.oval:def:4702</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6829">oval:org.mitre.oval:def:6829</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7084">oval:org.mitre.oval:def:7084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7496">oval:org.mitre.oval:def:7496</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7906">oval:org.mitre.oval:def:7906</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7448">oval:org.mitre.oval:def:7448</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0.2800.1106" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0728" published="2004-07-27" seq="2004-0728" severity="Medium" type="CVE"><desc><descript source="cve">The Remote Control Client service in Microsoft&apos;s Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16696">sms-remote-service-dos(16696)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108983763710315&amp;w=2">20040714 [HV-MED] DoS in Microsoft SMS Client</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10726">BID:10726</ref></refs><vuln_soft><prod name="Systems Management Server" vendor="Microsoft"><vers num="1.2 SP4"/><vers num="1.2 SP3"/><vers num="1.2 SP2"/><vers num="1.2 SP1"/><vers num="1.2"/><vers num="2.0 SP1"/><vers num="2.0"/><vers num="2.50.2726 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0729" published="2004-07-27" seq="2004-0729" severity="Medium" type="CVE"><desc><descript source="cve">PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999024506020&amp;w=2">20040716 [waraxe-2004-SA#034 - XSS and path full path disclosure in PhpBB 2.0.8]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16723">phpBB usercp_viewprofile.php script path disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16716">phpbb-indexphp-path-disclosure(16716)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16720">phpbb-lang-faq-path-disclosure(16720)</ref><ref source="" url="http://www.waraxe.us/index.php?modname=sa&amp;id=34"></ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.8a"/><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0730" published="2004-07-27" seq="2004-0730" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parameter in lang_faq.php as accessible from faq.php, or (3) the faq[0][0] parameter in lang_bbcode.php as accessible from faq.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999024506020&amp;w=2">20040716 [waraxe-2004-SA#034 - XSS and path full path disclosure in PhpBB 2.0.8]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16725">phpBB lang_faq.php script cross-site scripting</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16724">phpbb-indexphp-xss(16724)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16726">phpbb-lang-bbcode-xss(16726)</ref><ref source="" url="http://www.waraxe.us/index.php?modname=sa&amp;id=34"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10738">10738</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.8a"/><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0731" published="2004-07-27" seq="2004-0731" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109002107329823&amp;w=2">20040716 [waraxe-2004-SA#035 - Multiple security holes in PhpNuke - part 2]</ref><ref adv="1" source="Waraxe" url="http://www.waraxe.us/index.php?modname=sa&amp;id=35"> [ Multiple security holes in PhpNuke - part 2]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16721">PHP-Nuke search module cross-site scripting</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0732" published="2004-07-27" seq="2004-0732" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109002107329823&amp;w=2">Multiple security holes in PhpNuke - part 2</ref><ref adv="1" source="Waraxe" url="http://www.waraxe.us/index.php?modname=sa&amp;id=35">[ Multiple security holes in PhpNuke - part 2]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16728">PHP-Nuke search module SQL injection</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0733" published="2004-07-27" seq="2004-0733" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10742">BID:10742</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16711">ollydbg-outputdebugstring-format-string(16711)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109007978822810&amp;w=2">20040717 [FMADV] Format String Bug in OllyDbg 1.10</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0711.html">20040717 [FMADV] Format String Bug in OllyDbg 1.10</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3757">
3757</ref></refs><vuln_soft><prod name="OllyDbg" vendor="OllyDbg"><vers num="1.0.9"/><vers num="1.0.8b"/><vers num="1.0.6"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0734" published="2004-07-27" seq="2004-0734" severity="High" type="CVE"><desc><descript source="cve">Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10744">BID:10744</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16710">extropia-webstore-command-execution(16710)</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109008402715874&amp;w=2">20040717 Web_Store.cgi allows Command Execution</ref></refs><vuln_soft><prod name="Extropia WebStore" vendor="Extropia"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0735" published="2004-07-27" seq="2004-0735" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10743">BID:10743</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16715">Medal of Honor games packet buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109008314631518&amp;w=2">20040717 Medal of Honor remote buffer-overflow</ref></refs><vuln_soft><prod name="Medal of Honor Allied Assault" vendor="Electronic Arts"><vers num="1.0"/><vers num="1.1"/><vers num="1.11 v9"/><vers num="Breakthrough 2.40 b"/><vers num="Spearhead 2.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0736" published="2004-07-27" seq="2004-0736" severity="Medium" type="CVE"><desc><descript source="cve">The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) &quot;**&quot; or (2) &quot;+&quot; search patterns, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16736">PHP-Nuke asterisk plus path disclosure</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0737" published="2004-07-27" seq="2004-0737" severity="High" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16721">PHP-Nuke search module cross-site scripting</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0738" published="2004-07-27" seq="2004-0738" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16737">PHP-Nuke search min SQL injection</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0739" published="2004-07-27" seq="2004-0739" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035224715409&amp;w=2">20040719 Buffer overflow in Whisper FTP Surfer 1.0.7</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16742">whisper-long-file-name-bo(16742)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10761/">BID:10761</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/024087.html">20040719 Buffer overflow in Whisper FTP Surfer 1.0.7</ref></refs><vuln_soft><prod name="Whisper FTP Surfer" vendor="SnapFiles"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0740" published="2004-07-27" seq="2004-0740" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035701329111&amp;w=2">20040720 Denial of Service vulnerability in several Lexmark HTTP servers</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16752">lexmark-long-host-bo(16752)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10765">BID:10765</ref></refs><vuln_soft><prod name="T522 Network Printer" vendor="Lexmark"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0741" published="2004-07-27" seq="2004-0741" severity="Medium" type="CVE"><desc><descript source="cve">LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16754">wwwfilesharepro-http-get-dos(16754)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035774701051&amp;w=2">20040720 dos_in_file_share_2.6</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.6"/><vers num="2.40"/><vers num="2.41"/><vers num="2.42"/><vers num="2.46"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0742" published="2004-07-27" seq="2004-0742" severity="High" type="CVE"><desc><descript source="cve">Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10788/">BID:10788</ref><ref adv="1" patch="1" source="Sunsolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57586">SUNALERT:57586</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16776">Sun Java System Portal Server allows access to Calendar Server</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/881254">VU#881254</ref><ref source="BID" url="http://www.securityfocus.com/bid/10788">10788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12134">12134</ref></refs><vuln_soft><prod name="Java System Calendar Server" vendor="Sun"><vers edition="x86" num="6.2"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0743" published="2004-11-23" seq="2004-0743" severity="Medium" type="CVE"><desc><descript source="cve">Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10904">Apple Mac OS X 10.3.5 Released - Multiple Vulnerabilities Fixed</ref><ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00056.html">APPLE-SA-2004-09-09</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/128414">VU#128414</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16944">safari-web-info-disclosure(16944)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0744" published="2004-11-23" seq="2004-0744" severity="Medium" type="CVE"><desc><descript source="cve">The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a &quot;Rose Attack&quot; that involves sending a subset of small IP fragments that do not form a complete, larger packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10904">Apple Mac OS X 10.3.5 Released - Multiple Vulnerabilities Fixed</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075899619193&amp;w=2">20040331 IPv4 fragmentation  --&gt; The Rose Attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308604119618&amp;w=2">20040427 Source Code To Test IPv4 fragmentation --&gt; The Rose Attack</ref><ref source="MISC" url="http://digital.net/~gandalf/Rose_Frag_Attack_Explained.txt">http://digital.net/~gandalf/Rose_Frag_Attack_Explained.txt</ref><ref source="APPLE" url="http://www.auscert.org.au/render.html?it=4291">APPLE-SA-2004-09-09</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16946">macos-tcp-ip-dos(16946)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0745" published="2004-09-28" seq="2004-0745" severity="High" type="CVE"><desc><descript source="cve">LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="redhat" url="http://www.redhat.com/support/errata/RHSA-2004-440.html">An updated lha package fixes security vulnerability</ref><ref adv="1" source="gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml">LHa: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17198">LHA metacharacter command execution</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref></refs><vuln_soft><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0746" published="2004-10-20" seq="2004-0746" severity="High" type="CVE"><desc><descript source="cve">Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user&apos;s HTTP session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327681304401&amp;w=2">KDE Security Advisory: Konqueror Cross-Domain Cookie Injection</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17063">KDE Konqueror allows attacker to set cookies in top-level domains</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10991">bid 10991</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20040823-1.txt">http://www.kde.org/info/security/advisory-20040823-1.txt</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:086">MDKSA-2004:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12341">12341</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864">CLA-2004:864</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="KDE" vendor="KDE"><vers num="3.1.3"/><vers num="3.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Konqueror" vendor="KDE"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.5b"/><vers num="3.0.5"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.5"/><vers num="3.2.1"/><vers num="3.2.3"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0747" published="2004-10-20" seq="2004-0747" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-463.html">Updated httpd packages fix security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11182">bid 11182</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml">GLSA-200409-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096">MDKSA-2004:096</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_32_apache2.html">SUSE-SA:2004:032</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17384">apache-env-configuration-bo(17384)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/481998">VU#481998</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011303">1011303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12540">12540</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/><vers num="2.0.50"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0748" published="2004-10-20" seq="2004-0748" severity="Medium" type="CVE"><desc><descript source="cve">mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Suse.com" url="http://www.suse.com/de/security/2004_30_apache2.html">SUSE Security Announcement: apache2</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-349.html">Updated httpd packages fix mod_ssl security flaw</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17200">Apache HTTP Server mod_ssl denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11094">bid 11094</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=130750">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=130750</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml">GLSA-200409-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096">MDKSA-2004:096</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_30_apache2.html">SUSE-SA:2004:030</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/><vers num="2.0.50"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0749" published="2004-12-23" seq="2004-0749" severity="Medium" type="CVE"><desc><descript source="cve">The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200409-35.xml">Subversion: Metadata information leak</ref><ref adv="1" patch="1" source="tigris.org" url="http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt">mod_authz_svn fails to protect metadata</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11243">bid 11243</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17472">Subversion mod_authz_svn information disclosure</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-318.shtml">FEDORA-2004-318</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Subversion" vendor="Subversion"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.1.0 rc3"/><vers num="1.1.0 rc2"/><vers num="1.1.0 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0750" published="2004-10-20" seq="2004-0750" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-434.html">Updated redhat-config-nfs package resolves several security issues</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17478">red-hat-permission-gain-privileges(17478)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11240">11240</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419762/100/0/threaded">FLSA:152787</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0751" published="2004-10-20" seq="2004-0751" severity="Medium" type="CVE"><desc><descript source="cve">The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-463.html">Updated httpd packages fix security issues</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.com/de/security/2004_30_apache2.html">SUSE Security Announcement: apache2</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17273">Apache HTTP Server speculative mode denial of service</ref><ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=30134">http://issues.apache.org/bugzilla/show_bug.cgi?id=30134</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0096.html">20040911 Remote buffer overflow in Apache mod_ssl when reverse proxying SSL</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml">GLSA-200409-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096">MDKSA-2004:096</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_30_apache2.html">SUSE-SA:2004:030</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/><vers num="2.0.50"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0752" published="2004-10-20" seq="2004-0752" severity="Low" type="CVE"><desc><descript source="cve">OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="OpenOffice.org" url="http://www.openoffice.org/issues/show_bug.cgi?id=33357"></ref><ref adv="1" patch="1" source="Security Tracker" url="http://securitytracker.com/id?1011205">OpenOffice World-Readable Temporary Files Disclose Files to Local Users</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-446.html">Updated openoffice.org packages resolve security issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/11151">11151</ref><ref source="OSVDB" url="http://www.osvdb.org/9804">9804</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12302/">12302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12546/">12546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12668/">12668</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12914/">12914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12932/">12932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17312">openofficeorg-tmpfile-insecure-permissions(17312)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483308421566&amp;w=2">20040910 OpenOffice World-Readable Temporary Files Disclose Files to Local Users</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0753" published="2004-10-20" seq="2004-0753" severity="Medium" type="CVE"><desc><descript source="cve">The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-447.html">Updated gdk-pixbuf packages fix security flaws</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-466.html">Updated gtk2 packages fix security flaws and bugs</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-546">DSA-546</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095">MDKSA-2004:095</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/825374">VU#825374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17383">gtk-bmp-dos(17383)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded">FLSA-2005:155510</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17657">17657</ref><ref source="BID" url="http://www.securityfocus.com/bid/11195">11195</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875">CLA-2004:875</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.17"/><vers num="0.18"/><vers num="0.20"/><vers num="0.22"/></prod><prod name="GTK+" vendor="GTK"><vers num="2.0.2"/><vers num="2.0.6"/><vers num="2.2.1"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0754" published="2004-10-20" seq="2004-0754" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Sourceforge.net" url="http://gaim.sourceforge.net/security/?id=2">Groupware message receive integer overflow</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml">gaim-0.82-0.FC1</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml">gaim-0.82-0.FC2</ref><ref adv="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml">Gaim: New vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-400.html">RHSA-2004:400</ref><ref source="BID" url="http://www.securityfocus.com/bid/11056">11056</ref><ref source="OSVDB" url="http://www.osvdb.org/9260">9260</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011083">1011083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12383">12383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12480">12480</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13101">13101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17140">gaim-groupware-integer-overflow(17140)</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10"/><vers num="0.10.3"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.59.1"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0755" published="2004-10-20" seq="2004-0755" severity="Low" type="CVE"><desc><descript source="cve">The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-537">ruby -- insecure file permissions</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-08.xml">Ruby: CGI::Session creates files insecurely</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16996">Ruby FileStore and PStore insecure permission</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:128">MDKSA-2004:128</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12290/">12290</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:128">MDKSA-2004:128</ref></refs><vuln_soft><prod name="Ruby" vendor="Yukihiro Matsumoto"><vers num="1.6"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0757" published="2004-08-18" seq="2004-0757" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=229374">bug fix</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3250.html">OVAL3250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16869">mozilla-senduidl-pop3-bo(16869)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/561022">VU#561022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10856">10856</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3250">oval:org.mitre.oval:def:3250</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0758" published="2004-08-18" seq="2004-0758" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=249004">Importing false CA certificate leading to error -8182 (perm DoS), especially exploitable by email</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127186">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127186</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml">GLSA-200408-22</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/784278">VU#784278</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3134.html">OVAL3134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16706">mozilla-certificate-dos(16706)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3134">oval:org.mitre.oval:def:3134</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-0759" published="2004-08-18" seq="2004-0759" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an &lt;input type=&quot;file&quot;&gt; tag.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=241924">Mozilla can upload files without user confirmation</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16870">mozilla-warning-file-upload(16870)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0760" published="2004-08-18" seq="2004-0760" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=250906">null (%00) in filename fakes extension (ftp, file)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1227.html">OVAL1227</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16691">mozilla-modify-mime-type(16691)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1227">oval:org.mitre.oval:def:1227</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0761" published="2004-08-18" seq="2004-0761" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=240053">SSL Certificate Spoof -- Allows malicious page to present SSL certificate from another site</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3603.html">OVAL3603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16871">mozilla-redirect-ssl-spoof(16871)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3603">oval:org.mitre.oval:def:3603</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0762" published="2004-08-18" seq="2004-0762" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=162020">pop up XPInstall/security dialog when user is about to click</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4403.html">OVAL4403</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11999/">11999</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16623">mozilla-dialog-code-execution(16623)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html">20040407 Race conditions in security dialogs</ref><ref source="" url="http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4403">oval:org.mitre.oval:def:4403</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0763" published="2004-08-18" seq="2004-0763" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the &quot;onunload&quot; method.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109087067730938&amp;w=2"> Mozilla Firefox Certificate Spoofing</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/12160/">Mozilla / Mozilla Firefox &quot;onunload&quot; SSL Certificate Spoofing</ref><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=253121">lock icon and certificates spoofable with onunload document.write</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/024372.html">20040725 Mozilla Firefox Certificate Spoofing</ref><ref source="MISC" url="http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory">http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml">GLSA-200408-22</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3989.html">OVAL3989</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16796">mozilla-ssl-certificate-spoofing(16796)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3989">oval:org.mitre.oval:def:3989</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="0.9.1"/><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0764" published="2004-08-18" seq="2004-0764" severity="High" type="CVE"><desc><descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the &quot;chrome&quot; flag and XML User Interface Language (XUL) files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=244965">Untrusted web content can display content using </ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/12160/">Mozilla / Mozilla Firefox </ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2418.html">OVAL2418</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16837">mozilla-user-interface-spoofing(16837)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/262350">VU#262350</ref><ref source="BID" url="http://www.securityfocus.com/bid/10832">10832</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12188">12188</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2418">oval:org.mitre.oval:def:2418</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0765" published="2004-08-18" seq="2004-0765" severity="High" type="CVE"><desc><descript source="cve">The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=234058">Certificate name matching for non-FQDNs is insecure</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-421.html">RHSA-2004:421</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16868">mozilla-certtesthostname-certificate-spoof(16868)</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0766" published="2004-08-18" seq="2004-0766" severity="Medium" type="CVE"><desc><descript source="cve">NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=119&amp;type=vulnerabilities&amp;flashstatus=false">NGSEC StackDefender 2.0 Invalid Pointer Dereference Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16892">stackdefender-baseaddress-dos(16892)</ref></refs><vuln_soft><prod name="StackDefender" vendor="NGSEC"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0767" published="2004-08-18" seq="2004-0767" severity="Medium" type="CVE"><desc><descript source="cve">NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="iDEFENSE" url="http://www.idefense.com/application/poi/display?id=118&amp;type=vulnerabilities&amp;flashstatus=false">NGSEC StackDefender 1.10 Invalid Pointer Dereference Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16879">stackdefender-objectattributes-dos(16879)</ref></refs><vuln_soft><prod name="StackDefender" vendor="NGSEC"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0768" published="2004-10-20" seq="2004-0768" severity="High" type="CVE"><desc><descript source="cve">libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-536">libpng -- several vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16914">libpng offset miscalculation buffer overflow</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1943">FLSA:1943</ref></refs><vuln_soft><prod name="libpng3" vendor="Greg Roelofs"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0769" published="2004-08-18" seq="2004-0769" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the &quot;x&quot; option but also exploitable through &quot;l&quot; and &quot;v&quot;, and fixed in header.c, a different issue than CVE-2004-0771.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo" url="http://bugs.gentoo.org/show_bug.cgi?id=51285">Bugzilla Bug 51285 app-arch/lha : buffer overflow again</ref><ref source="MISC" url="http://lw.ftw.zamosc.pl/lha-exploit.txt">http://lw.ftw.zamosc.pl/lha-exploit.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml">GLSA-200409-13</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-440.html">RHSA-2004:440</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16917">lha-long-pathname-bo(16917)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108745217504379&amp;w=2">20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re:</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0770" published="2005-01-10" seq="2004-0770" severity="Low" type="CVE"><desc><descript source="cve">romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10855">DGen Emulator Symbolic Link Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16884">DGen ROM decompression symlink attack</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12214">12214</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=263282&amp;archive=yes"></ref></refs><vuln_soft><prod name="Emulator" vendor="DGen"><vers num="1.15"/><vers num="1.16"/><vers num="1.17"/><vers num="1.18"/><vers num="1.20 a"/><vers num="1.20"/><vers num="1.21"/><vers num="1.22"/><vers num="1.23"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0771" published="2004-11-23" seq="2004-0771" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10354">LHA Multiple extract_one Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16196">LHA extract_one buffer overflows</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/363418">20040515 lha buffer overflow(s) again</ref><ref source="Gentoo" url="http://bugs.gentoo.org/show_bug.cgi?id=51285">51285</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml">GLSA-200409-13</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-440.html">RHSA-2004:440</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108668791510153">20040606 Re: [SECURITY] [DSA 515-1] New lha packages fix several</ref></refs><vuln_soft><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14"/><vers num="1.15"/><vers num="1.17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0772" published="2004-10-20" seq="2004-0772" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mit.edu" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt">double-free vulnerabilities in KDC and libraries</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html">Vulnerabilities in MIT Kerberos 5</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17158">Kerberos krb524d double-free</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350792">VU#350792</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-543">DSA-543</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml">GLSA-200409-09</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:088">MDKSA-2004:088</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0045/">2004-0045</ref><ref source="BID" url="http://www.securityfocus.com/bid/11078">11078</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4661.html">OVAL4661</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860">CLA-2004:860</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4661">oval:org.mitre.oval:def:4661</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:088">MDKSA-2004:088</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.0.8MIT"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2.Beta1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.3 alpha1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0774" published="2004-11-03" seq="2004-0774" severity="High" type="CVE"><desc><descript source="cve">RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17648">RealNetworks Helix Universal Server POST denial of service</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=151&amp;type=vulnerabilities">20041007 RealNetworks Helix Server Content-Length Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="Helix Universal Server" vendor="RealNetworks"><vers num="9.0.2"/><vers num="9.0.4.958" prev="1"/></prod><prod name="Helix Universal Mobile Server &amp; Gateway" vendor="RealNetworks"><vers num="10.3.1.716" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0775" published="2004-10-20" seq="2004-0775" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitrary code via certain service requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Pentest" url="http://www.pentest.co.uk/documents/ptl-2004-03.html">WIDCOMM Bluetooth Connectivity Software Buffer Overflows</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16953">Bluetooth BTW and BTW-CE/PPC service request buffer overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0029.html">20040811 ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/418633/100/0/threaded">20051204 have you ever been BluePIMped?</ref><ref source="" url="http://www.internetnews.com/security/article.php/3394181"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109223783402624&amp;w=2">20040811 ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows</ref></refs><vuln_soft><prod name="BTStackServer" vendor="WIDCOMM"><vers num="1.3.2.7"/><vers num="1.4.2.10"/></prod><prod name="Bluetooth Communication Software" vendor="WIDCOMM"><vers num="1.4.1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0777" published="2004-10-20" seq="2004-0777" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 to 2.2.1, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=131&amp;type=vulnerabilities">Courier-IMAP Remote Format String Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17034">Courier-IMAP auth_debug format string attack</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-19.xml">GLSA-200408-19</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0043/">2004-0043</ref><ref source="BID" url="http://www.securityfocus.com/bid/10976">10976</ref></refs><vuln_soft><prod name="Courier-IMAP" vendor="Inter7"><vers num="1.6"/><vers num="1.7"/><vers num="2.0.0"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="3.0.0."/><vers num="3.0.1"/><vers num="3.0.2 r1"/><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0778" published="2004-10-20" seq="2004-0778" severity="Medium" type="CVE"><desc><descript source="cve">CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=130&amp;type=vulnerabilities">CVS Undocumented Flag Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/579225">CVS &quot;history&quot; command may disclose sensitive information</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10955">bid 10955</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17001">CVS history information disclosure</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108">MDKSA-2004:108</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10.6"/><vers num="1.10.7"/><vers num="1.10.8"/><vers num="1.11"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11.2"/><vers num="1.11.3"/><vers num="1.11.4"/><vers num="1.11.5"/><vers num="1.11.6"/><vers num="1.11.10"/><vers num="1.11.11"/><vers num="1.11.14"/><vers num="1.11.15"/><vers num="1.11.16"/><vers num="1.12.1"/><vers num="1.12.2"/><vers num="1.12.5"/><vers num="1.12.7"/><vers num="1.12.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-0779" published="2004-08-18" seq="2004-0779" severity="High" type="CVE"><desc><descript source="cve">The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mandrakesoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:082">Updated mozilla packages fix multiple vulnerabilities</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=226278">http://bugzilla.mozilla.org/show_bug.cgi?id=226278</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17018">mozilla-plaintext-password(17018)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:082">MDKSA-2004:082</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="0.7"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2004-0780" published="2004-12-31" seq="2004-0780" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=366">20060110 Sun Solaris uustat Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1">101933</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16193">16193</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0113">ADV-2006-0113</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18371">18371</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015455">1015455</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24045">solaris-uustat-bo(24045)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0781" published="2004-10-20" seq="2004-0781" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-541">icecast-server -- missing escape</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11021">bid 11021</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17086">Icecast list.cgi UserAgent cross-site scripting</ref></refs><vuln_soft><prod name="Icecast" vendor="Icecast"><vers num="1.3.10"/><vers num="1.3.0"/><vers num="1.3.5.1"/><vers num="1.3.5"/><vers num="1.3.7.1"/><vers num="1.3.7"/><vers num="1.3.8"/><vers num="1.3.9.2"/><vers num="1.3.9.1"/><vers num="1.3.9"/><vers num="1.3.10.1"/><vers num="1.3.11"/><vers num="1.3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0782" published="2004-10-20" seq="2004-0782" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109528994916275&amp;w=2">gtk+ XPM decoder</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-447.html">Updated gdk-pixbuf packages fix security flaws</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-466.html">Updated gtk2 packages fix security flaws and bugs</ref><ref source="MISC" url="http://scary.beasts.org/security/CESA-2004-005.txt">http://scary.beasts.org/security/CESA-2004-005.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-546">DSA-546</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095">MDKSA-2004:095</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/729894">VU#729894</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17386">gtk-xpm-pixbufcreatefromxpm-bo(17386)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded">FLSA-2005:155510</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17657">17657</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1">101776</ref><ref source="BID" url="http://www.securityfocus.com/bid/11195">11195</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875">CLA-2004:875</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1617">oval:org.mitre.oval:def:1617</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.17"/><vers num="0.18"/><vers num="0.20"/><vers num="0.22"/></prod><prod name="GTK+" vendor="GTK"><vers num="2.0.2"/><vers num="2.0.6"/><vers num="2.2.1"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0783" published="2004-10-20" seq="2004-0783" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109528994916275&amp;w=2">gtk+ XPM decoder</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-447.html">Updated gdk-pixbuf packages fix security flaws</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-466.html">Updated gtk2 packages fix security flaws and bugs</ref><ref source="MISC" url="http://scary.beasts.org/security/CESA-2004-005.txt">http://scary.beasts.org/security/CESA-2004-005.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095">MDKSA-2004:095</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096">MDKSA-2004:096</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/369358">VU#369358</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17385">gtk-xpm-xpmextractcolor-bo(17385)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded">FLSA-2005:155510</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17657">17657</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1">101776</ref><ref source="BID" url="http://www.securityfocus.com/bid/11195">11195</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875">CLA-2004:875</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1786">oval:org.mitre.oval:def:1786</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.17"/><vers num="0.18"/><vers num="0.20"/><vers num="0.22"/></prod><prod name="GTK+" vendor="GTK"><vers num="2.0.2"/><vers num="2.0.6"/><vers num="2.2.1"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0784" published="2004-10-20" seq="2004-0784" severity="High" type="CVE"><desc><descript source="cve">The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sourceforge.net" url="http://gaim.sourceforge.net/security/?id=1">Smiley theme installation lack of escaping</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml">gaim-0.82-0.FC1</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml">gaim-0.82-0.FC2</ref><ref adv="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml">Gaim: New vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17144">Gaim smiley theme filename command execution</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-400.html">RHSA-2004:400</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10"/><vers num="0.10.3"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.59.1"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0785" published="2004-10-20" seq="2004-0785" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sourceforge.net" url="http://gaim.sourceforge.net/security/?id=3">URL decode buffer overflow</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml">gaim-0.82-0.FC1</ref><ref adv="1" patch="1" source="Fedoranews.org" url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml">gaim-0.82-0.FC2</ref><ref adv="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml">Gaim: New vulnerabilities</ref><ref source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=4">http://gaim.sourceforge.net/security/?id=4</ref><ref source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=5">http://gaim.sourceforge.net/security/?id=5</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-400.html">RHSA-2004:400</ref><ref source="BID" url="http://www.securityfocus.com/bid/11056">11056</ref><ref source="OSVDB" url="http://www.osvdb.org/9261">9261</ref><ref source="OSVDB" url="http://www.osvdb.org/9262">9262</ref><ref source="OSVDB" url="http://www.osvdb.org/9263">9263</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011083">1011083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12383">12383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12480">12480</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12929">12929</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13101">13101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17142">gaim-hostname-bo(17142)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17141">gaim-rtf-bo(17141)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17143">gaim-url-bo(17143)</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10"/><vers num="0.10.3"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.59.1"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0786" published="2004-10-20" seq="2004-0786" severity="Medium" type="CVE"><desc><descript source="cve">The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-463.html">Updated httpd packages fix security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11187">bid 11187</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml">GLSA-200409-21</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096">MDKSA-2004:096</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_32_apache2.html">SUSE-SA:2004:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-463.html">RHSA-2004:463</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17382">apache-ipv6-aprutil-dos(17382)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12540">12540</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/><vers num="2.0.50"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0787" published="2004-10-20" seq="2004-0787" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="OpenCA.org" url="http://www.openca.org/news/CAN-2004-0787.txt">Cross Site Scripting vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17274">OpenCA Web front end allows cross-site scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11113">bid 11113</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109448767123954&amp;w=2">20040906 OpenCA Security Advisory: Cross Site Scripting vulnerability</ref></refs><vuln_soft><prod name="OpenCA" vendor="OpenCA"><vers num="0.8.0"/><vers num="0.8.1"/><vers num="0.8.6"/><vers num="0.9.0.2"/><vers num="0.9.0.1"/><vers num="0.9.0"/><vers num="0.9.1.8"/><vers num="0.9.1.7"/><vers num="0.9.1.6"/><vers num="0.9.1.5"/><vers num="0.9.1.4"/><vers num="0.9.1.3"/><vers num="0.9.1.2"/><vers num="0.9.1"/><vers num="0.9.2 RC6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0788" published="2004-10-20" seq="2004-0788" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-447.html">Updated gdk-pixbuf packages fix security flaws</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-466.html">Updated gtk2 packages fix security flaws and bugs</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-546">DSA-546</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095">MDKSA-2004:095</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/577654">VU#577654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17387">gtk-ico-integer-bo(17387)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded">FLSA-2005:155510</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17657">17657</ref><ref source="BID" url="http://www.securityfocus.com/bid/11195">11195</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875">CLA-2004:875</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.17"/><vers num="0.18"/><vers num="0.20"/><vers num="0.22"/></prod><prod name="GTK+" vendor="GTK"><vers num="2.0.2"/><vers num="2.0.6"/><vers num="2.2.1"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-0789" published="2004-12-31" seq="2004-0789" severity="Medium" type="CVE"><desc><descript source="cve">Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men &amp; Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdf"></ref><ref adv="1" patch="1" source="" url="http://www.posadis.org/advisories/pos_adv_006.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11642">11642</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1012157">1012157</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13145">13145</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17997">dns-localhost-dos(17997)</ref></refs><vuln_soft><prod name="AXIS 2110 Network Camera" vendor="Axis Communications"><vers num="2.41"/><vers num="2.40"/><vers num="2.34"/><vers num="2.32"/><vers num="2.31"/><vers num="2.30"/><vers num="2.12"/></prod><prod name="Posadis" vendor="Posadis"><vers num="0.60.1"/><vers num="0.60.0"/><vers num="0.50.9"/><vers num="0.50.8"/><vers num="0.50.7"/><vers num="0.50.6"/><vers num="0.50.5"/><vers num="0.50.4"/><vers num="m5pre2"/><vers num="m5pre1"/></prod><prod name="Pliant DNS Server" vendor="Pliant"><vers num=""/></prod><prod name="AXIS 2400+ Video Server" vendor="Axis Communications"><vers num="3.12"/><vers num="3.11"/></prod><prod name="MaraDNS" vendor="MaraDNS"><vers num="0.8.05"/><vers num="0.5.31"/><vers num="0.5.30"/><vers num="0.5.29"/><vers num="0.5.28"/></prod><prod name="AXIS 2420 Network Camera" vendor="Axis Communications"><vers num="2.41"/><vers num="2.40"/><vers num="2.34"/><vers num="2.33"/><vers num="2.32"/><vers num="2.31"/><vers num="2.30"/><vers num="2.12"/></prod><prod name="AXIS 2100 Network Camera" vendor="Axis Communications"><vers num="2.41"/><vers num="2.40"/><vers num="2.34"/><vers num="2.33"/><vers num="2.32"/><vers num="2.31"/><vers num="2.30"/><vers num="2.12"/><vers num="2.03"/><vers num="2.02"/><vers num="2.01"/><vers num="2.0"/></prod><prod name="AXIS 2120 Network Camera" vendor="Axis Communications"><vers num="2.41"/><vers num="2.40"/><vers num="2.34"/><vers num="2.32"/><vers num="2.31"/><vers num="2.30"/><vers num="2.12"/></prod><prod name="DeleGate" vendor="DeleGate"><vers num="8.9.5"/><vers num="8.9.4"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9"/><vers num="8.5.0"/><vers num="8.4.0"/><vers num="8.3.4"/><vers num="8.3.3"/><vers num="7.9.11"/><vers num="7.8.2"/><vers num="7.8.1"/><vers num="7.8.0"/><vers num="7.7.1"/><vers num="7.7.0"/></prod><prod name="WinGate" vendor="Qbik"><vers num="6.0.1 build 995"/><vers num="6.0.1 build 993"/><vers num="6.0"/><vers num="4.1 Beta A"/><vers num="4.0.1"/><vers num="3.0"/></prod><prod name="dnrd" vendor="dnrd"><vers num="2.10"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="AXIS 2401+ Video Server" vendor="Axis Communications"><vers num="3.12"/></prod><prod name="AXIS 2460 Digital Video Recorder" vendor="Axis Communications"><vers num="3.12"/></prod><prod name="RaidenDNSD" vendor="Team JohnLong"><vers num=""/></prod><prod name="MyDNS" vendor="Don Moore"><vers num="0.10.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0790" published="2005-04-12" seq="2004-0790" severity="Medium" type="CVE"><desc><descript source="cve">Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the &quot;blind connection-reset attack.&quot;  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt">http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt</ref><ref adv="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref><ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1">57746</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3458.html">OVAL3458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1910.html">OVAL1910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4804.html">OVAL4804</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded">HPSBUX01164</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt">SCOSA-2006.4</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18317">18317</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2">HPSBTU01210</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1">101658</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx">MS06-064</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3983">ADV-2006-3983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22341">22341</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded">HPSBST02161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3458">oval:org.mitre.oval:def:3458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1910">oval:org.mitre.oval:def:1910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4804">oval:org.mitre.oval:def:4804</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1177">oval:org.mitre.oval:def:1177</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:176">oval:org.mitre.oval:def:176</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:211">oval:org.mitre.oval:def:211</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:412">oval:org.mitre.oval:def:412</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:514">oval:org.mitre.oval:def:514</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:53">oval:org.mitre.oval:def:53</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:622">oval:org.mitre.oval:def:622</ref><ref source="SREASON" url="http://securityreason.com/securityalert/19">19</ref><ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="SP1" num="64-bit"/><vers num="64-bit Version 2003"/></prod><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="SPARC" num="9.0"/><vers num="8.0"/><vers num="7.0"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP3"/><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0791" published="2005-04-12" seq="2004-0791" severity="Medium" type="CVE"><desc><descript source="cve">Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the &quot;ICMP Source Quench attack.&quot;  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt">http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt</ref><ref adv="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref><ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1">57746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded">HPSBUX01164</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt">SCOSA-2006.4</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18317">18317</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">RHSA-2005:043</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2">HPSBTU01210</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1">101658</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1112">oval:org.mitre.oval:def:1112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:184">oval:org.mitre.oval:def:184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:464">oval:org.mitre.oval:def:464</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:596">oval:org.mitre.oval:def:596</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:688">oval:org.mitre.oval:def:688</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:726">oval:org.mitre.oval:def:726</ref><ref source="SREASON" url="http://securityreason.com/securityalert/19">19</ref><ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="SPARC" num="9.0"/><vers num="8.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0792" published="2004-10-20" seq="2004-0792" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-538">rsync -- unsanitised input processing</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml">rsync: Potential information leakage</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:083">Updated rsync packages fix remotely-exploitable vulnerability</ref><ref source="CONFIRM" url="http://samba.org/rsync/#security_aug04">http://samba.org/rsync/#security_aug04</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_26_rsync.html">SUSE-SA:2004:026</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0042/">2004-0042</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109268147522290&amp;w=2">20040816 TSSA-2004-020-ES - rsync</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109277141223839&amp;w=2">20040817 LNSA-#2004-0017: rsync (Aug, 17 2004)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:083">MDKSA-2004:083</ref></refs><vuln_soft><prod name="rsync" vendor="Andrew Tridgell"><vers num="2.3.1"/><vers num="2.3.2_1.3"/><vers edition="Sparc" num="2.3.2_1.2"/><vers edition="PPC" num="2.3.2_1.2"/><vers edition="M68K" num="2.3.2_1.2"/><vers edition="Intel" num="2.3.2_1.2"/><vers edition="ARM" num="2.3.2_1.2"/><vers edition="Alpha" num="2.3.2_1.2"/><vers num="2.3.2"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.8"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="2.5.5"/><vers num="2.5.6"/><vers num="2.5.7"/><vers num="2.6"/><vers num="2.6.1"/><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0793" published="2004-10-20" seq="2004-0793" severity="High" type="CVE"><desc><descript source="cve">The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396230317359&amp;w=2">Possible root compromose with bsdmainutils 6.0.x &lt; 6.0.15</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11077">bid 11077</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17162">bsdmainutils calendar allows attacker to gain root access</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="6.0"/><vers num="6.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0794" published="2004-10-20" seq="2004-0794" severity="Medium" type="CVE"><desc><descript source="cve">Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NetBSB.org" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc">ftpd root escalation</ref><ref adv="1" source="netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-August/025418.html">Multiple remote vulnerabilities in lukemftpd aka. tnftpd</ref><ref adv="1" source="VuXML.org" url="http://www.vuxml.org/freebsd/c4b025bb-f05d-11d8-9837-000c41e2cdad.html">tnftpd -- remotely exploitable vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025418.html">20040817 Multiple remote vulnerabilities in lukemftpd aka. tnftpd</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-551">DSA-551</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17020">tnftpd-gain-access(17020)</ref></refs><vuln_soft><prod name="lukemftp" vendor="Luke Mewburn"><vers num="1.1"/><vers num="1.5"/></prod><prod name="TNFTPD" vendor="Luke Mewburn"><vers num="2003-12-17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0795" published="2004-10-20" seq="2004-0795" severity="High" type="CVE"><desc><descript source="cve">DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107885081414173&amp;w=2"> IBM DB2 Remote Command Execution Privilege Upgrade</ref><ref adv="1" source="IBM" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY53894">NAMED PIPE AUTHENTICATION INSTEAD OF USING AUTHENTICATION OF THEUSER IT IS LOGGED IN AS</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15420">IBM DB2 Remote Command Server allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9821">bid 9821</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/db2rmtcmd.txt">http://www.nextgenss.com/advisories/db2rmtcmd.txt</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="AIX" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0796" published="2004-10-20" seq="2004-0796" severity="Medium" type="CVE"><desc><descript source="cve">SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=spamassassin-announce&amp;m=109168121628767&amp;w=2">SpamAssassin 2.64 is released!</ref><ref patch="1" source="Mandrakesoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:084">Updated spamassassin packages fixes possible malformed message vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10957">bid 10957</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2268">FLSA:2268</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-06.xml">GLSA-200408-06</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=129337">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=129337</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16938">spamassassin-dos(16938)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:084">MDKSA-2004:084</ref></refs><vuln_soft><prod name="SpamAssassin" vendor="SpamAssassin"><vers num="2.40"/><vers num="2.41"/><vers num="2.42"/><vers num="2.43"/><vers num="2.44"/><vers num="2.50"/><vers num="2.55"/><vers num="2.60"/><vers num="2.63"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0797" published="2004-10-20" seq="2004-0797" severity="Low" type="CVE"><desc><descript source="cve">The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109353792914900&amp;w=2">OpenPKG Security Advisory (zlib)</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_29_zlib.html">zlib</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=252253">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=252253</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2043">FLSA:2043</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:090">MDKSA-2004:090</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.17/SCOSA-2004.17.txt">SCOSA-2004.17</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_29_zlib.html">SUSE-SA:2004:029</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/238678">VU#238678</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-26.xml">GLSA-200408-26</ref><ref source="OSVDB" url="http://www.osvdb.org/9360">9360</ref><ref source="OSVDB" url="http://www.osvdb.org/9361">9361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11129">11129</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011085">1011085</ref><ref source="BID" url="http://www.securityfocus.com/bid/11051">11051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17119">zlib-inflate-inflateback-dos(17119)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt">SCOSA-2006.6</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18377">18377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17054">17054</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000865">CLA-2004:865</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000878">CLA-2004:878</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.319160">SSA:2004-278</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:090">MDKSA-2004:090</ref></refs><vuln_soft><prod name="zlib" vendor="GNU"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0798" published="2004-10-20" seq="2004-0798" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17111">WhatsUp Gold _maincfgret.cgi buffer overflow</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?type=vulnerabilities">20040825 Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html">http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11043">11043</ref></refs><vuln_soft><prod name="WhatsUp Gold" vendor="Ipswitch"><vers num="7.04"/><vers num="7.03"/><vers num="7.0"/><vers num="8.03"/><vers num="8.01"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0799" published="2004-10-20" seq="2004-0799" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using &quot;prn.htm&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=142&amp;type=vulnerabilities">Ipswitch WhatsUp Gold Remote Denial of Service Vulnerability</ref><ref patch="1" source="Ipswitch.com" url="http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html">WhatsUp Gold Patches &amp; Upgrades</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17418">whatsup-get-prn-dos(17418)</ref></refs><vuln_soft><prod name="WhatsUp Gold" vendor="Ipswitch"><vers num="7.04"/><vers num="7.03"/><vers num="7.0"/><vers num="8.03 hotfix 1"/><vers num="8.03"/><vers num="8.01"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0800" published="2004-08-24" seq="2004-0800" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=132&amp;type=vulnerabilities">20040824 CDE Mailer argv[0] Format String Vulnerability</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/928598">VU#928598</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4030.html">OVAL4030</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4030">oval:org.mitre.oval:def:4030</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-202.shtml">O-202</ref><ref source="BID" url="http://www.securityfocus.com/bid/11027">11027</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17095">dtmail-argv-format-string(17095)</ref></refs><vuln_soft><prod name="DtMail" vendor="Sun"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod><prod name="CMS Server" vendor="Avaya"><vers num="12.0"/><vers num="11.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0801" published="2004-09-16" seq="2004-0801" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000880">CLA-2004:880</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.12/SCOSA-2005.12.txt">SCOSA-2005.12</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_31_cups.html">SUSE-SA:2004:031</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0047/">2004-0047</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12557/">12557</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17388">foomatic-command-execution(17388)</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0007.html">SUSE-SA:2006:026</ref><ref source="BID" url="http://www.securityfocus.com/bid/11184">11184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20312">20312</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/><vers num="2.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Foomatic-Filters" vendor="LinuxPrinting.org"><vers num="3.1"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="Java Desktop System" vendor="Sun"><vers num="2.0"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-13" name="CVE-2004-0802" published="2004-12-31" seq="2004-0802" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870">CLA-2004:870</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml">GLSA-200409-12</ref><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html">http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html</ref><ref source="MISC" url="http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup">http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11084">11084</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17183">imlib2-bmp-bo(17183)</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.0.2"/><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.3"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="amd64" num="9.2"/><vers num="9.2"/></prod><prod name="Imlib" vendor="Enlightenment"><vers num="1.9.14"/><vers num="1.9.13"/><vers num="1.9.12"/><vers num="1.9.11"/><vers num="1.9.10"/><vers num="1.9.9"/><vers num="1.9.8"/><vers num="1.9.7"/><vers num="1.9.6"/><vers num="1.9.5"/><vers num="1.9.4"/><vers num="1.9.3"/><vers num="1.9.2"/><vers num="1.9.1"/><vers num="1.9"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Java Desktop System" vendor="Sun"><vers num="2.0"/><vers num="2003"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Imlib2" vendor="Enlightenment"><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="TurboLinux Desktop" vendor="TurboLinux"><vers num="10.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2004-0803" published="2004-12-23" seq="2004-0803" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2004-577.html">Updated libtiff packages</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_38_libtiff.html">libtiff</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17703">LibTIFF library tiff library image decoding routines buffer overflow</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/948752">LibTIFF contains multiple heap-based buffer overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-567">DSA-567-1 tiff -- heap overflows</ref><ref source="MISC" url="http://scary.beasts.org/security/CESA-2004-006.txt">http://scary.beasts.org/security/CESA-2004-006.txt</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041209-2.txt">http://www.kde.org/info/security/advisory-20041209-2.txt</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-11.xml">GLSA-200410-11</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:109">MDKSA-2004:109</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-354.html">RHSA-2005:354</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html">SUSE-SA:2004:038</ref><ref source="BID" url="http://www.securityfocus.com/bid/11406">11406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12818">12818</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100114.html">OVAL100114</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-021.html">RHSA-2005:021</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778785107450&amp;w=2">20041013 CESA-2004-006: libtiff</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888">CLA-2004:888</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1">101677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100114">oval:org.mitre.oval:def:100114</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109">MDKSA-2004:109</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="LibTIFF" vendor="LibTIFF"><vers num="3.4"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.5.7"/><vers num="3.6.0"/><vers num="3.6.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="wxGTK2" vendor="wxGTK2"><vers num="2.5 .0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="PDF Library" vendor="PDFLib"><vers num="5.0.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0804" published="2004-11-03" seq="2004-0804" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="www.debian.org" url="http://www.debian.org/security/2004/dsa-567">DSA-567-1 tiff -- heap overflows</ref><ref adv="1" patch="1" source="www.mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:109">MDKSA-2004:109</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-577.html">Updated libtiff packages</ref><ref adv="1" patch="1" source="www.suse.de" url="http://www.suse.de/de/security/2004_38_libtiff.html">[suse-security-announce] SuSE Security Announcement: libtiff (SUSE-SA:2004:038)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17755">LibTIFF tif_dirread.c denial of service</ref><ref source="MISC" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=111">http://bugzilla.remotesensing.org/show_bug.cgi?id=111</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041209-2.txt">http://www.kde.org/info/security/advisory-20041209-2.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888">CLA-2004:888</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-354.html">RHSA-2005:354</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html">SUSE-SA:2004:038</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/555304">VU#555304</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100115.html">OVAL100115</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-021.html">RHSA-2005:021</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1">101677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100115">oval:org.mitre.oval:def:100115</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109">MDKSA-2004:109</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref></refs><vuln_soft><prod name="LibTIFF" vendor="LibTiff"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0805" published="2004-12-23" seq="2004-0805" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-564">mpg123 -- missing user input sanitising</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11121">bid 11121</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17287">mpg123 layer2.c buffer overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/374433">20040916 mpg123 buffer overflow vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026151.html">20040907 mpg123 buffer overflow vulnerability</ref><ref source="MISC" url="http://www.alighieri.org/advisories/advisory-mpg123.txt">http://www.alighieri.org/advisories/advisory-mpg123.txt</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-20.xml">GLSA-200409-20</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:100">MDKSA-2004:100</ref><ref source="BID" url="http://www.securityfocus.com/bid/">11121</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="mpg123" vendor="mpg123"><vers num="0.59s"/><vers num="0.59r"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0806" published="2004-12-31" seq="2004-0806" severity="High" type="CVE"><desc><descript source="cve">cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2004/Sep/0097.html">20040909 Bugtraq: cdrecord local root exploit</ref><ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-09/0108.html">20040910 CAU-EX-2004-0002: cdrecord-suidshell.sh</ref><ref adv="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2058">FLSA:2058</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:091">MDKSA-2004:091</ref><ref patch="1" source="BID" url="http://www.securityfocus.org/bid/11075">11075</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12481/">12481</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17303">cdrecord-rsh-gain-privileges(17303)</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/700326">VU#700326</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011091">1011091</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:091">MDKSA-2004:091</ref></refs><vuln_soft><prod name="CDRecord" vendor="CDRTools"><vers num="1.11"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0807" published="2004-09-13" seq="2004-0807" severity="Medium" type="CVE"><desc><descript source="cve">Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=139&amp;type=vulnerabilities">20040913 Samba 3.x SMBD Remote Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509335230495&amp;w=2">20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 &amp; CAN-2004-0808)</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873">CLA-2004:873</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml">GLSA-200409-16</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-467.html">RHSA-2004:467</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0046/">2004-0046</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526231623307&amp;w=2">20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba)</ref></refs><vuln_soft><prod name="samba_irix" vendor="SGI"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4 r1"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0808" published="2004-12-31" seq="2004-0808" severity="Medium" type="CVE"><desc><descript source="cve">The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=138&amp;type=vulnerabilities">20040913 Samba nmbd Invalid Length Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509335230495&amp;w=2">20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 &amp; CAN-2004-0808)</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873">CLA-2004:873</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml">GLSA-200409-16</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-467.html">RHSA-2004:467</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.net/errata/2004/0046/">2004-0046</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526231623307&amp;w=2">20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba)</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4 r1"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0809" published="2004-09-16" seq="2004-0809" severity="Medium" type="CVE"><desc><descript source="cve">The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml">GLSA-200409-21</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-558">DSA-558</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-463.html">RHSA-2004:463</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2004/0047/">2004-0047</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17366">apache-moddav-lock-dos(17366)</ref><ref source="" url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/fs/lock.c?r1=1.32&amp;r2=1.33"></ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="amd64" num="9.2"/><vers num="9.2"/></prod><prod name="Tru64 UNIX Compaq Secure Web Server" vendor="HP"><vers num="6.3"/><vers num="5.9.2"/><vers num="5.9.1"/><vers num="5.8.2"/><vers num="5.8.1"/><vers num="5.1 A"/><vers num="5.1"/><vers num="5.0 A"/><vers num="4.0 G"/><vers num="4.0 F"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Turbolinux Home" vendor="Turbolinux"><vers num=""/></prod><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.50"/><vers num="2.0.47"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="TurboLinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.00"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/><vers num="2.0"/></prod><prod name="TurboLinux Desktop" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0810" published="2004-12-23" seq="2004-0810" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Securepoint.com" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0411/218.html">Netopia Timbuktu remote buffer overflow issue</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11714">bid 11714</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18172">Timbuktu multiple connections denial of service</ref><ref source="MISC" url="http://www.corsaire.com/advisories/c040720-001.txt">http://www.corsaire.com/advisories/c040720-001.txt</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/190204/index.htm">http://www.uniras.gov.uk/vuls/2004/190204/index.htm</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13250/">13250</ref></refs><vuln_soft><prod name="Timbuktu Pro Mac" vendor="Netopia"><vers num="6.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0811" published="2004-12-31" seq="2004-0811" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Apache 2.0.51 prevents &quot;the merging of the Satisfy directive,&quot; which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apacheweek.com/features/security-20">http://www.apacheweek.com/features/security-20</ref><ref patch="1" source="CONFIRM" url="http://www.apache.org/dist/httpd/patches/apply_to_2.0.51/CAN-2004-0811.patch">http://www.apache.org/dist/httpd/patches/apply_to_2.0.51/CAN-2004-0811.patch</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17473">apache-satisfy-gain-access(17473)</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-313.shtml">FEDORA-2004-313</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-33.xml">GLSA-200409-33</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0049">2004-0049</ref><ref source="BID" url="http://www.securityfocus.com/bid/11239">11239</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0812" published="2005-04-14" seq="2004-0812" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with &quot;setting up TSS limits,&quot; allows local users to cause a denial of service (crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">Updated kernel packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Ciac.org" url="http://www.ciac.org/ciac/bulletins/p-047.shtml">Red Hat Updated Kernel Packages</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11794">bid 11794</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@3fad673ber4GuU7iWppydzNIyLntEQ">http://linux.bkbits.net:8080/linux-2.6/cset@3fad673ber4GuU7iWppydzNIyLntEQ</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13359">13359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18346">linux-tss-gain-privilege(18346)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-09" name="CVE-2004-0813" published="2004-12-31" seq="2004-0813" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform unauthorized write and erase operations.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://lkml.org/lkml/2004/7/30/147">http://lkml.org/lkml/2004/7/30/147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17505">linux-sgio-gain-privileges(17505)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12498/">12498</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-23.xml">GLSA-200711-23</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0465.html">RHSA-2007:0465</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/25749">25749</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25631">25631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26909">26909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref></refs><vuln_soft><prod name="ide-cd" vendor="ide-cd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0814" published="2004-12-23" seq="2004-0814" severity="Low" type="CVE"><desc><descript source="cve">Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11491">bid 11491</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11492">bid 11492</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17816">Linux kernel TIOCSETD race condition</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2">[USN-38-1] Linux kernel vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/379005">20041020 CAN-2004-0814: Linux terminal layer races</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131672">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131672</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=133110">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=133110</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.2.25"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0815" published="2004-11-03" seq="2004-0815" severity="High" type="CVE"><desc><descript source="cve">The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via &quot;/.////&quot; style sequences in pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="www.idefense.com" url="http://www.idefense.com/application/poi/display?id=146&amp;type=vulnerabilities&amp;flashstatus=true">Samba Arbitrary File Access Vulnerability</ref><ref adv="1" patch="1" source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655827913457&amp;w=2"> Samba Security Announcement -- Potential Arbitrary File Access</ref><ref adv="1" patch="1" source="distro.conectiva.com.br" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873">Correes para vulnerabilidades do samba</ref><ref adv="1" patch="1" source="www.debian.org" url="http://www.debian.org/security/2004/dsa-600">DSA-600-1 samba -- arbitrary file access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11281">Samba Remote Arbitrary File Access Vulnerability</ref><ref source="CONFIRM" url="http://us4.samba.org/samba/news/#security_2.2.12">http://us4.samba.org/samba/news/#security_2.2.12</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2102">FLSA:2102</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:104">MDKSA-2004:104</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_35_samba.html">SUSE-SA:2004:035</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0051/">2004-0051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17556">samba-file-access(17556)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/377618">20041005 ERRATA: Potential Arbitrary File Access (CAN-2004-0815)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-498.html">RHSA-2004:498</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1">101584</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1">57664</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.2a"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.2"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/><vers num="2.2.8a"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.11"/><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2a"/><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0816" published="2004-12-23" seq="2004-0816" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_37_kernel.html">kernel</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17800">Linux, kernel, IP packet denial of service</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_37_kernel.html">SUSE-SA:2004:037</ref><ref source="BID" url="http://www.securityfocus.com/bid/11488">11488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11202/">11202</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-13" name="CVE-2004-0817" published="2004-12-31" seq="2004-0817" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870">CLA-2004:870</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-548">DSA-548</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml">GLSA-200409-12</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:089">MDKSA-2004:089</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-465.html">RHSA-2004:465</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11084">11084</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17182">imlib-bmp-bo(17182)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:089">MDKSA-2004:089</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.0.2"/><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.3"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="amd64" num="9.2"/><vers num="9.2"/></prod><prod name="Imlib" vendor="Enlightenment"><vers num="1.9.14"/><vers num="1.9.13"/><vers num="1.9.12"/><vers num="1.9.11"/><vers num="1.9.10"/><vers num="1.9.9"/><vers num="1.9.8"/><vers num="1.9.7"/><vers num="1.9.6"/><vers num="1.9.5"/><vers num="1.9.4"/><vers num="1.9.3"/><vers num="1.9.2"/><vers num="1.9.1"/><vers num="1.9"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Java Desktop System" vendor="Sun"><vers num="2.0"/><vers num="2003"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Imlib2" vendor="Enlightenment"><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="TurboLinux Desktop" vendor="TurboLinux"><vers num="10.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0819" published="2004-08-25" seq="2004-0819" severity="Medium" type="CVE"><desc><descript source="cve">The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345131508824&amp;w=2">20040825 Vulnerability: OpenBSD 3.5 Kernel Panic.</ref><ref adv="1" patch="1" source="OPENBSD" url="http://www.openbsd.org/errata.html">20040826 028: RELIABILITY FIX: August 26, 2004</ref><ref adv="1" patch="1" source="OPENBSD" url="http://openbsd.org/errata34.html">20040826 028: RELIABILITY FIX: August 26, 2004</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0820" published="2004-08-28" seq="2004-0820" severity="Medium" type="CVE"><desc><descript source="cve">Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.frsirt.com/exploits/08252004.skinhead.php">http://www.frsirt.com/exploits/08252004.skinhead.php</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12381/">12381</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4338">ESB-2004.0537</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17124">winamp-wsz-execute-code(17124)</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.04"/><vers num="5.03"/><vers num="5.02"/><vers num="5.01"/><vers num="3.1"/><vers num="3.0"/><vers num="2.91"/><vers num="2.81"/><vers num="2.80"/><vers num="2.79"/><vers num="2.78"/><vers num="2.77"/><vers num="2.76"/><vers num="2.75"/><vers num="2.74"/><vers edition="full" num="2.73"/><vers num="2.73"/><vers num="2.72"/><vers num="2.71"/><vers edition="full" num="2.70"/><vers num="2.70"/><vers num="2.65"/><vers edition="standard" num="2.64"/><vers edition="standard" num="2.62"/><vers edition="full" num="2.61"/><vers edition="lite" num="2.60"/><vers edition="full" num="2.60"/><vers num="2.50"/><vers num="2.24"/><vers num="2.10"/><vers num="2.64"/><vers num="2.5e"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0821" published="2004-12-31" seq="2004-0821" severity="High" type="CVE"><desc><descript source="cve">The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://www.auscert.org.au/render.html?it=4363">APPLE-SA-0024-09-07</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704110">VU#704110</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12491/">12491</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11135">11135</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17291">macos-corefoundation-gain-privileges(17291)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0822" published="2004-09-07" seq="2004-0822" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://www.securityfocus.com/advisories/7148">APPLE-SA-2004-09-07</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545446">VU#545446</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12491/">12491</ref><ref source="BID" url="http://www.securityfocus.com/bid/11136">11136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17295">macos-corefoundation-bo(17295)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0823" published="2004-09-07" seq="2004-0823" severity="High" type="CVE"><desc><descript source="cve">OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://www.securityfocus.com/advisories/7148">APPLE-SA-2004-09-07</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4363">ESB-2004.0559</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11137">11137</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12491/">12491</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17300">openldap-crypt-gain-access(17300)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-751.html">RHSA-2005:751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17233">17233</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21520">21520</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod><prod name="OpenLDAP" vendor="OpenLDAP"><vers num="2.1.19"/><vers num="2.1.18"/><vers num="2.1.17"/><vers num="2.1.16"/><vers num="2.1.15"/><vers num="2.1.14"/><vers num="2.1.13"/><vers num="2.1.12"/><vers num="2.1.11"/><vers num="2.1.10"/><vers num="2.1.4"/><vers num="2.1 .20"/><vers num="2.0.27"/><vers num="2.0.25"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11_9"/><vers num="2.0.11_11S"/><vers num="2.0.11_11"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0824" published="2004-12-31" seq="2004-0824" severity="Low" type="CVE"><desc><descript source="cve">PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://www.securityfocus.com/advisories/7148">APPLE-SA-2004-09-07</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4363">ESB-2004.0559</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11139">11139</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011175">1011175</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17298">macosx-pppdialer-symlink(17298)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0825" published="2004-12-31" seq="2004-0825" severity="Medium" type="CVE"><desc><descript source="cve">QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://www.securityfocus.com/advisories/7148">APPLE-SA-2004-09-07</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109467471617466&amp;w=2">20040908 Re: Apple, Apple Remote Desktop client [Multiple vulnerabilities]</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17294">quicktime-dos(17294)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11138">11138</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/914870">VU#914870</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011176">1011176</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12491">12491</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0826" published="2004-12-31" seq="2004-0826" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/180">20040823 Netscape NSS Library Remote Compromise</ref><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109351293827731&amp;w=2">SSRT4779</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11015">11015</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16314">sslv2-client-hello-overflow(16314)</ref></refs><vuln_soft><prod name="Personalization Engine" vendor="Netscape"><vers num=""/></prod><prod name="Java Enterprise System" vendor="Sun"><vers num="2004Q2"/><vers num="2003Q4"/></prod><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.11"/><vers num="B.11.00"/></prod><prod name="ONE Web Server" vendor="Sun"><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="6.0 SP8"/><vers num="6.0 SP7"/><vers num="6.0 SP6"/><vers num="6.0 SP5"/><vers num="6.0 SP4"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="4.1 SP9"/><vers num="4.1 SP8"/><vers num="4.1 SP7"/><vers num="4.1 SP6"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP14"/><vers num="4.1 SP13"/><vers num="4.1 SP12"/><vers num="4.1 SP11"/><vers num="4.1 SP10"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Netscape Enterprise Server Netware" vendor="Netscape"><vers num="5.0"/><vers num="4.1.1"/><vers num="3.0.7a"/></prod><prod name="Certificate Server" vendor="Netscape"><vers num="4.2"/><vers num="1.0 P1"/></prod><prod name="Netscape Directory Server" vendor="Netscape"><vers num="4.13"/><vers num="4.11"/><vers num="4.1"/><vers num="3.12"/><vers num="3.1P1"/><vers num="1.3P5"/></prod><prod name="Network Security Services" vendor="Mozilla"><vers num="3.9"/><vers num="3.8"/><vers num="3.7.7"/><vers num="3.7.5"/><vers num="3.7.3"/><vers num="3.7.2"/><vers num="3.7.1"/><vers num="3.7"/><vers num="3.6.1"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4.2"/><vers num="3.4.1"/><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.1"/><vers num="3.2"/></prod><prod name="Netscape Enterprise Server Solaris" vendor="Netscape"><vers num="3.6"/><vers num="3.5"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="4.1 SP8"/><vers num="4.1 SP7"/><vers num="4.1 SP6"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.0"/><vers num="3.51"/><vers num="3.6 SP3"/><vers num="3.6 SP2"/><vers num="3.6 SP1"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0.1b"/><vers num="3.0.1"/><vers num="3.0L"/><vers num="3.0"/><vers num="2.0.1c"/><vers num="2.0a"/><vers num="2.0"/></prod><prod name="Java System Application Server" vendor="Sun"><vers num="7.1"/><vers num="7.0 UR4"/><vers edition="Standard" num="7.0"/><vers edition="Platform" num="7.0"/><vers edition="Enterprise" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-13" name="CVE-2004-0827" published="2004-09-16" seq="2004-0827" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-547">DSA-547</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-480.html">RHSA-2004:480</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-494.html">RHSA-2004:494</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17173">imagemagick-bmp-Bo(17173)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28800">28800</ref></refs><vuln_soft><prod name="Imlib" vendor="Enlightenment"><vers num="1.9.14"/><vers num="1.9.13"/><vers num="1.9.12"/><vers num="1.9.11"/><vers num="1.9.10"/><vers num="1.9.9"/><vers num="1.9.8"/><vers num="1.9.7"/><vers num="1.9.6"/><vers num="1.9.5"/><vers num="1.9.4"/><vers num="1.9.3"/><vers num="1.9.2"/><vers num="1.9.1"/><vers num="1.9"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="amd64" num="9.2"/><vers num="9.2"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Java Desktop System" vendor="Sun"><vers num="2.0"/><vers num="2003"/></prod><prod name="Turbolinux" vendor="Turbolinux"><vers num="Workstation 8.0"/><vers num="Workstation 7.0"/><vers num="Server 8.0"/><vers num="Server 7.0"/><vers num="Desktop 10.0"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.0.2"/><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.3"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Imlib2" vendor="Enlightenment"><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0828" published="2004-11-03" seq="2004-0828" severity="Low" type="CVE"><desc><descript source="cve">The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17514">IBM ctstrtcasd file overwrite</ref><ref source="BID" url="http://www.securityfocus.com/bid/11264">11264</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12664/">12664</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011429">1011429</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0829" published="2004-12-31" seq="2004-0829" severity="Medium" type="CVE"><desc><descript source="cve">smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2004/Sep/0003.html">20040831 Samba FindNextPrintChangeNotify() Error Lets Remote Authenticated Users Crash smbd</ref><ref patch="1" source="CONFIRM" url="http://samba.org/samba/history/samba-2.2.11.html">http://samba.org/samba/history/samba-2.2.11.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-14.xml">GLSA-200409-14</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2004/0043">2004-0043</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17138">samba-findnextprintchangenotify-dos(17138)</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.2.10"/><vers num="2.2.9"/><vers num="2.2.8a"/><vers num="2.2.8"/><vers num="2.2.7a"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5a"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="1.9.18 p10"/><vers num="1.9.18 p8"/><vers num="1.9.18 p7"/><vers num="1.9.18 p6"/><vers num="1.9.18 p5"/><vers num="1.9.18 p4"/><vers num="1.9.18 p3"/><vers num="1.9.18 p2"/><vers num="1.9.18 p1"/><vers num="1.9.18"/><vers num="1.9.17 p5"/><vers num="1.9.17 p4"/><vers num="1.9.17 p3"/><vers num="1.9.17 p2"/><vers num="1.9.17 p1"/><vers num="1.9.17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-0830" published="2004-09-09" seq="2004-0830" severity="Medium" type="CVE"><desc><descript source="cve">The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=137&amp;type=vulnerabilities">20040909 F-Secure Internet Gatekeeper Content Scanning Server Denial of Service Vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483205925698&amp;w=2">20040910 F-Secure Internet Gatekeeper Content Scanning Server Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.f-secure.com/security/fsc-2004-2.shtml">http://www.f-secure.com/security/fsc-2004-2.shtml</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11145">11145</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17307">fsecure-content-scanner-dos(17307)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.32"/><vers num="6.31"/><vers num="6.3"/></prod><prod name="F-Secure Content Scanner Server" vendor="F-Secure"><vers num="6.31"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers edition="MS Exchange" num="6.21"/><vers edition="MS Exchange" num="6.2"/><vers edition="MS Exchange" num="6.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0831" published="2004-09-14" seq="2004-0831" severity="High" type="CVE"><desc><descript source="cve">McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the &quot;System Scan&quot; properties of the System Tray applet, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526269429728&amp;w=2">20040915 McAfee VirusScan Privilege Escalation Vulnerability [iDEFENSE]</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=140&amp;type=vulnerabilities">20040914 McAfee VirusScan Privilege Escalation Vulnerability</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17367">mcafee-virusscan-gain-privileges(17367)</ref></refs><vuln_soft><prod name="VirusScan" vendor="McAfee"><vers num="4.5.1"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0832" published="2004-11-03" seq="2004-0832" severity="Medium" type="CVE"><desc><descript source="cve">The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200409-04.xml">Squid: Denial of service when using NTLM authentication</ref><ref adv="1" patch="1" source="Mandrakesoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:093">MDKSA-2004:093</ref><ref adv="1" patch="1" source="trustix" url="http://www.trustix.org/errata/2004/0047/">http://www.trustix.org/errata/2004/0047/</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17218">Squid Web Proxy Cache NTLMSSP packet denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11098">Squid Proxy NTLM Authentication Denial Of Service Vulnerability</ref><ref source="CONFIRM" url="http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string">http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string</ref><ref source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1045">http://www.squid-cache.org/bugs/show_bug.cgi?id=1045</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:093">MDKSA-2004:093</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0833" published="2004-12-23" seq="2004-0833" severity="High" type="CVE"><desc><descript source="cve">Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-554">sendmail -- pre-set password</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/12667/">Debian sendmail sasl-bin Mail Relaying Security Issue</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11262">bid 11262</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17531">Sendmail sasl-bin mail relay</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12667">12667</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0834" published="2004-12-23" seq="2004-0834" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Sourceforge.net" url="http://speedtouch.sourceforge.net/index.php?/news.en.html">Speedtouch USB driver homepage</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17792">SpeedTouch format string attack</ref><ref source="MISC" url="http://www.mail-archive.com/speedtouch@ml.free.fr/msg06688.html">http://www.mail-archive.com/speedtouch@ml.free.fr/msg06688.html</ref><ref source="" url="http://sourceforge.net/project/showfiles.php?group_id=32758&amp;package_id=28264&amp;release_id=271734"></ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="ppc" num="8.2"/><vers num="8.2"/><vers num="9.0"/><vers edition="ppc" num="9.1"/><vers num="9.1"/><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Speedtouch USB Driver" vendor="Speedtouch"><vers num="1.0"/><vers num="1.1"/><vers num="1.2 Beta3"/><vers num="1.2 Beta2"/><vers num="1.2 Beta1"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0835" published="2004-11-03" seq="2004-0835" severity="High" type="CVE"><desc><descript source="cve">MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="www.debian.org" url="http://www.debian.org/security/2004/dsa-562">DSA-562-1 mysql -- several vulnerabilities</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">Updated mysql packages fix security issues and bugs</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-611.html">Updated mysql-server package</ref><ref adv="1" source="www.trustix.org" url="http://www.trustix.org/errata/2004/0054/">Trustix Secure Linux Security Advisory #2004-0054</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17666">MySQL ALTER TABLE RENAME bypass restriction</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml">GLSA-200410-22</ref><ref source="MISC" url="http://bugs.mysql.com/bug.php?id=3270">http://bugs.mysql.com/bug.php?id=3270</ref><ref adv="1" source="MISC" url="http://lists.mysql.com/internals/13073">http://lists.mysql.com/internals/13073</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12783/">12783</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Oct/1011606.html">http://www.securitytracker.com/alerts/2004/Oct/1011606.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11357">11357</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892">CLA-2004:892</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011606">1011606</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="" url="http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html"></ref><ref source="" url="http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html"></ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.59" prev="1"/><vers num="4.0.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0836" published="2004-11-03" seq="2004-0836" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="www.debian.org" url="http://www.debian.org/security/2004/dsa-562">DSA-562-1 mysql -- several vulnerabilities</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">Updated mysql packages fix security issues and bugs</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-611.html">Updated mysql-server package</ref><ref adv="1" source="www.trustix.org" url="http://www.trustix.org/errata/2004/0054/">Trustix Secure Linux Security Advisory #2004-0054</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17047">MySQL mysql_real_connect buffer overflow</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml">GLSA-200410-22</ref><ref source="MISC" url="http://bugs.mysql.com/bug.php?id=4017">http://bugs.mysql.com/bug.php?id=4017</ref><ref source="MISC" url="http://lists.mysql.com/internals/14726">http://lists.mysql.com/internals/14726</ref><ref source="BID" url="http://www.securityfocus.com/bid/10981">10981</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12305/">12305</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892">CLA-2004:892</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2">20041125 [USN-32-1] mysql vulnerabilities</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.49" prev="1"/><vers num="4.0.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0837" published="2004-11-03" seq="2004-0837" severity="Low" type="CVE"><desc><descript source="cve">MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref patch="1" source="www.debian.org" url="http://www.debian.org/security/2004/dsa-562">DSA-562-1 mysql -- several vulnerabilities</ref><ref adv="1" patch="1" source="rhn.redhat.com" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">Updated mysql packages fix security issues and bugs</ref><ref adv="1" source="www.trustix.org" url="http://www.trustix.org/errata/2004/0054/">Trustix Secure Linux Security Advisory #2004-0054</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17667">MySQL UNION change denial of service</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml">GLSA-200410-22</ref><ref source="MISC" url="http://bugs.mysql.com/2408">http://bugs.mysql.com/2408</ref><ref source="MISC" url="http://lists.mysql.com/internals/16168">http://lists.mysql.com/internals/16168</ref><ref source="MISC" url="http://lists.mysql.com/internals/16173">http://lists.mysql.com/internals/16173</ref><ref source="MISC" url="http://lists.mysql.com/internals/16174">http://lists.mysql.com/internals/16174</ref><ref source="MISC" url="http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15">http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-611.html">RHSA-2004:611</ref><ref source="BID" url="http://www.securityfocus.com/bid/11357">11357</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Oct/1011606.html">http://www.securitytracker.com/alerts/2004/Oct/1011606.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12783/">12783</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011606">1011606</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892">CLA-2004:892</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2">20041125 [USN-32-1] mysql vulnerabilities</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.49" prev="1"/><vers num="4.0.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0838" published="2004-09-13" seq="2004-0838" severity="Low" type="CVE"><desc><descript source="cve">Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a091304-1.txt">A091304-1</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11162">11162</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12522">12522</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17342">jumpdrive-safeguard-obtain-password(17342)</ref></refs><vuln_soft><prod name="JumpDrive Secure" vendor="Lexar"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0839" published="2004-08-18" seq="2004-0839" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by &quot;wottapoop.html&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2004/Aug/0868.html">20040818 What A Drag II XP SP2</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109303291513335&amp;w=2">20040818 What A Drag II XP SP2</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109336221826652&amp;w=2">20040824 What A Drag! -revisited-</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">MS04-038</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">TA04-293A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/526089">VU#526089</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10973">10973</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1563.html">OVAL1563</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2073.html">OVAL2073</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3773.html">OVAL3773</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4152.html">OVAL4152</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6272.html">OVAL6272</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7721.html">OVAL7721</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17044">ie-dragdrop-code-execution(17044)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1563">oval:org.mitre.oval:def:1563</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2073">oval:org.mitre.oval:def:2073</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3773">oval:org.mitre.oval:def:3773</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4152">oval:org.mitre.oval:def:4152</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6272">oval:org.mitre.oval:def:6272</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7721">oval:org.mitre.oval:def:7721</ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Mobile Voice Client" vendor="Nortel"><vers num="2050"/></prod><prod name="IP softphone" vendor="Nortel"><vers num="2050"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/></prod><prod name="Symposium Web Client" vendor="Nortel"><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="2.0"/><vers num="1.1"/></prod><prod name="S3400 Message Application Server" vendor="Avaya"><vers num=""/></prod><prod name="Optivity Telephony Manager (OTM)" vendor="Nortel"><vers num=""/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Symposium Web Center Portal (SWCP)" vendor="Nortel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0840" published="2004-11-03" seq="2004-0840" severity="High" type="CVE"><desc><descript source="cve">The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-035.asp">Vulnerability in SMTP Could Allow Remote Code Execution (885881)</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/394792">Microsoft Windows SMTP component vulnerable to remote code execution</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17621">Microsoft Windows 2003 SMTP service code execution</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17660">Microsoft Windows MS04-035 patch is not installed</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2300.html">OVAL2300</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3460.html">OVAL3460</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5509.html">OVAL5509</ref><ref source="BID" url="http://www.securityfocus.com/bid/11374">11374</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2300">oval:org.mitre.oval:def:2300</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3460">oval:org.mitre.oval:def:3460</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5509">oval:org.mitre.oval:def:5509</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2003"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="64-bit"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="64-bit"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0841" published="2004-12-23" seq="2004-0841" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka &quot;HijackClick 3&quot; and the &quot;Script in Image Tag File Download Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/368652">HijackClick 3</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10690">bid 10690</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16675">Microsoft, Internet Explorer, popup.show allows attacker to perform actions</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/368666">20040712 Re: HijackClick 3</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.html">20040712 Brand New Hole: Internet Explorer: HijackClick 3</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">TA04-293A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/413886">VU#413886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2611.html">OVAL2611</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4363.html">OVAL4363</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5620.html">OVAL5620</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6031.html">OVAL6031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6048.html">OVAL6048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval8077.html">OVAL8077</ref><ref source="OSVDB" url="http://www.osvdb.org/7774">7774</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010679">1010679</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12048">12048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2611">oval:org.mitre.oval:def:2611</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4363">oval:org.mitre.oval:def:4363</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5620">oval:org.mitre.oval:def:5620</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6031">oval:org.mitre.oval:def:6031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6048">oval:org.mitre.oval:def:6048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8077">oval:org.mitre.oval:def:8077</ref></refs><vuln_soft><prod name="S3400 Message Application Server" vendor="Avaya"><vers num=""/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="1.1"/><vers num="2.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-0842" published="2004-12-23" seq="2004-0842" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from &quot;memory corruption&quot;) via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the &quot;&lt;STYLE&gt;@;/*&quot; string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the &quot;CSS Heap Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109107496214572&amp;w=2">Crash IE with 11 bytes</ref><ref adv="1" source="Ecqurity.com" url="http://www.ecqurity.com/adv/IEstyle.html">Memory Corruption Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10816">bid 10816</ref><ref source="MISC" url="http://www.securiteam.com/exploits/5NP042KF5A.html">http://www.securiteam.com/exploits/5NP042KF5A.html</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp">MS04-038</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">TA04-293A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/291304">VU#291304</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2906.html">OVAL2906</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3372.html">OVAL3372</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4169.html">OVAL4169</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5592.html">OVAL5592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6579.html">OVAL6579</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-006.shtml">P-006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12806">12806</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16675">ie-popupshow-perform-actions(16675)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109060455614702&amp;w=2">20040723 Crash IE with 11 bytes ;)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109102919426844&amp;w=2">20040728 Re: Crash IE with 11 bytes ;)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2906">oval:org.mitre.oval:def:2906</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3372">oval:org.mitre.oval:def:3372</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4169">oval:org.mitre.oval:def:4169</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5592">oval:org.mitre.oval:def:5592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6579">oval:org.mitre.oval:def:6579</ref></refs><vuln_soft><prod name="S3400 Message Application Server" vendor="Avaya"><vers num=""/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="1.1"/><vers num="2.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0843" published="2004-11-03" seq="2004-0843" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the &quot;Plug-in Navigation Address Bar Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="www.us-cert.gov" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">Multiple Vulnerabilities in Microsoft Internet Explorer</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/625616">Microsoft Internet Explorer does not properly handle navigations from plug-ins</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17655">Microsoft Internet Explorer plug-in navigation allows address bar spoofing</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17651">Microsoft Internet Explorer MS04-038 patch is not installed</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2487.html">OVAL2487</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2537.html">OVAL2537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3949.html">OVAL3949</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6313.html">OVAL6313</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7095.html">OVAL7095</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7194.html">OVAL7194</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2487">oval:org.mitre.oval:def:2487</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2537">oval:org.mitre.oval:def:2537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3949">oval:org.mitre.oval:def:3949</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6313">oval:org.mitre.oval:def:6313</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7095">oval:org.mitre.oval:def:7095</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7194">oval:org.mitre.oval:def:7194</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0844" published="2004-11-03" seq="2004-0844" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the &quot;Address Bar Spoofing on Double Byte Character Set Systems Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="www.us-cert.gov" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">Multiple Vulnerabilities in Microsoft Internet Explorer</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/431576">Microsoft Internet Explorer vulnerable to address bar spoofing on double byte character set systems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17652">Microsoft Internet Explorer Double Byte Character Set spoof Web site to obtain information</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17651">Microsoft Internet Explorer MS04-038 patch is not installed</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110178042025729&amp;w=2">20041128 Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110174346717733&amp;w=2">20041128 Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2448.html">OVAL2448</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval8127.html">OVAL8127</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2448">oval:org.mitre.oval:def:2448</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8127">oval:org.mitre.oval:def:8127</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0845" published="2004-11-03" seq="2004-0845" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109770364504803&amp;w=2">ACROS Security: Poisoning Cached HTTPS Documents in Internet Explorer</ref><ref patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="www.us-cert.gov" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">Multiple Vulnerabilities in Microsoft Internet Explorer</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/795720">Microsoft Internet Explorer does not properly handle cached HTTPS contents</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17654">Microsoft Internet Explorer cache from SSL Web sites obtain information</ref><ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2004-10-13-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2004-10-13-1-PUB.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2219.html">OVAL2219</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3872.html">OVAL3872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5150.html">OVAL5150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5520.html">OVAL5520</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5740.html">OVAL5740</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7611.html">OVAL7611</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17651">ie-ms04038-patch(17651)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2219">oval:org.mitre.oval:def:2219</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3872">oval:org.mitre.oval:def:3872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5150">oval:org.mitre.oval:def:5150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5520">oval:org.mitre.oval:def:5520</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5740">oval:org.mitre.oval:def:5740</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7611">oval:org.mitre.oval:def:7611</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0846" published="2004-11-03" seq="2004-0846" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-033.asp">Vulnerability in Microsoft Excel Could Allow Remote Code Execution (886836)</ref><ref adv="1" source="www.ciac.org" url="http://www.ciac.org/ciac/bulletins/p-009.shtml">P-009: Microsoft Excel Vulnerability Could Allow Remote Code Execution</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/274496">Microsoft Excel parameter validation error</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17653">Microsoft Excel allows code execution</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2673.html">OVAL2673</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4226.html">OVAL4226</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12800/">12800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17683">excel-ms04033-patch(17683)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779810827096&amp;w=2">20041013 Buffer Overflow In Microsoft Excel</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2673">oval:org.mitre.oval:def:2673</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4226">oval:org.mitre.oval:def:4226</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2001"/><vers num="v. X"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2001"/><vers num="2002"/><vers num="X"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0847" published="2004-11-03" seq="2004-0847" severity="High" type="CVE"><desc><descript source="cve">The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) &quot;\&quot; (backslash) or (2) &quot;%5C&quot; (encoded backslash), aka &quot;Path Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2004-q3/0221.html">Security bug in .NET Forms Authentication</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17644">Microsoft ASP.NET Framework bypass security</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-004.mspx">MS05-004</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/283646">VU#283646</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3556.html">OVAL3556</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4987.html">OVAL4987</ref><ref source="" url="http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&amp;forum_id=24754"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3556">oval:org.mitre.oval:def:3556</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4987">oval:org.mitre.oval:def:4987</ref><ref source="BID" url="http://www.securityfocus.com/bid/11342">11342</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0848" published="2005-02-08" seq="2004-0848" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) &quot;%00 (null byte) in .doc filenames or (2) &quot;%0a&quot; (carriage return) in .rtf filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-005.mspx">MS05-005</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/416001">VU#416001</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2348.html">OVAL2348</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2738.html">OVAL2738</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4022.html">OVAL4022</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19107">ms-url-bo(19107)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2348">oval:org.mitre.oval:def:2348</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2738">oval:org.mitre.oval:def:2738</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4022">oval:org.mitre.oval:def:4022</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers num="2002 SP3"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod><prod name="Office" vendor="Microsoft"><vers num="XP SP3"/><vers num="XP SP1"/><vers num="XP SP2"/><vers num=""/></prod><prod name="Project" vendor="Microsoft"><vers num="2002 SP1"/><vers num="2002"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2003"/><vers num="2002"/></prod><prod name="Word" vendor="Microsoft"><vers num="2002 SP3"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod><prod name="Visio" vendor="Microsoft"><vers edition="Standard" num="2002 SP2"/><vers edition="Professional" num="2002 SP2"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0849" published="2004-12-23" seq="2004-0849" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=141&amp;type=vulnerabilities">GNU Radius SNMP String Length Integer Overflow Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="gnu.org" url="http://lists.gnu.org/archive/html/info-gnu-radius/2004-09/msg00000.html">GNU Radius 1.2.94.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17391">GNU Radius asn_decode_string integer overflow</ref></refs><vuln_soft><prod name="Radius" vendor="GNU"><vers num="0.92.1"/><vers num="0.93"/><vers num="0.94"/><vers num="0.95"/><vers num="0.96"/><vers num="1.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0850" published="2004-12-23" seq="2004-0850" severity="High" type="CVE"><desc><descript source="cve">Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/339089">star fails to set proper permissions on programs specified in RSH environment variable</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17297">Star ssh gain privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11141">bid 11141</ref><ref adv="1" patch="1" source="Securitytracker.com" url="http://www.securitytracker.com/alerts/2004/Sep/1011195.html">Star Has Unspecified Flaw That May Let Local Users Gain Root Privileges</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-11.xml">GLSA-200409-11</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011195">1011195</ref></refs><vuln_soft><prod name="Star Tape Archiver" vendor="Joerg Schilling"><vers num="1.5 a45"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0851" published="2004-09-08" seq="2004-0851" severity="Low" type="CVE"><desc><descript source="cve">The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109466910232385&amp;w=2">20040908 Insecure Temporary File Creation Vulnerability in Net-Acct</ref><ref adv="1" source="CONFIRM" url="http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch">http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-559">DSA-559</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11125">11125</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12476">12476</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17283">net-acct-tmp-symlink(17283)</ref></refs><vuln_soft><prod name="Net-Acct" vendor="Ulrich Callmeier"><vers num="0.71"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0852" published="2004-12-20" seq="2004-0852" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-611">DSA-611</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13579">13579</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18603">htget-bo(18603)</ref></refs><vuln_soft><prod name="HTGET" vendor="HTGET"><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0866" published="2004-09-16" seq="2004-0866" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user&apos;s HTTP session.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109536612321898&amp;w=2">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11186">11186</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17415">web-browser-session-hijack(17415)</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011332.html">http://www.securitytracker.com/alerts/2004/Sep/1011332.html</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1011332">1011332</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="0.9.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="Konqueror" vendor="KDE"><vers num="3.2.3"/><vers num="3.2.1"/><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.5b"/><vers num="3.0.5"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.1.2"/><vers num="2.1.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-07-17" name="CVE-2004-0867" published="2004-12-23" seq="2004-0867" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user&apos;s HTTP session.  NOTE: it was later reported that 2.x is also affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11186">bid 11186</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17415">Multiple vendor Web browsers allows attacker to hijack a user&apos;s session</ref><ref adv="1" source="Securitytracker.com" url="http://www.securitytracker.com/alerts/2004/Sep/1011331.html">Firefox Bug in Setting Cookies in Certain Domains May Let Remote Users Conduct Session Fixation Attacks</ref><ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=252342">https://bugzilla.mozilla.org/show_bug.cgi?id=252342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12580/">12580</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011331">1011331</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109536612321898&amp;w=2">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref source="" url="http://kuza55.blogspot.com/2008/02/understanding-cookie-security.html"></ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/></prod><prod name="Konqueror" vendor="KDE"><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.5b"/><vers num="3.0.5"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.2.1"/><vers num="3.2.3"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.2"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0868" published="2004-12-23" reject="1" seq="2004-0868" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0866.  Reason: This candidate is a duplicate of CVE-2004-0866.  Notes: The description for CVE-2004-0866 was inadvertently attached to this issue instead.  All CVE users should reference CVE-2004-0866 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0869" published="2004-09-16" seq="2004-0869" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka &quot;Cross Security Boundary Cookie Injection.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://securityfocus.com/archive/1/375407">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011332">1011332</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17417">web-browser-cookie-session-hijack(17417)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0870" published="2004-09-16" seq="2004-0870" severity="Medium" type="CVE"><desc><descript source="cve">KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka &quot;Cross Security Boundary Cookie Injection.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://securityfocus.com/archive/1/375407">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011330">1011330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17417">web-browser-cookie-session-hijack(17417)</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.2.3"/><vers num="3.2.1"/><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.5b"/><vers num="3.0.5"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.1.2"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0871" published="2004-09-16" seq="2004-0871" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka &quot;Cross Security Boundary Cookie Injection.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://securityfocus.com/archive/1/375407">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011331">1011331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17417">web-browser-cookie-session-hijack(17417)</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0872" published="2004-09-16" seq="2004-0872" severity="Medium" type="CVE"><desc><descript source="cve">Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka &quot;Cross Security Boundary Cookie Injection.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://securityfocus.com/archive/1/375407">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011329">1011329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17417">web-browser-cookie-session-hijack(17417)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0873" published="2004-12-23" seq="2004-0873" severity="High" type="CVE"><desc><descript source="cve">Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a &quot;link&quot; that references the program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple" url="http://lists.apple.com/archives/security-announce/2004/Sep/msg00001.html">APPLE-SA-2004-09-16 Security Update 2004-09-16</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17420">iChat AV link allows application execution</ref></refs><vuln_soft><prod name="iChat AV" vendor="Apple"><vers num="2.0"/><vers num="2.1"/></prod><prod name="iChat" vendor="Apple"><vers num="1.0.1"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0874" published="2005-01-10" reject="1" seq="2004-0874" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1123.  Reason: This candidate is a reservation duplicate of CVE-2004-1123.  Notes: All CVE users should reference CVE-2004-1123 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0875" published="2004-12-23" seq="2004-0875" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200409-22.xml">phpGroupWare: XSS vulnerability in wiki module</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17289">phpGroupWare Wiki module cross-site scripting</ref><ref source="CONFIRM" url="http://downloads.phpgroupware.org/changelog">http://downloads.phpgroupware.org/changelog</ref></refs><vuln_soft><prod name="PHPGroupWare" vendor="PHPGroupWare"><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14.007"/><vers num="0.9.14.006"/><vers num="0.9.14.005"/><vers num="0.9.14.003"/><vers num="0.9.16 RC1"/><vers num="0.9.16.002"/><vers num="0.9.16.000"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0880" published="2005-01-27" seq="2004-0880" severity="Low" type="CVE"><desc><descript source="cve">getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.</descript></desc><loss_types><int/></loss_types><vuln_types><config/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571883130372&amp;w=2">Local root compromise possible with getmail</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17437">getmail mbox file race condition</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11224">Getmail Local Symbolic Link Vulnerability</ref><ref source="CONFIRM" url="http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG">http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-553">DSA-553</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-32.xml">GLSA-200409-32</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="getmail" vendor="getmail"><vers num="3.x"/><vers num="2.3.7"/><vers num="4.0.0 b10"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="current"/><vers num="9.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0881" published="2005-01-27" seq="2004-0881" severity="Low" type="CVE"><desc><descript source="cve">getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571883130372&amp;w=2">Local root compromise possible with getmail</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17439">getmail maildir race condition</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11224">Getmail Local Symbolic Link Vulnerability</ref><ref source="CONFIRM" url="http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG">http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-553">DSA-553</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-32.xml">GLSA-200409-32</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="getmail" vendor="getmail"><vers num="3.x"/><vers num="2.3.7"/><vers num="4.0.0 b10"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="current"/><vers num="9.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0882" published="2005-01-27" seq="2004-0882" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small &quot;maximum data bytes&quot; value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Trustix.net" url="http://www.trustix.net/errata/2004/0058/">Trustix Secure Linux Security Advisory #2004-0058</ref><ref adv="1" source="Suse" url="http://www.suse.de/de/security/2004_40_samba.html">Online Security Support</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18070">Samba QFILEPATHINFO buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11678">Samba QFILEPATHINFO Unicode Filename Remote Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://security.e-matters.de/advisories/132004.html">http://security.e-matters.de/advisories/132004.html</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt">SCOSA-2005.17</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P">20041201-01-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_40_samba.html">SUSE-SA:2004:040</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-038.shtml">P-038</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/457622">VU#457622</ref><ref source="OSVDB" url="http://www.osvdb.org/11782">11782</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012235">1012235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13189">13189</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054671403755&amp;w=2">20041115 Advisory 13/2004: Samba 3.x QFILEPATHINFO unicode filename buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110055646329581&amp;w=2">20041115 [SAMBA] CAN-2004-0882: Possiebl Buffer Overrun in smbd</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000899">CLA-2004:899</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330519803655&amp;w=2">20041217 [OpenPKG-SA-2004.054] OpenPKG Security Advisory (samba)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4 r1"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0883" published="2005-01-10" seq="2004-0883" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11695">Linux Kernel SMBFS Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18135">Linux kernel smb_proc_readX_data denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">Updated openmotif packages fix image vulnerability</ref><ref source="MISC" url="http://security.e-matters.de/advisories/142004.html">http://security.e-matters.de/advisories/142004.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082989725345&amp;w=2">20041118 [USN-30-1] Linux kernel vulnerabilities</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13232/">13232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18134">linux-smb-response-dos(18134)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18136">linux-smbreceivetrans2-dos(18136)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/726198">VU#726198</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110072140811965&amp;w=2">20041117 Advisory 14/2004: Linux 2.x smbfs multiple remote vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0884" published="2005-01-27" seq="2004-0884" severity="High" type="CVE"><desc><descript source="cve">The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-563">DSA-563-3 cyrus-sasl -- unsanitised input</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11347">Cyrus SASL Multiple Remote And Local Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17643">Cyrus-SASL SASL_PATH environment variable</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:106">Updated cyrus-sasl packages fix local vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-568">DSA-568</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2137">FLSA:2137</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml">GLSA-200410-05</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-546.html">RHSA-2004:546</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0053/">2004-0053</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134657">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134657</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-003.shtml">P-003</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693126007214&amp;w=2">20050128 [OpenPKG-SA-2005.004] OpenPKG Security Advisory (sasl)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:106">MDKSA-2004:106</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="SASL" vendor="Cyrus"><vers num="1.5.24"/><vers num="1.5.27"/><vers num="1.5.28"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.11"/><vers num="2.1.12"/><vers num="2.1.13"/><vers num="2.1.14"/><vers num="2.1.15"/><vers num="2.1.16"/><vers num="2.1.17"/><vers num="2.1.18 r1"/><vers num="2.1.18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0885" published="2004-11-03" seq="2004-0885" severity="High" type="CVE"><desc><descript source="cve">The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the &quot;SSLCipherSuite&quot; directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17671">Apache HTTP Server SSLCipherSuite bypass restrictions</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-600.html">Updated apache and mod_ssl packages fix security vulnerabilities</ref><ref source="CONFIRM" url="http://www.apacheweek.com/features/security-20">http://www.apacheweek.com/features/security-20</ref><ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=31505">http://issues.apache.org/bugzilla/show_bug.cgi?id=31505</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01123">HPSBUX01123</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-177-1">USN-177-1</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786159119069&amp;w=2">20041015 [OpenPKG-SA-2004.044] OpenPKG Security Advisory (modssl)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-562.html">RHSA-2004:562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="BID" url="http://www.securityfocus.com/bid/11360">11360</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/><vers num="2.0.50"/><vers num="2.0.51"/><vers num="2.0.52"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0886" published="2005-01-27" seq="2004-0886" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-577.html">Updated libtiff packages</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11406">LibTIFF Multiple Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17715">LibTiff integer overflow</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:109">Updated libtiff packages fix multiple vulnerabilities</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041209-2.txt">http://www.kde.org/info/security/advisory-20041209-2.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-567">DSA-567</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-354.html">RHSA-2005:354</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html">SUSE-SA:2004:038</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0054/">2004-0054</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/687568">VU#687568</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-015.shtml">P-015</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Oct/1011674.html">http://www.securitytracker.com/alerts/2004/Oct/1011674.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12818">12818</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011674">1011674</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100116.html">OVAL100116</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-021.html">RHSA-2005:021</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888">CLA-2004:888</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779465621929&amp;w=2">OpenPKG-SA-2004.043</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1">101677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100116">oval:org.mitre.oval:def:100116</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109">MDKSA-2004:109</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="LibTIFF" vendor="LibTIFF"><vers num="3.4"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.5.7"/><vers num="3.6.0"/><vers num="3.6.1"/></prod><prod name="PDF Library" vendor="PDFLib"><vers num="5.0.2"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="wxGTK2" vendor="wxGTK2"><vers num=""/><vers num="2.5 .0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0887" published="2005-01-27" seq="2004-0887" severity="High" type="CVE"><desc><descript source="cve">SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="suse" url="http://www.suse.de/de/security/2004_37_kernel.html">Online Security Support</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17801">Linux kernel instruction allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11489">Linux IBM S/390 Kernel SACF Instruction Local Privilege Escalation Vulnerability</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_37_kernel.html">SUSE-SA:2004:037</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref></refs><vuln_soft><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9.0"/><vers edition="S_390" num="9.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0888" published="2005-01-27" seq="2004-0888" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-543.html">Updated CUPS packages fix security issues</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:113">Updated xpdf packages fix vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17818">Xpdf PDF integer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11501">Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-573">DSA-573</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-581">DSA-581</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-599">DSA-599</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2353">FLSA:2353</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml">GLSA-200410-20</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml">GLSA-200410-30</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:114">MDKSA-2004:114</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:115">MDKSA-2004:115</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:116">MDKSA-2004:116</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-592.html">RHSA-2004:592</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-066.html">RHSA-2005:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-354.html">RHSA-2005:354</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000886">CLA-2004:886</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815379627883&amp;w=2">FLSA:2352</ref><ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880927526773&amp;w=2">SUSE-SA:2004:039</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900116408307&amp;w=2">USN-9-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:113">MDKSA-2004:113</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:114">MDKSA-2004:114</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:115">MDKSA-2004:115</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:116">MDKSA-2004:116</ref></refs><vuln_soft><prod name="GPdf" vendor="GNOME"><vers num="0.112"/><vers num="0.131"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="kpdf" vendor="KDE"><vers num="3.2"/></prod><prod name="PDFTOHTML" vendor="PDFTOHTML"><vers num="0.32b"/><vers num="0.32a"/><vers num="0.33a"/><vers num="0.33"/><vers num="0.34"/><vers num="0.35"/><vers num="0.36"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/></prod><prod name="teTeX" vendor="teTeX"><vers num="1.0.7"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/></prod><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="2.3"/><vers num="2.1"/><vers num="2.0"/><vers num="3.0"/></prod><prod name="Koffice" vendor="KDE"><vers num="1.3 Beta3"/><vers num="1.3 Beta2"/><vers num="1.3 Beta1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0889" published="2005-01-27" seq="2004-0889" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml">Xpdf, CUPS: Multiple integer overflows</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:113">Updated xpdf packages fix vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17819">Xpdf PDF file integer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11501/info/">Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml">GLSA-200410-30</ref><ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880927526773&amp;w=2">SUSE-SA:2004:039</ref><ref source="BID" url="http://www.securityfocus.com/bid/11501">11501</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:113">MDKSA-2004:113</ref></refs><vuln_soft><prod name="GPdf" vendor="GNOME"><vers num="0.112"/><vers num="0.131"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="kpdf" vendor="KDE"><vers num="3.2"/></prod><prod name="PDFTOHTML" vendor="PDFTOHTML"><vers num="0.32b"/><vers num="0.32a"/><vers num="0.33a"/><vers num="0.33"/><vers num="0.34"/><vers num="0.35"/><vers num="0.36"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/></prod><prod name="teTeX" vendor="teTeX"><vers num="1.0.7"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/></prod><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="2.3"/><vers num="2.1"/><vers num="2.0"/><vers num="3.0"/></prod><prod name="Koffice" vendor="KDE"><vers num="1.3 Beta3"/><vers num="1.3 Beta2"/><vers num="1.3 Beta1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0890" published="2005-01-10" reject="1" seq="2004-0890" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reasons: This candidate is a reservation duplicate of another candidate.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0891" published="2005-01-27" seq="2004-0891" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an &quot;unexpected sequence of MSNSLP messages&quot; that results in an unbounded copy operation that writes to the wrong buffer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-604.html">Updated gaim package fixes security issues and bugs</ref><ref adv="1" source="Sourceforge.net" url="http://gaim.sourceforge.net/security/?id=9">MSN SLP buffer overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17786">Gaim MSN SLP message buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11482">Gaim MSN SLP Remote Buffer Overflow Vulnerability</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2188">FLSA:2188</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-23.xml">GLSA-200410-23</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17790">gaim-file-transfer-dos(17790)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17787">gaim-msn-slp-dos(17787)</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900412126643&amp;w=2">USN-8-1</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10"/><vers num="0.10.3"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.59.1"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/><vers num="0.66"/><vers num="0.67"/><vers num="0.68"/><vers num="0.69"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/><vers num="0.78"/><vers num="0.82"/><vers num="0.82.1"/><vers num="1.0"/><vers num="1.0.1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="current"/><vers num="9.0"/><vers num="9.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-0892" published="2005-01-27" seq="2004-0892" severity="High" type="CVE"><desc><descript source="cve">Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-039.asp">Vulnerability in ISA Server 2000 and Proxy Server 2.0 Could Allow Internet Content Spoofing (888258)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11605">Microsoft ISA and Proxy Server Web Site Spoofing Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17906">Microsoft ISA Server and Proxy Server allow Web site spoofing caused by cache reverse lookup results</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4264.html">OVAL4264</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4859.html">OVAL4859</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4264">oval:org.mitre.oval:def:4264</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4859">oval:org.mitre.oval:def:4859</ref></refs><vuln_soft><prod name="proxy server" vendor="Microsoft"><vers num="2.0 SP1"/><vers num="2.0"/></prod><prod name="ISA Server" vendor="Microsoft"><vers num="2000 SP2"/><vers num="2000 SP1"/><vers num="2000"/></prod><prod name="Small Business Server" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0893" published="2005-01-10" seq="2004-0893" severity="High" type="CVE"><desc><descript source="cve">The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka &quot;Windows Kernel Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11913">Microsoft Windows Kernel Unchecked LPC Buffer Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-044.asp">Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1321.html">OVAL1321</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1561.html">OVAL1561</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1581.html">OVAL1581</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1886.html">OVAL1886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2008.html">OVAL2008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4021.html">OVAL4021</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4458.html">OVAL4458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval450.html">OVAL450</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18339">win-kernel-lpc-gain-privileges(18339)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1321">oval:org.mitre.oval:def:1321</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1561">oval:org.mitre.oval:def:1561</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1581">oval:org.mitre.oval:def:1581</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1886">oval:org.mitre.oval:def:1886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2008">oval:org.mitre.oval:def:2008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4021">oval:org.mitre.oval:def:4021</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4458">oval:org.mitre.oval:def:4458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:450">oval:org.mitre.oval:def:450</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="R2"/><vers edition="64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Web"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0894" published="2005-01-10" seq="2004-0894" severity="High" type="CVE"><desc><descript source="cve">LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11914">Microsoft Windows LSASS Connection Validation Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-044.asp">Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1888.html">OVAL1888</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2062.html">OVAL2062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3312.html">OVAL3312</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3325.html">OVAL3325</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4368.html">OVAL4368</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval778.html">OVAL778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18340">win-lsass-gain-privileges(18340)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1888">oval:org.mitre.oval:def:1888</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2062">oval:org.mitre.oval:def:2062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3312">oval:org.mitre.oval:def:3312</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3325">oval:org.mitre.oval:def:3325</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4368">oval:org.mitre.oval:def:4368</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:778">oval:org.mitre.oval:def:778</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="R2"/><vers edition="64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Web"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0897" published="2005-01-11" seq="2004-0897" severity="High" type="CVE"><desc><descript source="cve">The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-003.mspx">MS05-003</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-095.shtml">P-095</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2128.html">OVAL2128</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2447.html">OVAL2447</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/657118">VU#657118</ref><ref source="BID" url="http://www.securityfocus.com/bid/12228">12228</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012833">1012833</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13802">13802</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2128">oval:org.mitre.oval:def:2128</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2447">oval:org.mitre.oval:def:2447</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0899" published="2005-01-10" seq="2004-0899" severity="Medium" type="CVE"><desc><descript source="cve">The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka &quot;Logging Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11919">Microsoft Windows DHCP Server Logging Remote Denial Of Service Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-042.asp">Vulnerability in DHCP Could Allow Remote Code Execution and Denial of Service (885249)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2280.html">OVAL2280</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4282.html">OVAL4282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18341">winnt-dhcp-machinename-dos(18341)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2280">oval:org.mitre.oval:def:2280</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4282">oval:org.mitre.oval:def:4282</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0 alpha"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0900" published="2005-01-10" seq="2004-0900" severity="High" type="CVE"><desc><descript source="cve">The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the &quot;DHCP Request Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11920">Microsoft Windows DHCP Server Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-042.asp">Vulnerability in DHCP Could Allow Remote Code Execution and Denial of Service (885249)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3577.html">OVAL3577</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4846.html">OVAL4846</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18342">winnt-dhcp-hardwareaddress-code-execution(18342)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3577">oval:org.mitre.oval:def:3577</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4846">oval:org.mitre.oval:def:4846</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0 alpha"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0901" published="2005-01-10" seq="2004-0901" severity="High" type="CVE"><desc><descript source="cve">Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka &quot;Font Conversion Vulnerability,&quot; a different vulnerability than CVE-2004-0571.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11929">Microsoft Word for Windows 6.0 Converter Font Conversion Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-041.asp">Vulnerability in WordPad Could Allow Code Execution (885836)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-055.shtml">P-055</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1241.html">OVAL1241</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1655.html">OVAL1655</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3310.html">OVAL3310</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3882.html">OVAL3882</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4076.html">OVAL4076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4576.html">OVAL4576</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4749.html">OVAL4749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval539.html">OVAL539</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18338">win-converter-font-code-execution(18338)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=162&amp;type=vulnerabilities&amp;flashstatus=true">20041214 Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1241">oval:org.mitre.oval:def:1241</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1655">oval:org.mitre.oval:def:1655</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3310">oval:org.mitre.oval:def:3310</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3882">oval:org.mitre.oval:def:3882</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4076">oval:org.mitre.oval:def:4076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4576">oval:org.mitre.oval:def:4576</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4749">oval:org.mitre.oval:def:4749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:539">oval:org.mitre.oval:def:539</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0902" published="2005-01-27" seq="2004-0902" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the &quot;Send page&quot; functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla.org" url="http://www.mozilla.org/projects/security/known-vulnerabilities.htmlmozilla1.7.3">Known Vulnerabilities in Mozilla</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html">Multiple vulnerabilities in Mozilla products</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17379">Mozilla, Firefox, and Thunderbird nsPop3Protocol.cpp buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11170">Mozilla Multiple URI Processing Heap Based Buffer Overflow Vulnerabilities</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=258005">http://bugzilla.mozilla.org/show_bug.cgi?id=258005</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=245066">http://bugzilla.mozilla.org/show_bug.cgi?id=245066</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=226669">http://bugzilla.mozilla.org/show_bug.cgi?id=226669</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=256316">http://bugzilla.mozilla.org/show_bug.cgi?id=256316</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17378">mozilla-netscape-nonascii-bo(17378)</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0903" published="2005-01-27" seq="2004-0903" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/414240">Mozilla Mail vulnerable to buffer overflow via </ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11174">Mozilla Browser Vcard Handling Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17380">Mozilla, Firefox, Thunderbird, and Netscape nsVCardObj.cpp buffer overflow</ref><ref adv="1" source="Mozilla.org" url="http://bugzilla.mozilla.org/show_bug.cgi?id=257314">stack based buffer overflow with vcards when previewing email message</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html">TA04-261A</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-0904" published="2004-12-31" seq="2004-0904" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/847200">Mozilla contains integer overflows in bitmap image decoder</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11171">Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17381">Mozilla BMP buffer overflow</ref><ref adv="1" source="Mozilla" url="http://bugzilla.mozilla.org/show_bug.cgi?id=255067">BMP integer overflow exploits</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html">TA04-261A</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="Navigator" vendor="Netscape"><vers num="7.0"/><vers num="7.0.2"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-0905" published="2004-09-14" seq="2004-0905" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possible execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref adv="1" patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=250862">http://bugzilla.mozilla.org/show_bug.cgi?id=250862</ref><ref adv="1" source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref adv="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html">TA04-261A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/651928">VU#651928</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11177">11177</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17374">mozilla-netscape-sameorigin-bypass(17374)</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="Navigator" vendor="Netscape"><vers num="7.2"/><vers num="7.1"/><vers num="7.0.2"/><vers num="7.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0906" published="2004-12-31" seq="2004-0906" severity="Medium" type="CVE"><desc><descript source="cve">The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=235781">http://bugzilla.mozilla.org/show_bug.cgi?id=235781</ref><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=231083">http://bugzilla.mozilla.org/show_bug.cgi?id=231083</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/653160">VU#653160</ref><ref source="BID" url="http://www.securityfocus.com/bid/11192">11192</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17375">mozilla-insecure-file-permissions(17375)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12526/">12526</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0907" published="2004-12-31" seq="2004-0907" severity="Medium" type="CVE"><desc><descript source="cve">The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=254303">http://bugzilla.mozilla.org/show_bug.cgi?id=254303</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17373">mozilla-tar-insecure-permissions(17373)</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0908" published="2004-12-31" seq="2004-0908" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=257523">http://bugzilla.mozilla.org/show_bug.cgi?id=257523</ref><ref patch="1" source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/460528">VU#460528</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11179">11179</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12526">12526</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17376">mozilla-shortcut-clipboard-access(17376)</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0909" published="2004-12-31" seq="2004-0909" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=253942">http://bugzilla.mozilla.org/show_bug.cgi?id=253942</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-26.xml">GLSA-200409-26</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2">SSRT4826</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html">SUSE-SA:2004:036</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/113192">VU#113192</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12526">12526</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17377">mozilla-enableprivilege-modify-dialog(17377)</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0910" published="2004-11-03" reject="1" seq="2004-0910" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0815.  Reason: This candidate is a reservation duplicate of CVE-2004-0815.  Notes: All CVE users should reference CVE-2004-0815 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0911" published="2004-11-03" seq="2004-0911" severity="Medium" type="CVE"><desc><descript source="cve">telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/375743">Debian netkit telnetd vulnerability</ref><ref adv="1" patch="1" source="debian" url="http://www.debian.org/security/2004/dsa-556">DSA-556-2 netkit-telnet -- invalid free(3)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17540">Netkit telnetd implementation buffer overflow</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=273694">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=273694</ref></refs><vuln_soft><prod name="netkit" vendor="Debian"><vers num="0.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0913" published="2004-12-31" seq="2004-0913" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-572">DSA-572</ref><ref patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4491">ESB-2004.0669</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11487">11487</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12918/">12918</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17809">ecartis-gain-privileges(17809)</ref></refs><vuln_soft><prod name="Ecartis" vendor="Ecartis"><vers num="1.0.0 snapshot 2003-04-17"/><vers num="1.0.0 snapshot 2003-04-16"/><vers num="1.0.0 snapshot 2003-03-18"/><vers num="1.0.0 snapshot 2003-03-12"/><vers num="1.0.0 snapshot 2003-03-09"/><vers num="1.0.0 snapshot 2003-03-03"/><vers num="1.0.0 snapshot 2003-02-27"/><vers num="1.0.0 snapshot 2002-10-13"/><vers num="1.0.0 snapshot 2002-05-14"/><vers num="1.0.0 snapshot 2002-04-27"/><vers num="1.0.0 snapshot 2002-01-25"/><vers num="1.0.0 snapshot 2002-01-21"/><vers num="0.129a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0914" published="2005-01-10" seq="2004-0914" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE&apos;s content decisions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11694">LibXPM Multiple Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18147">libXpm denial of service</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-607">DSA-607-1 xfree86 -- several vulnerabilities</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-28.xml">X.Org, XFree86: libXpm vulnerabilities</ref><ref source="CONFIRM" url="http://www.x.org/pub/X11R6.8.1/patches/README.xorg-681-CAN-2004-0914.patch">http://www.x.org/pub/X11R6.8.1/patches/README.xorg-681-CAN-2004-0914.patch</ref><ref source="FEDORA" url="http://www.linuxsecurity.com/content/view/106877/102/">FEDORA-2004-433</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-06.xml">GLSA-200502-06</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml">GLSA-200502-07</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:137">MDKSA-2004:137</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-537.html">RHSA-2004:537</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-004.html">RHSA-2005:004</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110859653219899&amp;w=2">20050216 [USN-83-1] LessTif 2 vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13224/">13224</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18142">libxpm-image-bo(18142):</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18144">libxpm-improper-memory-access(18144):</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18145">libxpm-command-execution(18145):</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18146">libxpm-directory-traversal(18146):</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-83-1">USN-83-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-83-2">USN-83-2</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTU01228">HPSBTU01228</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html">FLSA-2006:152803</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-610.html">RHSA-2004:610</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:137">MDKSA-2004:137</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Lesstif" vendor="Lesstif"><vers num="0.93"/><vers num="0.93.12"/><vers num="0.93.18"/><vers num="0.93.34"/><vers num="0.93.36"/><vers num="0.93.40"/><vers num="0.93.91"/><vers num="0.93.94"/><vers num="0.93.96"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.7.0"/><vers num="6.8"/><vers num="6.8.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="3.3"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="3.3.4"/><vers num="3.3.5"/><vers num="3.3.6"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2.11"/><vers num="4.0.3"/><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0915" published="2005-01-10" seq="2004-0915" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11819">ViewCVS Multiple Information Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18369">ViewCVS repository weak security</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-605">DSA-605-1 viewcvs -- settings not honored</ref></refs><vuln_soft><prod name="ViewCVS" vendor="ViewCVS"><vers num="0.9.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0916" published="2005-01-27" seq="2004-0916" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-574">DSA-574-1 cabextract -- missing directory sanitising</ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/12882/">cabextract Directory Traversal Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11460">Cabextract Remote Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17766">cabextract directory traversal</ref><ref source="CONFIRM" url="http://www.kyz.uklinux.net/cabextract.php#changes">http://www.kyz.uklinux.net/cabextract.php#changes</ref></refs><vuln_soft><prod name="cabextract" vendor="cabextract"><vers num="0.2"/><vers num="0.6"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0917" published="2005-01-27" seq="2004-0917" severity="Medium" type="CVE"><desc><descript source="cve">The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="atstake.com" url="http://www.atstake.com/research/advisories/2004/a092804-1.txt">Vignette Application Portal Unauthenticated Diagnostics</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11267">Vignette Application Portal Remote Information Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17530">Vignette Application Portal diagnostic utility obtain information</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011447">1011447</ref></refs><vuln_soft><prod name="Application Portal" vendor="Vignette"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-07-17" name="CVE-2004-0918" published="2005-01-27" seq="2004-0918" severity="Medium" type="CVE"><desc><descript source="cve">The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-591.html">Updated squid package fixes vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17688">Squid Web Proxy Cache SNMP asn_parse_header denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11385">Squid Proxy SNMP ASN.1 Parser Denial Of Service Vulnerability</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-15.xml">GLSA-200410-15</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt">SCOSA-2005.16</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109913064629327&amp;w=2">20041029 [OpenPKG-SA-2004.048] OpenPKG Security Advisory (squid)</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=152&amp;type=vulnerabilities&amp;flashstatus=false">20041011 Squid Web Proxy Cache Remote Denial of Service Vulnerability</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00122.html">FEDORA-2008-6045</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html">SUSE-SR:2008:014</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30914">30914</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30967">30967</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Squid" vendor="Squid"><vers num="2.0 PATCH2"/><vers num="2.1 PATCH2"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="3.0 PRE3"/><vers num="3.0 PRE2"/><vers num="3.0 PRE1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0919" published="2004-12-31" seq="2004-0919" severity="Medium" type="CVE"><desc><descript source="cve">The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:15.syscons.asc">FreeBSD-SA-04:15</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/969078">VU#969078</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11321">11321</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12722">12722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17584">syscons-consscrshot-info-disclosure(17584)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0920" published="2004-11-03" seq="2004-0920" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17603">Symantec Norton AntiVirus device name bypass security</ref><ref source="MISC" url="http://www.seifried.org/security/advisories/kssa-010.html">http://www.seifried.org/security/advisories/kssa-010.html</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=147&amp;type=vulnerabilities">20041005 Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability</ref></refs><vuln_soft><prod name="Norton AntiVirus" vendor="Symantec"><vers edition="MS Exchange" num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0921" published="2005-01-27" seq="2004-0921" severity="High" type="CVE"><desc><descript source="cve">AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to &quot;terminate authenticated user mounts&quot; via modified SessionDestroy packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11322">Apple Mac OS X Multiple Security Vulnerabilities</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Quicktime" vendor="Apple"><vers num="6.0"/><vers num="5.0.2"/><vers num="6.1"/><vers num="6.5"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0922" published="2005-01-27" seq="2004-0922" severity="Medium" type="CVE"><desc><descript source="cve">AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11322">Apple Mac OS X Multiple Security Vulnerabilities</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Quicktime" vendor="Apple"><vers num="6.0"/><vers num="5.0.2"/><vers num="6.1"/><vers num="6.5"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0923" published="2005-01-27" seq="2004-0923" severity="Low" type="CVE"><desc><descript source="cve">CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/557062">CUPS stores user account details in plain text in log file</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17593">CUPS disclose passwords in log files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11324">CUPS Error_Log Local Password Disclosure Vulnerability</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-543.html">Updated CUPS packages fix security issues</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-566">DSA-566</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:116">MDKSA-2004:116</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-002.shtml">P-002</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:116">MDKSA-2004:116</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0924" published="2005-01-27" seq="2004-0924" severity="Medium" type="CVE"><desc><descript source="cve">NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11322">Apple Mac OS X Multiple Security Vulnerabilities</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0925" published="2005-01-27" seq="2004-0925" severity="Medium" type="CVE"><desc><descript source="cve">Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11323">Apple Mac OS X Postfix Release SMTPD AUTH Username Denial Of Service Vulnerability</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0926" published="2005-01-27" seq="2004-0926" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11322">Apple Mac OS X Multiple Security Vulnerabilities</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html">APPLE-SA-2004-10-27</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0927" published="2005-01-27" seq="2004-0927" severity="Medium" type="CVE"><desc><descript source="cve">ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html">APPLE-SA-2004-09-30 Security Update 2004-09-30</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/11322">Apple Mac OS X Multiple Security Vulnerabilities</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-2004-0928" published="2004-10-05" seq="2004-0928" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in &quot;;.cfm&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=148&amp;type=vulnerabilities">20041005 ColdFusion MX 6.1 on IIS File Contents Disclosure</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2">20040923 New Macromedia Security Zone Bulletins Posted</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/977440">VU#977440</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11245">11245</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12638/">12638</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12647/">12647</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17484">coldfusion-jrun-restriction-bypass(17484)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="J2EE 6.1"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Cosminexus Server" vendor="Hitachi"><vers num="Web 01-01_2"/><vers num="Web 01-01_1"/></prod><prod name="Cosminexus Enterprise" vendor="Hitachi"><vers edition="Standard" num="01_02_2"/><vers edition="Standard" num="01_01_1"/><vers edition="Enterprise" num="01_02_2"/><vers edition="Enterprise" num="01_01_1"/></prod><prod name="JRun" vendor="Macromedia"><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0929" published="2005-01-27" seq="2004-0929" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=154&amp;type=vulnerabilities">Novell SuSe Linux LibTIFF Heap Overflow Vulnerability</ref><ref adv="1" source="Suse" url="http://www.suse.de/de/security/2004_38_libtiff.html">Online Security Support</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17843">LibTIFF OJPEGVSetField heap overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11506">LibTIFF OJPEG Heap Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/129910">VU#129910</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html">SUSE-SA:2004:038</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="LibTIFF" vendor="LibTIFF"><vers num="3.6.1"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0930" published="2005-01-27" seq="2004-0930" severity="Medium" type="CVE"><desc><descript source="cve">The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=156&amp;type=vulnerabilities&amp;flashstatus=false">Samba SMBD Remote Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11624">Samba Remote Wild Card Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17987">Samba ms_fnmatch denial of service</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200411-21.xml">GLSA 200411-21</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:131">MDKSA-2004:131</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt">SCOSA-2005.17</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P">20041201-01-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_40_samba.html">SUSE-SA:2004:040</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109993720717957&amp;w=2">20041108 [SECURITY] CAN-2004-0930: Potential Remote Denial of Service Vulnerability</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000899">CLA-2004:899</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110022719024619&amp;w=2">USN-22-1</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330519803655&amp;w=2">OpenPKG-SA-2004.054</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101783-1">101783</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:131">MDKSA-2004:131</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="samba_irix" vendor="SGI"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0.0"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0931" published="2004-12-31" seq="2004-0931" severity="Medium" type="CVE"><desc><descript source="cve">MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=150&amp;type=vulnerabilities&amp;flashstatus=false">20041006 MySQL MaxDB Web Agent WebDBMServer Name Denial of Service Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11346">11346</ref><ref source="OSVDB" url="http://www.osvdb.org/10532">10532</ref><ref patch="1" source="SECUNIA" url="http://www.secunia.com/advisories/12756">12756</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17633">maxdb-isascii7dos(17633)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=150&amp;type=vulnerabilities&amp;flashstatus=false">20041006 MySQL MaxDB Web Agent WebDBMServer Name Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0932" published="2005-01-27" seq="2004-0932" severity="High" type="CVE"><desc><descript source="cve">McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0933" published="2005-01-27" seq="2004-0933" severity="High" type="CVE"><desc><descript source="cve">Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp">http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0934" published="2005-01-27" seq="2004-0934" severity="High" type="CVE"><desc><descript source="cve">Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/968818">VU#968818</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0935" published="2005-01-27" seq="2004-0935" severity="High" type="CVE"><desc><descript source="cve">Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/968818">VU#968818</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0936" published="2005-01-27" seq="2004-0936" severity="High" type="CVE"><desc><descript source="cve">RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/968818">VU#968818</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-0937" published="2005-02-09" seq="2004-0937" severity="High" type="CVE"><desc><descript source="cve">Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/968818">VU#968818</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref></refs><vuln_soft><prod name="Archive_Zip" vendor="Archive_Zip"><vers num="1.13"/></prod><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0938" published="2004-11-03" seq="2004-0938" severity="Medium" type="CVE"><desc><descript source="cve">FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="www.gentoo.org" url="http://security.gentoo.org/glsa/glsa-200409-29.xml">FreeRADIUS: Multiple Denial of Service vulnerabilities</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/541574">freeRADIUS Server vulnerable to a denial-of-service attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11222">FreeRADIUS Multiple Attribute Decoding Denial Of Service Vulnerabilities</ref><ref adv="1" patch="1" source="www.osvdb.org" url="http://www.osvdb.org/10178">10178</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17440">FreeRADIUS denial of service</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1347.html">OVAL1347</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1347">oval:org.mitre.oval:def:1347</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0939" published="2005-02-09" seq="2004-0939" severity="Medium" type="CVE"><desc><descript source="cve">changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17629">Juniper Networks NetScreen password brute force</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109709990708794&amp;w=2"> [GoSecure Advisory] Neoteris IVE Vulnerability</ref><ref source="MISC" url="http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt">http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt</ref><ref source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1011552.html">http://securitytracker.com/alerts/2004/Oct/1011552.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011552">1011552</ref><ref source="OSVDB" url="http://www.osvdb.org/8365">8365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12752">12752</ref></refs><vuln_soft><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2004-0940" published="2005-02-09" seq="2004-0940" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17785">Apache mod_include module buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11471">Apache mod_include Local Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109906660225051&amp;w=2">  [OpenPKG-SA-2004.047] OpenPKG Security Advisory (apache)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-594">DSA-594</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:134">MDKSA-2004:134</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-600.html">RHSA-2004:600</ref><ref source="CONFIRM" url="http://www.apacheweek.com/features/security-13">http://www.apacheweek.com/features/security-13</ref><ref source="MISC" url="http://securitytracker.com/id?1011783">http://securitytracker.com/id?1011783</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12898/">12898</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1">102197</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19073">19073</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:134">MDKSA-2004:134</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.6"/><vers edition="Dev" num="1.3.7"/><vers num="1.3.9"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.14"/><vers num="1.3.17"/><vers num="1.3.18"/><vers num="1.3.19"/><vers num="1.3.20"/><vers num="1.3.22"/><vers num="1.3.23"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.26"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.3.29"/><vers num="1.3.31"/><vers num="1.3.32"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.00"/><vers num="11.0"/><vers num="11.11"/><vers num="11.20"/><vers num="11.22"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="current"/><vers num="8.0"/><vers num="8.1"/><vers num="9.0"/><vers num="9.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0941" published="2005-02-09" seq="2004-0941" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Trustix" url="http://www.trustix.org/errata/2004/0058">Trustix Secure Linux Security Advisory #2004-0058</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11663">GD Graphics Library Multiple Unspecified Remote Buffer overflow Vulnerabilities</ref><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2004/Nov/0203.html">20041115 [USN-25-1] libgd2 vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13179/">13179</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1195.html">OVAL1195</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0194.html">RHSA-2006:0194</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18686">18686</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:113">MDKSA-2006:113</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:114">MDKSA-2006:114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20824">20824</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21050">21050</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1195">oval:org.mitre.oval:def:1195</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-601">DSA-601</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-638.html">RHSA-2004:638</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-071.shtml">P-071</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:113">MDKSA-2006:113</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:114">MDKSA-2006:114</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-33-1">USN-33-1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18048">gd-graphics-gdmalloc-bo(18048)</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="gdlib" vendor="GD Graphics Library"><vers num="1.8.4"/><vers num="2.0.1"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="2.0.28"/><vers num="2.0.33"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0942" published="2005-02-09" seq="2004-0942" severity="Medium" type="CVE"><desc><descript source="cve">Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17930">Apache HTTP Server HTTP GET request denial of service</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:135">Updated apache2 packages fix request DoS</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028248.html">20041101 DoS in Apache 2.0.52 ?</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384374213596&amp;w=2">SSRT4876</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01123">HPSBUX01123</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0061/">2004-0061</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-562.html">RHSA-2004:562</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:135">MDKSA-2004:135</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.52" prev="1"/></prod></vuln_soft></entry><entry modified="2005-10-27" name="CVE-2004-0943" published="2004-12-31" reject="1" seq="2004-0943" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0944" published="2004-02-28" seq="2004-0944" severity="Medium" type="CVE"><desc><descript source="cve">The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.corsaire.com/advisories/c040817-002.txt">http://www.corsaire.com/advisories/c040817-002.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mitel.com/DocController?documentId=14223">http://www.mitel.com/DocController?documentId=14223</ref><ref adv="1" patch="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</ref></refs><vuln_soft><prod name="Mitel 3300 Integrated Communication Platform" vendor="Mitel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0945" published="2005-02-28" seq="2004-0945" severity="Medium" type="CVE"><desc><descript source="cve">The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP&apos;s maximum.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.corsaire.com/advisories/c040817-003.txt">http://www.corsaire.com/advisories/c040817-003.txt</ref><ref adv="1" source="CONFIRM" url="http://www.mitel.com/DocController?documentId=14223">http://www.mitel.com/DocController?documentId=14223</ref><ref adv="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</ref></refs><vuln_soft><prod name="Mitel 3300 Integrated Communication Platform" vendor="Mitel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0946" published="2005-01-10" seq="2004-0946" severity="High" type="CVE"><desc><descript source="cve">rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18455">nfs-utils getquotainfo function buffer overflow</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-583.html">Updated nfs-utils package fixes security vulnerabilities</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200412-08.xml">nfs-utils: Multiple remote vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11911">Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:005">MDKSA-2005:005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-014.html">RHSA-2005:014</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=72113">http://bugs.gentoo.org/show_bug.cgi?id=72113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698302">VU#698302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13440/">13440</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426072/30/6740/threaded">

FLSA-2006:138098</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:005">MDKSA-2005:005</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="nfs-utils" vendor="nfs"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.6"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0947" published="2005-02-09" seq="2004-0947" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11665">ARJ Software UNARJ Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18044">unarj file name buffer overflow</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-29.xml">unarj: Long filenames buffer overflow and a path traversal vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-652">DSA-652</ref><ref source="FEDORA" url="http://lwn.net/Articles/121827/">FLSA:2272</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-007.html">RHSA-2005:007</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="UNARJ" vendor="ARJ Software Inc."><vers num="2.62"/><vers num="2.63 a"/><vers num="2.64"/><vers num="2.65"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0948" published="2004-12-31" reject="1" seq="2004-0948" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  It was a duplicate assignment before public disclosure.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0949" published="2005-01-10" seq="2004-0949" severity="Medium" type="CVE"><desc><descript source="cve">The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11695">Linux Kernel SMBFS Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110072140811965&amp;w=2">Advisory 14/2004: Linux 2.x smbfs multiple remote vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18137">Linux kernel smb_recv_trans2 memory leak</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">Updated openmotif packages fix image vulnerability</ref><ref source="MISC" url="http://security.e-matters.de/advisories/142004.html">http://security.e-matters.de/advisories/142004.html</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0061/">2004-0061</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13232/">13232</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082989725345&amp;w=2">USN-30-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0950" published="2005-02-09" seq="2004-0950" severity="Medium" type="CVE"><desc><descript source="cve">NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a &quot;custom&quot; HELO request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11710">Danware NetOp Remote Control Information Disclosure Vulnerability</ref><ref adv="1" source="Corsaire" url="http://www.corsaire.com/advisories/c040619-001.txt">Danware NetOp Host multiple information disclosure issues</ref><ref source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0411/213.html">20041119 Corsaire Security Advisory - Danware NetOp Host multiple information disclosure issues</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18171">danware-helo-obtain-information(18171)</ref></refs><vuln_soft><prod name="NetOp" vendor="Danware Data"><vers num="6.0"/><vers num="6.50"/><vers num="7.0.1 build2002-01-29"/><vers num="7.50 build2003-08-04"/><vers num="7.60 build2003-06-24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0951" published="2004-12-31" seq="2004-0951" severity="High" type="CVE"><desc><descript source="cve">The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CORSAIRE" url="http://www.corsaire.com/advisories/c041123-001.txt">http://www.corsaire.com/advisories/c041123-001.txt</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16456/">16456</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21858">hpigniteux-makerecovery-bypass-security(21858)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14568">14568</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014711">1014711</ref></refs><vuln_soft><prod name="Ignite-UX" vendor="HP"><vers num="C.6.2.241"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0952" published="2004-12-31" seq="2004-0952" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112420609211136&amp;w=2">20050816 Corsaire Security Advisory: HP Ignite-UX filesystem permissions issue</ref><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112422597529112&amp;w=2">HPSBUX01219</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16456/">16456</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21857">hpigniteux-addnewclient-gain-access(21857)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014711">1014711</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.11"/><vers num="B.11.22"/><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0953" published="2005-01-10" seq="2004-0953" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11741">Jabber Server Multiple Remote Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18238">Jabberd2 C2S module buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110144303826709&amp;w=2">Jabberd2.x remote BuffJabberd2.x remote Buffer Overflowser Overflows</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029346.html">20041124 Jabberd2.x remote BuffJabberd2.x remote Buffer Overflowser Overflows</ref></refs><vuln_soft><prod name="Jabber Server" vendor="Jabber Software Foundation"><vers num="2.0"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0954" published="2004-12-23" reject="1" seq="2004-0954" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0597.  Reason: This candidate is a reservation duplicate of CVE-2004-0597.  Notes: All CVE users should reference CVE-2004-0597 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry modified="2005-10-28" name="CVE-2004-0955" published="2004-12-23" reject="1" seq="2004-0955" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0599.  Reason: This candidate is a reservation duplicate of CVE-2004-0599 (the first item listed in that candidate).  Notes: All CVE users should reference CVE-2004-0599 instead of this candidate.  All references and descriptions have been removed from this candidate to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0956" published="2005-01-10" seq="2004-0956" severity="Medium" type="CVE"><desc><descript source="cve">MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11432">MySQL Remote FULLTEXT Search Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17768">MySQL MATCH ... AGAINST SQL statement denial of service</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml">MySQL: Multiple vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.mysql.com/bug.php?id=3870">http://bugs.mysql.com/bug.php?id=3870</ref><ref source="CONFIRM" url="http://lists.mysql.com/packagers/202">http://lists.mysql.com/packagers/202</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_01_sr.html">SUSE-SR:2004:001</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0054/">2004-0054</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.0.14"/><vers num="4.0.15"/><vers num="4.0.18"/><vers num="4.0.20"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0957" published="2005-02-09" seq="2004-0957" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a &quot;_&quot; (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11435">MySQL Database Unauthorized GRANT Privilege Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17783">MySQL underscore allows elevated privileges</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947">CLA-2005:947</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-707">DSA-707</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:070">MDKSA-2005:070</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-597.html">RHSA-2004:597</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-611.html">RHSA-2004:611</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2">20041125 [USN-32-1] mysql vulnerabilities</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-018.shtml">P-018</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:070">MDKSA-2005:070</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="MySQL" vendor="MySQL"><vers num="3.20"/><vers num="3.20.32a"/><vers num="3.21"/><vers num="3.22"/><vers num="3.22.26"/><vers num="3.22.27"/><vers num="3.22.28"/><vers num="3.22.29"/><vers num="3.22.30"/><vers num="3.22.32"/><vers num="3.23"/><vers num="3.23.2"/><vers num="3.23.3"/><vers num="3.23.4"/><vers num="3.23.5"/><vers num="3.23.8"/><vers num="3.23.9"/><vers num="3.23.10"/><vers num="3.23.22"/><vers num="3.23.23"/><vers num="3.23.24"/><vers num="3.23.25"/><vers num="3.23.26"/><vers num="3.23.27"/><vers num="3.23.28 gamma"/><vers num="3.23.28"/><vers num="3.23.29"/><vers num="3.23.30"/><vers num="3.23.31"/><vers num="3.23.32"/><vers num="3.23.33"/><vers num="3.23.34"/><vers num="3.23.36"/><vers num="3.23.37"/><vers num="3.23.38"/><vers num="3.23.39"/><vers num="3.23.40"/><vers num="3.23.41"/><vers num="3.23.42"/><vers num="3.23.43"/><vers num="3.23.44"/><vers num="3.23.45"/><vers num="3.23.46"/><vers num="3.23.47"/><vers num="3.23.48"/><vers num="3.23.49"/><vers num="3.23.50"/><vers num="3.23.51"/><vers num="3.23.52"/><vers num="3.23.53a"/><vers num="3.23.53"/><vers num="3.23.54a"/><vers num="3.23.54"/><vers num="3.23.55"/><vers num="3.23.56"/><vers num="3.23.58"/><vers num="3.23.59"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.0.14"/><vers num="4.0.15"/><vers num="4.0.18"/><vers num="4.0.20"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0958" published="2004-11-03" seq="2004-0958" severity="Medium" type="CVE"><desc><descript source="cve">php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17393">PHP phpinfo discloses memory contents</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-687.html">Updated php packages fix security issues and bugs</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html">20040915 [VulnWatch] PHP Vulnerability N. 1</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011279.html">http://www.securitytracker.com/alerts/2004/Sep/1011279.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12560/">12560</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011279">1011279</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109527531130492&amp;w=2">20040915 PHP Vulnerability N. 1</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0959" published="2004-11-03" seq="2004-0959" severity="Low" type="CVE"><desc><descript source="cve">rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the &quot;$_FILES&quot; array to be modified.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011307.html">http://www.securitytracker.com/alerts/2004/Sep/1011307.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12560/">12560</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011307">1011307</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17392">PHP MIME array execute code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-687.html">Updated php packages fix security issues and bugs</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0054.html">20040915 Php Vulnerability N. 2</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109534848430404&amp;w=2">20040915 Php Vulnerability N. 2</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0960" published="2005-02-09" seq="2004-0960" severity="Medium" type="CVE"><desc><descript source="cve">FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11222">FreeRADIUS Multiple Attribute Decoding Denial Of Service Vulnerabilities</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/541574">freeRADIUS Server vulnerable to a denial-of-service attack</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17440">FreeRADIUS denial of service</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-29.xml">GLSA-200409-29</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.8"/><vers num="0.8.1"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="1.0.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0961" published="2005-02-09" seq="2004-0961" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11222">FreeRADIUS Multiple Attribute Decoding Denial Of Service Vulnerabilities</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/541574">freeRADIUS Server vulnerable to a denial-of-service attack</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17440">FreeRADIUS denial of service</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200409-29.xml">GLSA-200409-29</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.8"/><vers num="0.8.1"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="1.0.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0962" published="2005-02-09" seq="2004-0962" severity="High" type="CVE"><desc><descript source="cve">Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11554">Apple Remote Desktop Administrator Privilege Escalation Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00002.html">APPLE-SA-2004-10-27</ref></refs><vuln_soft><prod name="Remote Desktop" vendor="Apple"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0963" published="2005-02-09" seq="2004-0963" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17635">Microsoft Word improper file parsing buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716247230733&amp;w=2"> [HV-HIGH] MS Word multiple exceptions, at least one exploitable</ref><ref source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-023.mspx">MS05-023</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1795.html">OVAL1795</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2105.html">OVAL2105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2216.html">OVAL2216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval420.html">OVAL420</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1795">oval:org.mitre.oval:def:1795</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2105">oval:org.mitre.oval:def:2105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2216">oval:org.mitre.oval:def:2216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:420">oval:org.mitre.oval:def:420</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2002 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0964" published="2005-02-09" seq="2004-0964" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11248">Zinf Malformed Playlist File Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17491">Zinf .pls playlist file buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109638486728548&amp;w=2"> Re: Buffer overflow in Zinf 2.2.1 for Win32+exploit</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-587">DSA-587-1 freeamp -- buffer overflow</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12656">12656</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109608092609200&amp;w=2">20040924 Buffer overflow in Zinf 2.2.1 for Win32</ref></refs><vuln_soft><prod name="Zinf" vendor="Zinf"><vers num="2.2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0965" published="2005-02-09" seq="2004-0965" severity="High" type="CVE"><desc><descript source="cve">stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17813">HP-UX stmkfont allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11493">HP-UX STMKFONT Local Privilege Escalation Vulnerability</ref><ref source="MISC" url="http://www.nsfocus.com/english/homepage/research/0402.htm">http://www.nsfocus.com/english/homepage/research/0402.htm</ref><ref source="HP" url="http://www.securityfocus.com/advisories/7351">SSRT4807</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109837243713696&amp;w=2">20041021 NSFOCUS SA2004-02 : HP-UX stmkfont Local Privilege Escalation Vulnerability</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0966" published="2005-02-09" seq="2004-0966" severity="Low" type="CVE"><desc><descript source="cve">The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11282">GNU GetText Unspecified Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-10.xml">GLSA-200410-10</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00000.html">FLSA:136323</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:051">MDKSA-2006:051</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899973325734&amp;w=2">USN-5-1</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382652226638&amp;w=2">OpenPKG-SA-2004.055</ref></refs><vuln_soft><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ia64 ppc" num="4.1"/><vers edition="ia64 ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="gettext" vendor="GNU"><vers num="0.14.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0967" published="2005-02-09" seq="2004-0967" severity="High" type="CVE"><desc><descript source="cve">The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11285">GhostScript Insecure Temporary File Creation Vulnerability</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136321">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136321</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-081.html">RHSA-2005:081</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16997">16997</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900135814990&amp;w=2">USN-3-1</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.23/SCOSA-2006.23.txt">SCOSA-2006.23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20056">20056</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.19/SCOSA-2006.19.txt">SCOSA-2006.19</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19799">19799</ref></refs><vuln_soft><prod name="Ghostscript" vendor="Aladdin Enterprises"><vers num="4.3"/><vers num="4.3.2"/><vers num="5.10cl"/><vers edition="mdk" num="5.10.10_1"/><vers num="5.10.10_1"/><vers edition="mdk" num="5.10.10"/><vers num="5.10.10"/><vers num="5.10.12cl"/><vers num="5.10.15"/><vers num="5.10.16"/><vers num="5.50"/><vers num="5.50.8_7"/><vers num="5.50.8"/><vers num="6.51"/><vers num="6.52"/><vers num="6.53"/><vers num="7.0.7"/><vers num="7.0.6"/><vers num="7.0.5"/><vers num="7.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0968" published="2005-02-09" seq="2004-0968" severity="Low" type="CVE"><desc><descript source="cve">The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11286">GNU GLibC Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-636">DSA-636</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200410-19.xml">GLSA-200410-19</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-586.html">RHSA-2004:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-261.html">RHSA-2005:261</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899903129801&amp;w=2">USN-4-1</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="glibc" vendor="Gnu"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.1"/><vers num="2.1.1.6"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3.10"/><vers num="2.1.3"/><vers num="2.1.9"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.10"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0969" published="2005-02-09" seq="2004-0969" severity="Low" type="CVE"><desc><descript source="cve">The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11287">GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml">OpenSSL, Groff: Insecure tempfile handling</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038">MDKSA-2006:038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18764">18764</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ia64 ppc" num="4.1"/><vers edition="ia64 ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="groff" vendor="GNU"><vers num="1.19"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0970" published="2005-02-09" seq="2004-0970" severity="Low" type="CVE"><desc><descript source="cve">The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files.  NOTE: the znew vulnerability may overlap CVE-2003-0367.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11288">GNU GZip Unspecified Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2004/dsa-588">DSA-588-1 gzip -- insecure temporary files</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="" url="http://www.zataz.net/adviso/ncompress-09052005.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/13131">13131</ref></refs><vuln_soft><prod name="Gzip" vendor="Gnu"><vers num="1.2.4a"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0971" published="2005-02-09" seq="2004-0971" severity="Low" type="CVE"><desc><descript source="cve">The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11289">MIT Kerberos 5 SEND-PR.SH Insecure Temporary File Creation Vulnerability</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200410-24.xml">MIT krb5: Insecure temporary file use in send-pr.sh</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-012.html">RHSA-2005:012</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136304">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136304</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0972" published="2005-02-09" seq="2004-0972" severity="Low" type="CVE"><desc><descript source="cve">The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11290">Trustix LVM Utilities Unspecified Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Trustix" url="http://www.trustix.org/errata/2004/0050">  Insecure tempfile handling</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136308">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136308</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHBA-2004-232.html">RHBA-2004:232</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Logical Volume Management Utilities" vendor="LVM"><vers num="1.0.1"/><vers num="1.0.4"/><vers num="1.0.7"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-0973" published="2004-12-23" reject="1" seq="2004-0973" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0457.  Reason: This candidate is a reservation duplicate of CVE-2004-0457.  Notes: All CVE users should reference CVE-2004-0457 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0974" published="2005-02-09" seq="2004-0974" severity="Low" type="CVE"><desc><descript source="cve">The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200410-25.xml">Netatalk: Insecure tempfile handling in etc2ps.sh</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11292">NetaTalk Unspecified Insecure Temporary File Creation Vulnerability</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Open Source Apple File Share Protocol Suite" vendor="Netatalk"><vers num="1.5 pre6"/><vers num="1.6.1"/><vers num="1.6.4"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0975" published="2005-02-09" seq="2004-0975" severity="Low" type="CVE"><desc><descript source="cve">The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11293">OpenSSL DER_CHOP Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-603">DSA-603</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml">GLSA-200411-15</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12973">12973</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval164.html">OVAL164</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-476.html">RHSA-2005:476</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:164">oval:org.mitre.oval:def:164</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6m"/><vers num="0.9.6l"/><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.6b"/><vers num="0.9.6a"/><vers num="0.9.6"/><vers num="0.9.7d"/><vers num="0.9.7c"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0976" published="2005-02-09" seq="2004-0976" severity="Low" type="CVE"><desc><descript source="cve">Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11294">Perl Unspecified Insecure Temporary File Creation Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-620">DSA-620</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-881.html">RHSA-2005:881</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18075">18075</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17661">17661</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547693019788&amp;w=2">OpenPKG-SA-2005.001</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.6"/><vers num="5.6.1"/><vers num="5.8.0"/><vers num="5.8.1"/><vers num="5.8.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0977" published="2005-02-09" seq="2004-0977" severity="Low" type="CVE"><desc><descript source="cve">The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17583">Multiple scripts temporary file overwrite</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11295">PostgreSQL Insecure Temporary File Creation Vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-577">DSA-577-1 postgresql -- insecure temporary file</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200410-16.xml">GLSA-200410-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:149">MDKSA-2004:149</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-489.html">RHSA-2004:489</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0050">2004-0050</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136300">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136300</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109902101714725&amp;w=2">USN-6-1</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109910073808903&amp;w=2">OpenPKG-SA-2004.046</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:149">MDKSA-2004:149</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.2.1"/><vers num="7.4.3"/><vers num="7.4.5"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0978" published="2005-02-09" seq="2004-0978" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17714">Heartbeat.ocx ActiveX control unknown vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/673134">Microsoft MSN &quot;Hrtbeat.ocx&quot; ActiveX control contains unspecified vulnerability</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/heartbeatfull.txt">http://www.ngssoftware.com/advisories/heartbeatfull.txt</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">MS04-038</ref><ref source="BID" url="http://www.securityfocus.com/bid/11367">11367</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616221411579&amp;w=2">20050119 MSN Heartbeat Control Buffer Overflow</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-0979" published="2004-12-31" seq="2004-0979" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer on Windows XP does not properly modify the &quot;Drag and Drop or copy and paste files&quot; setting when the user sets it to &quot;Disable&quot; or &quot;Prompt,&quot; which may enable security-sensitive operations that are inconsistent with the user&apos;s intended configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17820">Microsoft Internet Explorer bypass Drag and Drop or copy and paste files security setting</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/630720">Microsoft Internet Explorer fails to honor </ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11770">Microsoft Internet Explorer Drag and Drop Vulnerability</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx">MS04-038</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">TA04-293A</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0980" published="2005-02-09" seq="2004-0980" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11657">EZ-IPupdate Remote Format String Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18032">ez-ipupdate show_message format string</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-20.xml">ez-ipupdate: Format string vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028590.html">20041111 ez-ipupdate format string bug</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-592">DSA-592</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:129">MDKSA-2004:129</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13167/">13167</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:129">MDKSA-2004:129</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="ez-ipupdate" vendor="Angus Mackay"><vers num="3.0.11b8"/><vers num="3.0.11b5"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0981" published="2005-02-09" seq="2004-0981" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11548">ImageMagick Remote EXIF Parsing Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17903">ImageMagick EXIF image file buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900325831136&amp;w=2"> [USN-7-1] imagemagick vulnerability</ref><ref source="CONFIRM" url="http://www.imagemagick.org/www/Changelog.html">http://www.imagemagick.org/www/Changelog.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-11.xml">GLSA-200411-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12995/">12995</ref><ref source="BID" url="http://www.securityfocus.org/bid/11548">11548</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.3.3"/><vers num="5.4.3"/><vers num="5.4.4.5"/><vers num="5.4.7"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.5.3.2.1.2.0"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.7"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0982" published="2005-02-09" seq="2004-0982" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11468">MPG123 Remote URL Open Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17574">mpg123 getauthfromurl buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-578">DSA-578-1 mpg123 -- buffer overflow</ref><ref source="" url="http://www.barrossecurity.com/advisories/mpg123_getauthfromurl_bof_advisory.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-27.xml">GLSA-200410-27</ref><ref source="OSVDB" url="http://www.osvdb.org/11023">11023</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011832">1011832</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12908">12908</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109834486312407&amp;w=2">20041019 mpg123 &quot;getauthfromurl&quot; buffer overflow</ref></refs><vuln_soft><prod name="mpg123" vendor="mpg123"><vers num="pre0.59s"/><vers num="0.59r"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0983" published="2005-03-01" seq="2004-0983" severity="Medium" type="CVE"><desc><descript source="cve">The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11618">Yukihiro Matsumoto Ruby CGI Module Unspecified Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17985">Ruby CGI module denial of service</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-586">DSA-586</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:128">MDKSA-2004:128</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-635.html">RHSA-2004:635</ref><ref source="MISC" url="http://www.ubuntulinux.org/support/documentation/usn/usn-20-1">http://www.ubuntulinux.org/support/documentation/usn/usn-20-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:128">MDKSA-2004:128</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Ruby" vendor="Yukihiro Matsumoto"><vers num="1.6"/><vers num="1.6.7"/><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2 pre2"/><vers num="1.8.2 pre1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2004-0984" published="2004-12-31" seq="2004-0984" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/m/mailutils/mailutils_0.6-2/changelog">http://packages.debian.org/changelogs/pool/main/m/mailutils/mailutils_0.6-2/changelog</ref><ref source="Debian" url="http://packages.debian.org/changelogs/pool/main/m/mailutils/mailutils_0.6.1-4/changelog">mailutils (1:0.5-4) unstable; urgency=HIGH</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="1.0.5.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-0985" published="2004-12-31" seq="2004-0985" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17824">Microsoft Internet Explorer AnchorClick command execution</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109828076802478&amp;w=2">  How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109828076802478&amp;w=2">20041020 How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109830296130857&amp;w=2">20041020 How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829111200055&amp;w=2">20041020 Re: How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0986" published="2005-03-01" seq="2004-0986" severity="High" type="CVE"><desc><descript source="cve">Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17928">iptables module initialization denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11570">Linux Kernel IPTables Initialization Failure Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-580">DSA-580</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2252">FLSA:2252</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:125">MDKSA-2004:125</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-026.shtml">P-026</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815247703862&amp;w=2">USN-81-1</ref><ref source="" url="http://rpmfind.net/linux/RPM/suse/updates/9.2/i386/rpm/i586/iptables-1.2.11-4.2.i586.html"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:125">MDKSA-2004:125</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.2"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="SuSE IPTables" vendor="SuSE"><vers num="1.2.11"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0987" published="2005-01-10" seq="2004-0987" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11753">Yard Radius Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18270">YardRadius process_menu function buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-598">DSA-598-1 yardradius -- buffer overflow</ref><ref source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278384">278384: yardradius: security vulnerability still present in stable</ref></refs><vuln_soft><prod name="Yard RADIUS" vendor="Yard RADIUS"><vers num="1.0 pre15"/><vers num="1.0 pre14"/><vers num="1.0 pre13"/><vers num="1.0.16"/><vers num="1.0.17"/><vers num="1.0.18"/><vers num="1.0.19"/><vers num="1.0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0988" published="2005-03-01" seq="2004-0988" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11553">Apple QuickTime Remote Integer Overflow Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html">APPLE-SA-2004-10-27</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="6.0"/><vers num="5.0.2"/><vers num="6.0.1"/><vers num="6.0.5"/><vers num="6.0.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0989" published="2005-03-01" seq="2004-0989" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11526">Libxml2 Multiple Remote Stack Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17870">Libxml2 xmlNanoFTPScanURL function of the nanoftp.c file buffer overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17875">Libxml2 xmlNanoFTPScanProxy function buffer overflow</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-582">DSA-582</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1173.html">OVAL1173</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880813013482&amp;w=2">20041026 libxml2 remote buffer overflows (not in xml parsing code though)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000890">CLA-2004:890</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972110516151&amp;w=2">USN-89-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-615.html">RHSA-2004:615</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-650.html">RHSA-2004:650</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1173">oval:org.mitre.oval:def:1173</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200411-05.xml">GLSA-200411-05</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-029.shtml">P-029</ref><ref source="OSVDB" url="http://www.osvdb.org/11179">11179</ref><ref source="OSVDB" url="http://www.osvdb.org/11180">11180</ref><ref source="OSVDB" url="http://www.osvdb.org/11324">11324</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011941">1011941</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13000">13000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17872">libxml2-nanoftp-file-bo(17872)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17876">libxml2-nanohttp-file-bo(17876)</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Libxml2" vendor="XMLSoft"><vers num="2.5.11"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers num="2.6.9"/><vers num="2.6.11"/><vers num="2.6.12"/><vers num="2.6.13"/><vers num="2.6.14"/></prod><prod name="Libxml" vendor="XMLSoft"><vers num="1.8.17"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Command Line XML Toolkit" vendor="XMLStarlet"><vers num="0.9.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0990" published="2005-03-01" seq="2004-0990" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/21050">21050</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1260">oval:org.mitre.oval:def:1260</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-638.html">RHSA-2004:638</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-071.shtml">P-071</ref><ref source="" url="https://issues.rpath.com/browse/RPL-939"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23783">23783</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:132">MDKSA-2004:132</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:113">MDKSA-2006:113</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:114">MDKSA-2006:114</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17866">GD Graphics Library PNG image integer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11523">GD Graphics Library Remote Integer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882489302099&amp;w=2"> libgd integer overflow</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-589">DSA-589</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-591">DSA-591</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-601">DSA-601</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-602">DSA-602</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:132">MDKSA-2004:132</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0058">2004-0058</ref><ref source="OSVDB" url="http://www.osvdb.org/11190">11190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1260.html">OVAL1260</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109907605501428&amp;w=2">USN-11-1</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110055781015402&amp;w=2">USN-25-1</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html">SUSE-SR:2006:003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18717">18717</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:113">MDKSA-2006:113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20866">20866</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:114">MDKSA-2006:114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20824">20824</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="gdlib" vendor="GD Graphics Library"><vers num="1.8.4"/><vers num="2.0.1"/><vers num="2.0.15"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="2.0.28"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0991" published="2005-01-11" seq="2004-0991" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-14.xml">GLSA-200501-14</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:009">MDKSA-2005:009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13779">13779</ref><ref source="BID" url="http://www.securityfocus.com/bid/12218">12218</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13788">13788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13899">13899</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:009">MDKSA-2005:009</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="mpg123" vendor="mpg123"><vers num="0.59s"/><vers num="0.59r"/><vers num="0.59q"/><vers num="0.59p"/><vers num="0.59o"/><vers num="0.59n"/><vers num="0.59m"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0992" published="2005-03-01" seq="2004-0992" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11592">Proxytunnel Remote Format String Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17945">proxytunnel message function in the message.c file format string</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-07.xml">Proxytunnel: Format string vulnerability</ref><ref source="CONFIRM" url="http://proxytunnel.sourceforge.net/news.html">http://proxytunnel.sourceforge.net/news.html</ref></refs><vuln_soft><prod name="proxytunnel" vendor="proxytunnel"><vers num="1.0.6"/><vers num="1.1.3"/><vers num="1.2 .0"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0993" published="2005-01-10" seq="2004-0993" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11800">HP HPSOCKD Unspecified Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18359">hpsockd buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-604">DSA-604-1 hpsockd -- missing input sanitising</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13371/">13371</ref></refs><vuln_soft><prod name="hpsockd" vendor="HP"><vers num="0.4"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0994" published="2005-01-10" seq="2004-0994" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297198402077&amp;w=2"> iDEFENSE Security Advisory 12.13.04 - Multiple Vendor xzgv PRF Parsing Integer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11556">ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities</ref><ref source="CONFIRM" url="http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff">http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-614">DSA-614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18454">xzgv-readprffile-bo(18454)</ref></refs><vuln_soft><prod name="xzgv Image Viewer" vendor="zgv"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="zgv Image Viewer" vendor="zgv"><vers num="5.5"/><vers num="5.6"/><vers num="5.7"/><vers num="5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0996" published="2005-01-10" seq="2004-0996" severity="Low" type="CVE"><desc><descript source="cve">main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11697">Cscope Insecure Temporary File Creation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18125">Cscope temporary file race condition</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-610">DSA-610-1 cscope -- insecure temporary file</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/381443">20041117 RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/381506">20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/381611">20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-11.xml">GLSA-200412-11</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110133485519690&amp;w=2">20041124 STG Security Advisory: [SSA-20041122-09] cscope insecure temp file creation vulnerability</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1.3"/><vers num="7.1.4"/></prod><prod name="Cscope" vendor="Cscope"><vers num="13.0"/><vers num="15.1"/><vers num="15.3"/><vers num="15.4"/><vers num="15.5"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-31" name="CVE-2004-0997" published="2004-12-31" seq="2004-0997" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.17</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref patch="1" source="DEBIAN" url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="" url="http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2004-0997?op=file&amp;rev=0&amp;sc=0"></ref><ref source="BID" url="http://www.securityfocus.com/bid/18176">18176</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4 .0-test9"/><vers num="2.4 .0-test8"/><vers num="2.4 .0-test7"/><vers num="2.4 .0-test6"/><vers num="2.4 .0-test5"/><vers num="2.4 .0-test4"/><vers num="2.4 .0-test3"/><vers num="2.4 .0-test2"/><vers num="2.4 .0-test12"/><vers num="2.4 .0-test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0998" published="2004-12-23" seq="2004-0998" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-616">DSA-616</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/995038">VU#995038</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13663">13663</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18654">netkit-telnetssl-format-string(18654)</ref></refs><vuln_soft><prod name="telnetd-ssl" vendor="telnetd"><vers edition="woody1" num="0.17.17_0.1.2"/><vers num="0.17.17_0.1.2"/><vers num="0.17.17_0.1.1"/></prod><prod name="telnetd" vendor="telnetd"><vers num="0.17.25"/><vers num="0.17.18"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0999" published="2004-12-31" seq="2004-0999" severity="Low" type="CVE"><desc><descript source="cve">zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-608">DSA-608</ref><ref patch="1" source="BID" url="http://securityfocus.com/bid/11915">11915</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18480">zgv-multiple-image-dos(18480)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11915">11915</ref></refs><vuln_soft><prod name="zgv Image Viewer" vendor="zgv"><vers num="5.5.3"/><vers num="5.6"/><vers num="5.7"/><vers num="5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1000" published="2004-01-10" seq="2004-1000" severity="Low" type="CVE"><desc><descript source="cve">lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18808">lintian-symlink(18808)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13771">13771</ref></refs><vuln_soft><prod name="lintian" vendor="Debian"><vers num="1.2 0.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-1001" published="2005-03-01" seq="2004-1001" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17902">shadow pwdcheck.c allows account modification</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000894">CLA-2004:894</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-585">DSA-585</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13028">13028</ref></refs><vuln_soft><prod name="Shadow" vendor="Debian"><vers num="4.0.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1002" published="2005-03-01" seq="2004-1002" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17874">ppp Callback Control Protocol header fields denial of service</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/379450">20041026 pppd out of bounds memory access, possible DOS</ref><ref source="MLIST" url="http://lists.ubuntu.com/archives/ubuntu-security-announce/2004-October/000012.html">[ubuntu-security-announce] 20041029 [USN-12-1] ppp Denial of Service</ref></refs><vuln_soft><prod name="ppp" vendor="Samba"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1003" published="2005-03-01" seq="2004-1003" severity="Medium" type="CVE"><desc><descript source="cve">Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17962">ScanMail allows access to sensitive files</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/11612">Trend Micro ScanMail for Domino Remote File Disclosure Vulnerability</ref><ref source="MISC" url="http://cgi.nessus.org/plugins/dump.php3?id=14312">http://cgi.nessus.org/plugins/dump.php3?id=14312</ref></refs><vuln_soft><prod name="ScanMail Domino" vendor="Trend Micro"><vers num="2.6"/><vers num="2.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1004" published="2005-04-14" seq="2004-1004" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-217.html">mc security update</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18902">Midnight Commander format string attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-639">DSA-639</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml">GLSA-200502-24</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1005" published="2005-04-14" seq="2004-1005" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-217.html">mc security update</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-639">DSA-639</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml">GLSA-200502-24</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18898">midnight-commander-bo(18898)</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1006" published="2005-03-01" seq="2004-1006" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17963">ICS DHCP log function format string attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11591">ISC DHCPD Remote Format String Vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-584">DSA-584-1 dhcp -- format string vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109968710822449&amp;w=2"> Re: debian dhcpd, old format string bug</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-10/0287.html">20041025 debian dhcpd, old format string bug</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0037.html">20041102 Re: debian dhcpd, old format string bug</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/448384">VU#448384</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-212.html">RHSA-2005:212</ref></refs><vuln_soft><prod name="DHCPD" vendor="ISC"><vers num="2.0.pl5"/><vers num="3.0 rc4"/><vers num="3.0 rc12"/><vers num="3.0 pl2"/><vers num="3.0 pl1"/><vers num="3.0 b2pl9"/><vers num="3.0 b2pl23"/><vers num="3.0"/><vers num="3.0.1 rc9"/><vers num="3.0.1 rc8"/><vers num="3.0.1 rc7"/><vers num="3.0.1 rc6"/><vers num="3.0.1 rc5"/><vers num="3.0.1 rc4"/><vers num="3.0.1 rc3"/><vers num="3.0.1 rc2"/><vers num="3.0.1 rc14"/><vers num="3.0.1 rc13"/><vers num="3.0.1 rc12"/><vers num="3.0.1 rc11"/><vers num="3.0.1 rc10"/><vers num="3.0.1 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1007" published="2005-03-01" seq="2004-1007" severity="Medium" type="CVE"><desc><descript source="cve">The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11568">Bogofilter EMail Filter Remote Quoted Printable Decoder Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17916">bogofilter quoted-printable decoder denial of service</ref><ref source="CONFIRM" url="http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01">http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01</ref></refs><vuln_soft><prod name="Email Filter" vendor="Bogofilter"><vers num="0.9.0.5"/><vers num="0.9.0.4"/><vers num="0.9.0.3"/><vers num="0.92"/><vers num="0.92.4"/><vers num="0.92.6"/><vers num="0.92.7"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1008" published="2005-01-10" seq="2004-1008" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11549">PuTTY Remote SSH2_MSG_DEBUG Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17886">PuTTY SSH2_MSG_DEBUG buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889312917613&amp;w=2">Anatole Shaw &lt;anatole () nationalsky ! com&gt;</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200410-29.xml">PuTTY: Pre-authentication buffer overflow</ref><ref source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/">http://www.chiark.greenend.org.uk/~sgtatham/putty/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13012/">13012</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414"></ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/12987/">12987</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17214">17214</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=155&amp;type=vulnerabilities&amp;flashstatus=true">20041027 PuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability </ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.48"/><vers num="0.49"/><vers num="0.50"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53b"/><vers num="0.53"/><vers num="0.54"/><vers num="0.55"/></prod><prod name="TortoiseCVS" vendor="TortoiseCVS"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1009" published="2005-04-14" seq="2004-1009" severity="Medium" type="CVE"><desc><descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18903">midnight-commander-dos(18903)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1010" published="2005-03-01" seq="2004-1010" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11603">Info-ZIP Zip Remote Recursive Directory Compression Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028379.html">20041103 [HV-MED] Zip/Linux long path buffer overflow</ref><ref source="MISC" url="http://www.hexview.com/docs/20041103-1.txt">http://www.hexview.com/docs/20041103-1.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-624">DSA-624</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2255">FLSA:2255</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:141">MDKSA-2004:141</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-16.xml">GLSA-200411-16</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-634.html">RHSA-2004:634</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-18.txt">TLSA-2005-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-18-1">USN-18-1</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-072.shtml">P-072</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17956">infozip-compressed-folder-bo(17956)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109958840611053&amp;w=2">20041103 [HV-MED] Zip/Linux long path buffer overflow</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:141">MDKSA-2004:141</ref></refs><vuln_soft><prod name="Zip" vendor="Info-ZIP"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1011" published="2005-01-10" seq="2004-1011" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18198">Cyrus IMAP username buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11729/">Cyrus IMAPD Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2">Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref><ref source="MISC" url="http://security.e-matters.de/advisories/152004.html">http://security.e-matters.de/advisories/152004.html</ref><ref source="CONFIRM" url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-34.xml">GLSA-200411-34</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13274/">13274</ref><ref source="MLIST" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Cyrus IMAP Server" vendor="Carnegie Mellon University"><vers num="2.1.7"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.16"/><vers num="2.2.0 Alpha"/><vers num="2.2.1 BETA"/><vers num="2.2.2 BETA"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1012" published="2005-01-10" seq="2004-1012" severity="High" type="CVE"><desc><descript source="cve">The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command (&quot;body[p&quot;) that is treated as a different command (&quot;body.peek&quot;) and causes an index increment error that leads to an out-of-bounds memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11729/">Cyrus IMAPD Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2">Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18199">Cyrus IMAP PARTIAL and FETCH commands execute code</ref><ref source="MISC" url="http://security.e-matters.de/advisories/152004.html">http://security.e-matters.de/advisories/152004.html</ref><ref source="CONFIRM" url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-597">DSA-597</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-34.xml">GLSA-200411-34</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13274/">13274</ref><ref source="MLIST" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110134117423743&amp;w=2">USN-31-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Cyrus IMAP Server" vendor="Carnegie Mellon University"><vers num="2.1.7"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.16"/><vers num="2.2.0 Alpha"/><vers num="2.2.1 BETA"/><vers num="2.2.2 BETA"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1013" published="2005-01-10" seq="2004-1013" severity="High" type="CVE"><desc><descript source="cve">The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) &quot;body[p&quot;, (2) &quot;binary[p&quot;, or (3) &quot;binary[p&quot;) that cause an index increment error that leads to an out-of-bounds memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11729/">Cyrus IMAPD Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2">Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-597">DSA-597-1 cyrus-imapd -- buffer overflow</ref><ref source="MISC" url="http://security.e-matters.de/advisories/152004.html">http://security.e-matters.de/advisories/152004.html</ref><ref source="CONFIRM" url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-34.xml">GLSA-200411-34</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13274/">13274</ref><ref source="MLIST" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110134117423743&amp;w=2">USN-31-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Cyrus IMAP Server" vendor="Carnegie Mellon University"><vers num="2.1.7"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.16"/><vers num="2.2.0 Alpha"/><vers num="2.2.1 BETA"/><vers num="2.2.2 BETA"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1014" published="2005-01-10" seq="2004-1014" severity="Medium" type="CVE"><desc><descript source="cve">statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11785">Linux NFS RPC.STATD Remote Denial Of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110194853709629&amp;w=2">  [USN-36-1] NFS statd vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18332">nfs-utils statd denial of service</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-606">DSA-606</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-583.html">RHSA-2004:583</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-014.html">RHSA-2005:014</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0065/">2004-0065</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/nfs/nfs-utils/ChangeLog?rev=1.258&amp;view=markup"></ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426072/30/6740/threaded">
FLSA-2006:138098</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="nfs-utils" vendor="nfs"><vers num="1.0.6"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1015" published="2005-01-10" seq="2004-1015" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11738">Cyrus IMAPD Multiple Remote Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18274">Cyrus IMAP Server &apos;imap magic plus&apos; support code buffer overflow</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200411-34.xml">Cyrus IMAP Server: Multiple remote vulnerabilities</ref><ref source="CONFIRM" url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref><ref source="MLIST" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=145">[cyrus-announce] 20041123 Cyrus IMAPd 2.2.10 Released</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139">MDKSA-2004:139</ref></refs><vuln_soft><prod name="Cyrus IMAP Server" vendor="Carnegie Mellon University"><vers num="1.4"/><vers num="1.5.19"/><vers num="2.0.12"/><vers num="2.0.16"/><vers num="2.1.7"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.16"/><vers num="2.2.0 Alpha"/><vers num="2.2.1 BETA"/><vers num="2.2.2 BETA"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1016" published="2005-01-10" seq="2004-1016" severity="Low" type="CVE"><desc><descript source="cve">The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11921">Linux Kernel SCM_SEND Local Denial of Service Vulnerability</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0019-scm.txt">http://isec.pl/vulnerabilities/isec-0019-scm.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-689.html">RHSA-2004:689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18483">linux-scmsend-dos(18483)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2">USN-38-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html">SUSE-SA:2004:044</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1017" published="2004-12-31" seq="2004-1017" severity="High" type="CVE"><desc><descript source="cve">Multiple &quot;overflows&quot; in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-689.html">RHSA-2004:689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18433">linux-ioedgeport-bo(18433)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="BID" url="http://www.securityfocus.com/bid/12102">12102</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1018" published="2005-01-10" seq="2004-1018" severity="High" type="CVE"><desc><descript source="cve">Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an &quot;integer overflow/underflow&quot; in the pack function, or (3) an &quot;integer overflow/underflow&quot; in the unpack function.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/384920">20041219 PHP shmop.c module permits write of arbitrary memory.</ref><ref source="MISC" url="http://www.hardened-php.net/advisories/012004.txt">http://www.hardened-php.net/advisories/012004.txt</ref><ref source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-032.html">RHSA-2005:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/12045">12045</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18515">php-shmopwrite-outofbounds-memory(18515)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314318531298&amp;w=2">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2">USN-99-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="OSVDB" url="http://www.osvdb.org/12411">12411</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-1019" published="2005-01-10" seq="2004-1019" severity="High" type="CVE"><desc><descript source="cve">The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger &quot;information disclosure, double-free and negative reference index array underflow&quot; results.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11964">PHP Multiple Local And Remote Vulnerabilities</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-687.html">Updated php packages fix security issues and bugs</ref><ref source="MISC" url="http://www.hardened-php.net/advisories/012004.txt">http://www.hardened-php.net/advisories/012004.txt</ref><ref source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0412/157.html">20041216 [OpenPKG-SA-2004.053] OpenPKG Security Advisory (php)</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-032.html">RHSA-2005:032</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_02_php4_mod_php4.html">SUSE-SA:2005:002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18514">php-unserialize-code-execution(18514)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314318531298&amp;w=2">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="3.0.10"/><vers num="4.0"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1020" published="2005-01-10" seq="2004-1020" severity="Medium" type="CVE"><desc><descript source="cve">The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/384663">20041216 PHP Input Validation Vulnerabilities</ref><ref adv="1" source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915">CLA-2005:915</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml">GLSA-200412-14</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11981">11981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18516">php-addslashes-view-files(18516)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.0.2"/><vers num="5.0.0.1"/><vers num="5.0.0 candidate 3"/><vers num="5.0.0 candidate 2"/><vers num="5.0.0 candidate 1"/><vers num="5.0.0.0"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1021" published="2005-03-01" seq="2004-1021" severity="High" type="CVE"><desc><descript source="cve">iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11728">Apple iCal Calendar Import Alarm Notification Failure Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2004/Nov/msg00000.html">APPLE-SA-2004-11-22</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18209">ical-calendar-authorization-bypass(18209)</ref></refs><vuln_soft><prod name="iCal" vendor="Apple"><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-1022" published="2005-01-10" seq="2004-1022" severity="Low" type="CVE"><desc><descript source="cve">Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11930">Multiple Kerio Products Universal Secret Key Storage Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304957607578&amp;w=2"> [CAN-2004-1022] Insecure Credential Storage on Kerio Software</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18470">kerio-weak-encryption(18470)</ref></refs><vuln_soft><prod name="Kerio Mailserver" vendor="Kerio"><vers num="5.0"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.6.3"/><vers num="5.6.4"/><vers num="5.6.5"/><vers num="5.7.0"/><vers num="5.7.1"/><vers num="5.7.2"/><vers num="5.7.3"/><vers num="5.7.4"/><vers num="5.7.5"/><vers num="5.7.6"/><vers num="5.7.7"/><vers num="5.7.8"/><vers num="5.7.9"/><vers num="5.7.10"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/></prod><prod name="WinRoute Firewall" vendor="Kerio"><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.8"/><vers num="5.0.9"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.1.7"/><vers num="5.1.8"/><vers num="5.1.9"/><vers num="5.1.10"/><vers num="5.10"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/></prod><prod name="ServerFirewall" vendor="Kerio"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-1023" published="2005-01-10" seq="2004-1023" severity="Low" type="CVE"><desc><descript source="cve">Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18471">kerio-insecure-permissions(18471)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305387813002&amp;w=2">20041214 [CAN-2004-1023] Insecure default file system permissions on Microsoft versions of Kerio Software</ref></refs><vuln_soft><prod name="Kerio MailServer" vendor="Kerio"><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/></prod><prod name="Winroute Firewall" vendor="Kerio"><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/></prod><prod name="ServerFirewall" vendor="Kerio"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-13" name="CVE-2004-1025" published="2005-01-10" seq="2004-1025" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11830">IMLib Multiple XPM Image Decoding Buffer Overflow Vulnerabilities</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-651.html">Updated imlib packages fix security vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:007">MDKSA-2005:007</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:007">MDKSA-2005:007</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Imlib" vendor="Enlightenment"><vers num="1.9.13"/><vers num="1.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-13" name="CVE-2004-1026" published="2005-01-10" seq="2004-1026" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11830">IMLib Multiple XPM Image Decoding Buffer Overflow Vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-651.html">Updated imlib packages fix security vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-628">DSA-628</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-03.xml">GLSA-200412-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:007">MDKSA-2005:007</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:007">MDKSA-2005:007</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Imlib" vendor="Enlightenment"><vers num="1.9.13"/><vers num="1.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1027" published="2005-03-01" seq="2004-1027" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11436">ARJ Software UNARJ Remote Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17684">unarj file extraction directory traversal</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027348.html">20041010 unarj dir-transversal bug (../../../..)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-628">DSA-628</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-652">DSA-652</ref><ref source="FEDORA" url="http://lwn.net/Articles/121827/">FLSA:2272</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-29.xml">GLSA-200411-29</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-007.html">RHSA-2005:007</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="UNARJ" vendor="ARJ Software Inc."><vers num="2.62"/><vers num="2.63 a"/><vers num="2.64"/><vers num="2.65"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1028" published="2005-01-10" seq="2004-1028" severity="High" type="CVE"><desc><descript source="cve">Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious &quot;grep&quot; program, which is executed from chcod.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12060">IBM AIX CHCOD Local Privilege Escalation Vulnerability</ref><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=170&amp;type=vulnerabilities">IBM AIX chcod Local Privilege Escalation Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18625">aix-chcod-gain-privileges(18625)</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64355&amp;apar=only">IY64355</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64354&amp;apar=only">IY64354</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64356&amp;apar=only">IY64356</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1L"/><vers num="5.1"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.2.2"/><vers num="5.3 L"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2004-1029" published="2005-03-01" seq="2004-1029" severity="High" type="CVE"><desc><descript source="cve">The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11726">Sun Java Runtime Environment Java Plug-in JavaScript Security Restriction Bypass Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html">APPLE-SA-2005-02-22</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1">57591</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18188">sdk-jre-applet-restriction-bypass(18188)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/760344">VU#760344</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13271">13271</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=158&amp;type=vulnerabilities">20041122 Sun Java Plugin Arbitrary Package Access Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=158&amp;type=vulnerabilities">20041122 Sun Java Plugin Arbitrary Package Access Vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1">101523</ref><ref source="" url="http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/61">61</ref><ref source="" url="http://jouko.iki.fi/adv/javaplugin.html"></ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21257249"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12317">12317</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0599">ADV-2008-0599</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29035">29035</ref></refs><vuln_soft><prod name="SDK Solaris Production Release" vendor="Sun"><vers num="1.3.1_07"/><vers num="1.3.1_06"/><vers num="1.3.1_05"/><vers num="1.3.1_03"/><vers num="1.3.1_02"/><vers num="1.3.1_01"/><vers num="1.4.0_4"/><vers num="1.4.0_03"/><vers num="1.4.0_02"/><vers num="1.4"/><vers num="1.4.1_03"/><vers num="1.4.1_02"/><vers num="1.4.1_01"/><vers num="1.4.1"/><vers num="1.4.2_05"/><vers num="1.4.2_04"/><vers num="1.4.2_03"/><vers num="1.4.2"/></prod><prod name="Enterprise Firewall" vendor="Symantec"><vers edition="Solaris" num="8.0"/><vers edition="Windows 2000_NT" num="8.0"/><vers num="8.0"/></prod><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0"/><vers num="2.0.1"/></prod><prod name="Java SDK_RTE HP-UX PA-RISC" vendor="HP"><vers num="1.3"/><vers num="1.4"/></prod><prod name="SDK Windows Production Release" vendor="Sun"><vers num="1.3.1 _07"/><vers num="1.3.1 _06"/><vers num="1.3.1 _05"/><vers num="1.3.1 _04"/><vers num="1.3.1 _03"/><vers num="1.3.1 _02"/><vers num="1.3.1 _01a"/><vers num="1.4 .0_4"/><vers num="1.4 .0_03"/><vers num="1.4 .0_02"/><vers num="1.4 .0_01"/><vers num="1.4"/><vers num="1.4.1 _03"/><vers num="1.4.1 _02"/><vers num="1.4.1 _01"/><vers num="1.4.1"/><vers num="1.4.2 _05"/><vers num="1.4.2 _04"/><vers num="1.4.2 _03"/><vers num="1.4.2"/></prod><prod name="JRE Windows Production Release" vendor="Sun"><vers num="1.3 .0_05"/><vers num="1.3 .0_04"/><vers num="1.3 .0_02"/><vers num="1.3"/><vers num="1.3.1 _09"/><vers num="1.3.1 _08"/><vers num="1.3.1 _07"/><vers num="1.3.1 _06"/><vers num="1.3.1 _05"/><vers num="1.3.1 _04"/><vers num="1.3.1 _03"/><vers num="1.3.1 _02"/><vers num="1.3.1 _01a"/><vers num="1.3.1 _01"/><vers num="1.4 .0_04"/><vers num="1.4 .0_03"/><vers num="1.4 .0_02"/><vers num="1.4 .0_01"/><vers num="1.4"/><vers num="1.4.1 _07"/><vers num="1.4.1 _03"/><vers num="1.4.1 _02"/><vers num="1.4.1 _01"/><vers num="1.4.1"/><vers num="1.4.2 _05"/><vers num="1.4.2 _04"/><vers num="1.4.2 _03"/><vers num="1.4.2 _02"/><vers num="1.4.2 _01"/><vers num="1.4.2"/></prod><prod name="SDK Linux Production Release" vendor="Sun"><vers num="1.3.1_07"/><vers num="1.3.1_06"/><vers num="1.3.1_05"/><vers num="1.3.1_03"/><vers num="1.3.1_02"/><vers num="1.3.1_01"/><vers num="1.4.0_4"/><vers num="1.4.0_03"/><vers num="1.4.0_02"/><vers num="1.4"/><vers num="1.4.1_03"/><vers num="1.4.1_02"/><vers num="1.4.1_01"/><vers num="1.4.1"/><vers num="1.4.2_05"/><vers num="1.4.2_04"/><vers num="1.4.2_03"/><vers num="1.4.2_02"/><vers num="1.4.2_01"/><vers num="1.4.2"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.00"/></prod><prod name="JRE Solaris Production Release" vendor="Sun"><vers num="1.3 .0_05"/><vers num="1.3 .0_02"/><vers num="1.3"/><vers num="1.3.1 _09"/><vers num="1.3.1 _08"/><vers num="1.3.1 _07"/><vers num="1.3.1 _06"/><vers num="1.3.1 _05"/><vers num="1.3.1 _04"/><vers num="1.3.1 _03"/><vers num="1.3.1 _02"/><vers num="1.3.1 _01"/><vers num="1.4 .0_04"/><vers num="1.4 .0_03"/><vers num="1.4 .0_02"/><vers num="1.4 .0_01"/><vers num="1.4"/><vers num="1.4.1 _03"/><vers num="1.4.1 _02"/><vers num="1.4.1 _01"/><vers num="1.4.1"/><vers num="1.4.2 _05"/><vers num="1.4.2 _04"/><vers num="1.4.2 _03"/><vers num="1.4.2 _02"/><vers num="1.4.2 _01"/><vers num="1.4.2"/></prod><prod name="JRE Linux Production Release" vendor="Sun"><vers num="1.3 .0_05"/><vers num="1.3 .0_04"/><vers num="1.3 .0_03"/><vers num="1.3 .0_02"/><vers num="1.3 .0_01"/><vers num="1.3 .0"/><vers num="1.3.1 _09"/><vers num="1.3.1 _08"/><vers num="1.3.1 _07"/><vers num="1.3.1 _06"/><vers num="1.3.1 _05"/><vers num="1.3.1 _03"/><vers num="1.3.1 _02"/><vers num="1.3.1 _01"/><vers num="1.3.1"/><vers num="1.4 .0_04"/><vers num="1.4 .0_03"/><vers num="1.4 .0_02"/><vers num="1.4"/><vers num="1.4.1 _03"/><vers num="1.4.1 _02"/><vers num="1.4.1 _01"/><vers num="1.4.1"/><vers num="1.4.2 _05"/><vers num="1.4.2 _04"/><vers num="1.4.2 _03"/><vers num="1.4.2 _02"/><vers num="1.4.2 _01"/><vers num="1.4.2"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1030" published="2005-03-01" seq="2004-1030" severity="Low" type="CVE"><desc><descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18075">Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11684">Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-27.xml">GLSA-200411-27</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false">20041115 Multiple Security Vulnerabilities in Fcron</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Fcron" vendor="Thibault Godouet"><vers num="2.0.1"/><vers num="2.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1031" published="2005-03-01" seq="2004-1031" severity="High" type="CVE"><desc><descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11684">Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18076">Fcron fcronsighup bypass restrictions</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-27.xml">GLSA-200411-27</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false">20041115 Multiple Security Vulnerabilities in Fcron</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Fcron" vendor="Thibault Godouet"><vers num="2.0.1"/><vers num="2.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1032" published="2005-03-01" seq="2004-1032" severity="Low" type="CVE"><desc><descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200411-27.xml">Fcron: Multiple vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18077">fcron-fcronsighup-create-files(18077)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false">20041115 Multiple Security Vulnerabilities in Fcron</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Fcron" vendor="Thibault Godouet"><vers num="2.0.1"/><vers num="2.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1033" published="2005-03-01" seq="2004-1033" severity="Low" type="CVE"><desc><descript source="cve">Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11684">Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18078">Fcron fcrontab allows attacker to obtain information</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-27.xml">GLSA-200411-27</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false">20041115 Multiple Security Vulnerabilities in Fcron</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Fcron" vendor="Thibault Godouet"><vers num="2.0.1"/><vers num="2.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2004-1034" published="2005-03-01" seq="2004-1034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17849">Kaffeine RAM playlist file buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11528">Kaffeine Remote Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028061.html">20041025 Kaffeine Media Player Conteny Type overflow</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-14.xml">GLSA-200411-14</ref><ref source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1060299&amp;group_id=9655&amp;atid=109655">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1060299&amp;group_id=9655&amp;atid=109655</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13117/">13117</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="gxine" vendor="xine"><vers num="0.3"/></prod><prod name="Kaffeine Player" vendor="Kaffeine"><vers num="0.4.2"/><vers num="0.4.3b"/><vers num="0.4.3"/><vers num="0.5 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1035" published="2005-03-01" seq="2004-1035" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in (1) imapcommon.c, (2) main.c, (3) request.c, and (4) select.c for up-imapproxy IMAP proxy 1.2.2 allow remote attackers to cause a denial of service (server crash) and possibly leak sensitive information via certain literal values that are not properly handled when using the IMAP_Line_Read function.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17999">up-imapproxy denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109995749510773&amp;w=2">20041107 up-imapproxy DoS vulnerabilities</ref></refs><vuln_soft><prod name="IMAP proxy" vendor="IMAP proxy"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1036" published="2005-03-01" seq="2004-1036" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18031">SquirrelMail mime.php cross-site scripting</ref><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11653">SquirrelMail decodeHeader HTML Injection Vulnerability</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-25.xml">SquirrelMail: Encoded text XSS vulnerability</ref><ref source="CONFIRM" url="http://www.squirrelmail.org/">http://www.squirrelmail.org/</ref><ref source="CONFIRM" url="http://voxel.dl.sourceforge.net/sourceforge/squirrelmail/sm143a-xss.diff">http://voxel.dl.sourceforge.net/sourceforge/squirrelmail/sm143a-xss.diff</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012133608004&amp;w=2">20041110 [SquirrelMail Security Advisory] Cross Site Scripting in encoded text</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000905">CLA-2004:905</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.2"/><vers num="1.5 dev"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1037" published="2005-03-01" seq="2004-1037" severity="High" type="CVE"><desc><descript source="cve">The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18062">TWiki search function command execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11674">TWiki Search Shell Metacharacter Remote Arbitrary Command Execution Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0201.html">20041116 Re: [Full-Disclosure] TWiki search function allows arbitrary shell command execution</ref><ref source="CONFIRM" url="http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithSearch">http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithSearch</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-33.xml">GLSA-200411-33</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-039.shtml">P-039</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037207516456&amp;w=2">20041112 TWiki search function allows arbitrary shell command execution</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000918">CLA-2005:918</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Twiki" vendor="Twiki"><vers num="2003-02-01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2004-1038" published="2005-03-01" seq="2004-1038" severity="High" type="CVE"><desc><descript source="cve">A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit.  NOTE: this was reported in 2008 to affect Windows Vista, but some Linux-based operating systems have protection mechanisms against this attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://pacsec.jp/advisories.html">http://pacsec.jp/advisories.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18041">firewire-ieee1394-interface-installed(18041)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109881362530790&amp;w=2">20041026 pacsec.jp advisory: Firewire/IEEE 1394 Considered Harmful to Physical Security</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489163/100/0/threaded">20080305 Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489189/100/0/threaded">20080305 RE: Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489175/100/0/threaded">20080305 Re: Firewire Attack on Windows Vista</ref><ref source="" url="http://it.slashdot.org/article.pl?sid=08/03/04/1258210"></ref><ref source="" url="http://md.hudora.de/presentations/firewire/2005-firewire-cansecwest.pdf"></ref><ref source="" url="http://storm.net.nz/projects/16"></ref><ref source="" url="http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf"></ref><ref source="" url="http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf"></ref><ref source="" url="http://www.theage.com.au/news/security/hack-into-a-windows-pc-no-password-needed/2008/03/04/1204402423638.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489322/100/0/threaded">20080309 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489335/100/0/threaded">20080309 Re: Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489330/100/0/threaded">20080310 RE: [Full-disclosure] Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489342/100/0/threaded">20080310 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489257/100/0/threaded">20080306 RE: Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489212/100/0/threaded">20080306 Re: Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489269/100/0/threaded">20080307 Re: Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489296/100/0/threaded">20080308 RE: [Full-disclosure] Firewire Attack on Windows Vista</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489295/100/0/threaded">20080308 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref></refs><vuln_soft><prod name="Firewire_IEEE" vendor="IEEE"><vers num="1394"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1039" published="2005-01-11" seq="2004-1039" severity="Medium" type="CVE"><desc><descript source="cve">The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/386814">20050111 [NILESA-20050101]: Denial of Service vulnerability due to the mountd bug</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.1/SCOSA-2005.1.txt">SCOSA-2005.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/12225">12225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13805">13805</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.4"/><vers num="7.1.3"/><vers num="7.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1043" published="2004-12-31" seq="2004-1043" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the &quot;Related Topics&quot; command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using &quot;writehta.txt&quot; and the ADODB recordset, which saves a .HTA file to the local system, aka the &quot;HTML Help ActiveX control Cross Domain Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0426.html">20041225 Microsoft Internet Explorer SP2 Fully Automated Remote Compromise</ref><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-001.mspx">MS05-001</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-012B.html">TA05-012B</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/972415">VU#972415</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1349.html">OVAL1349</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1963.html">OVAL1963</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2830.html">OVAL2830</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3496.html">OVAL3496</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18311">ie-helpactivexcontrol-save-file(18311)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1349">oval:org.mitre.oval:def:1349</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1963">oval:org.mitre.oval:def:1963</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2830">oval:org.mitre.oval:def:2830</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3496">oval:org.mitre.oval:def:3496</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2004-1049" published="2004-12-31" seq="2004-1049" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the &quot;Cursor and Icon Format Handling Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382891718076&amp;w=2">20041223 Microsoft Windows LoadImage API Integer Buffer overflow </ref><ref source="MISC" url="http://www.xfocus.net/flashsky/icoExp/index.html">http://www.xfocus.net/flashsky/icoExp/index.html</ref><ref adv="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx">MS05-002</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-012A.html">TA05-012A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/625856">VU#625856</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2956.html">OVAL2956</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3097.html">OVAL3097</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3220.html">OVAL3220</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3355.html">OVAL3355</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4671.html">OVAL4671</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2956">oval:org.mitre.oval:def:2956</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3097">oval:org.mitre.oval:def:3097</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3220">oval:org.mitre.oval:def:3220</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3355">oval:org.mitre.oval:def:3355</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4671">oval:org.mitre.oval:def:4671</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-094.shtml">P-094</ref><ref source="BID" url="http://www.securityfocus.com/bid/12095">12095</ref><ref source="OSVDB" url="http://www.osvdb.org/12623">12623</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012684">1012684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13645">13645</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18668">win-loadimage-bo(18668)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/><vers num="SP1"/><vers num="SP2"/><vers num="SP3"/><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-1050" published="2004-12-31" seq="2004-1050" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka &quot;the IFRAME vulnerability&quot; or the &quot;HTML Elements Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11515">Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17889">Microsoft Internet Explorer IFRAME SRC NAME buffer overflow</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/842160">Microsoft Internet Explorer vulnerable to buffer overflow via FRAME and IFRAME elements</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html">20041023 python does mangleme (with IE bugs!)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html">20041025 python does mangleme (with IE bugs!)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/379261">20041024 python does mangleme (with IE bugs!)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109942758911846&amp;w=2">20041102 MSIE &lt;IFRAME&gt; and &lt;FRAME&gt; tag NAME property bufferoverflow PoC</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS04-040.mspx">MS04-040</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-315A.html">TA04-315A</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-336A.html">TA04-336A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1294.html">OVAL1294</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12959/">12959</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109942758911846&amp;w=2">20041102 MSIE &lt;IFRAME&gt; and &lt;FRAME&gt; tag NAME property bufferoverflow PoC</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1294">oval:org.mitre.oval:def:1294</ref></refs><vuln_soft><prod name="S3400 Message Application Server" vendor="Avaya"><vers num=""/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num="R9"/><vers num="R8"/><vers num="R7"/><vers num="R6"/><vers num="R12"/><vers num="R11"/><vers num="R10"/><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num="R9"/><vers num="R8"/><vers num="R7"/><vers num="R6"/><vers num="R12"/><vers num="R11"/><vers num="R10"/><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num="R9"/><vers num="R8"/><vers num="R7"/><vers num="R6"/><vers num="R12"/><vers num="R11"/><vers num="R10"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1051" published="2005-03-01" seq="2004-1051" severity="High" type="CVE"><desc><descript source="cve">sudo before 1.6.8p2 allows local users to execute arbitrary commands by using &quot;()&quot; style environment variables to create functions that have the same name as any program within the bash script that is called without using the program&apos;s full pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11668">GratiSoft Sudo Restricted Command Execution Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18055">Sudo bash command execution</ref><ref source="CONFIRM" url="http://www.sudo.ws/sudo/alerts/bash_functions.html">http://www.sudo.ws/sudo/alerts/bash_functions.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-596">DSA-596</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:133">MDKSA-2004:133</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0061/">2004-0061</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110028877431192&amp;w=2">20041112 Sudo version 1.6.8p2 now available (fwd)</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110598298225675&amp;w=2">OpenPKG-SA-2005.002</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110073149111410&amp;w=2">USN-28-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:133">MDKSA-2004:133</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Sudo" vendor="Todd Miller"><vers num="1.5.6"/><vers num="1.5.7"/><vers num="1.5.8"/><vers num="1.5.9"/><vers num="1.6"/><vers num="1.6.1"/><vers num="1.6.2"/><vers num="1.6.3 p7"/><vers num="1.6.3 p6"/><vers num="1.6.3 p5"/><vers num="1.6.3 p4"/><vers num="1.6.3 p3"/><vers num="1.6.3 p2"/><vers num="1.6.3 p1"/><vers num="1.6.3"/><vers num="1.6.4 p2"/><vers num="1.6.4 p1"/><vers num="1.6.4"/><vers num="1.6.5 p2"/><vers num="1.6.5 p1"/><vers num="1.6.5"/><vers num="1.6.6"/><vers num="1.6.7"/><vers num="1.6.8 p1"/><vers num="1.6.8"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1052" published="2005-03-01" seq="2004-1052" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11647">BNC getnickuserhost IRC Server Response Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18013">BNC IRC getnickuserhost function buffer overflow</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-595">DSA-595</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13149/">13149</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011817627839&amp;w=2">20041110 BNC 2.8.9 remote buffer overflow</ref><ref source="" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2004-11-03"></ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="BNC" vendor="BNC"><vers num="2.2.4"/><vers num="2.4.6"/><vers num="2.4.8"/><vers num="2.6"/><vers num="2.6.2"/><vers num="2.6.4"/><vers num="2.8.8"/><vers num="2.8.9"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1053" published="2005-03-01" seq="2004-1053" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11702">FreeBSD Fetch Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18160">fetch HTTP header buffer overflow</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:16.fetch.asc">FreeBSD-SA-04:16</ref></refs><vuln_soft><prod name="fetch" vendor="FreeBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1054" published="2005-01-10" seq="2004-1054" severity="High" type="CVE"><desc><descript source="cve">Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious &quot;uname&quot; program, which is executed from lsvpd after lsvpd has been invoked by invscout.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12061">IBM AIX LSVPD Local Privilege Escalation Vulnerability</ref><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=171&amp;type=vulnerabilities">IBM AIX invscout Local Command Execution Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18619">aix-invscout-gain-privileges(18619)</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64852&amp;apar=only">IY64852</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64976&amp;apar=only">IY64976</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64820&amp;apar=only">IY64820</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1L"/><vers num="5.1"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.2.2"/><vers num="5.3 L"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1055" published="2005-03-01" seq="2004-1055" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11707/">PHPMyAdmin Multiple Remote Cross-Site Scripting Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.netvigilance.com/html/advisory0005.htm">http://www.netvigilance.com/html/advisory0005.htm</ref><ref source="CONFIRM" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-3">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18158">phpmyadmin-multiple-xss(18158)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.4"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/><vers num="2.5.6 rc1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1056" published="2005-01-10" seq="2004-1056" severity="Medium" type="CVE"><desc><descript source="cve">Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11936">Linux Kernel Local DRM Denial Of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2"> [USN-38-1] Linux kernel vulnerabilities</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15972">linux-i810-dma-dos(15972)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-529.html">RHSA-2005:529</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2004-1057" published="2005-01-21" seq="2004-1057" severity="High" type="CVE"><desc><descript source="cve">Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.kernel.org/pub/linux/kernel/people/andrea/kernels/v2.4/2.4.23aa3/00_VM_IO-4">http://www.kernel.org/pub/linux/kernel/people/andrea/kernels/v2.4/2.4.23aa3/00_VM_IO-4</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=137821">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=137821</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19275">linux-kernel-vmio-dos(19275)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0140.html">RHSA-2006:0140</ref><ref source="BID" url="http://www.securityfocus.com/bid/12338">12338</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18562">18562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref></refs><vuln_soft><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19 pre6"/><vers num="2.4.19" prev="1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.3"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.27 rc2"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.21"/><vers num="2.2.20"/><vers num="2.2.2"/><vers num="2.2.19"/><vers num="2.2.18"/><vers num="2.2.17"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.11"/><vers num="2.2.10"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.89"/><vers num="2.1"/><vers num="2.0.9.9"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.39"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.32"/><vers num="2.0.31"/><vers num="2.0.30"/><vers num="2.0.3"/><vers num="2.0.29"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.25"/><vers num="2.0.24"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.2"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.6.20.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1058" published="2005-01-10" seq="2004-1058" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11937">Linux Kernel PROC Filesystem Local Information Disclosure Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2"> [USN-38-1] Linux kernel vulnerabilities</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml">GLSA-200408-24</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17151">linux-spawning-race-condition(17151)</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-38-1">USN-38-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0190.html">RHSA-2006:0190</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html">SUSE-SA:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19038">19038</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref><ref source="BID" url="http://www.securityfocus.com/bid/11052">11052</ref><ref source="BID" url="http://www.securityfocus.com/bid/11937">11937</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1059" published="2004-12-10" seq="2004-1059" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch 3.2.26 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) next and (2) prev result search pages, and the (3) extended and (4) simple search forms.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html">20041223 Cross-Site Scripting - an industry-wide problem</ref><ref adv="1" patch="1" source="MISC" url="http://www.mikx.de/index.php?p=6">http://www.mikx.de/index.php?p=6</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mnogosearch.org/history.html">http://www.mnogosearch.org/history.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11895">11895</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18434">mnogosearch-search-xss(18434)</ref></refs><vuln_soft><prod name="mnoGoSearch" vendor="mnoGoSearch"><vers num="3.2.26"/><vers num="3.2.25"/><vers num="3.2.24"/><vers num="3.2.23"/><vers num="3.2.22"/><vers num="3.2.21"/><vers num="3.2.20"/><vers num="3.2.19"/><vers num="3.2.18"/><vers num="3.2.17"/><vers num="3.2.16"/><vers num="3.2.15"/><vers num="3.2.14"/><vers num="3.2.13"/><vers num="3.2.10"/><vers num="3.1.20"/><vers num="3.1.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1060" published="2004-04-12" seq="2004-1060" severity="Medium" type="CVE"><desc><descript source="cve">Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP (&quot;Fragmentation Needed and Don&apos;t Fragment was Set&quot;) packets with a low next-hop MTU value, aka the &quot;Path MTU discovery attack.&quot;  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml">20050412 Crafted ICMP Messages Can Cause Denial of Service</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2188.html">OVAL2188</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3826.html">OVAL3826</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval780.html">OVAL780</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded">HPSBUX01164</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt">SCOSA-2006.4</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18317">18317</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2">HPSBTU01210</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2188">oval:org.mitre.oval:def:2188</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3826">oval:org.mitre.oval:def:3826</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:780">oval:org.mitre.oval:def:780</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:181">oval:org.mitre.oval:def:181</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:196">oval:org.mitre.oval:def:196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:405">oval:org.mitre.oval:def:405</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:651">oval:org.mitre.oval:def:651</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:899">oval:org.mitre.oval:def:899</ref><ref source="SREASON" url="http://securityreason.com/securityalert/19">19</ref><ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref></refs><vuln_soft><prod name="ICMP" vendor="ICMP"><vers num=""/></prod><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1061" published="2005-01-04" seq="2004-1061" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html">20041223 Cross-Site Scripting - an industry-wide problem</ref><ref adv="1" source="MISC" url="http://www.mikx.de/index.php?p=6">http://www.mikx.de/index.php?p=6</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18728">bugzilla-xss(18728)</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=272620"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12154">12154</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040">CLSA-2005:1040</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.11"/><vers num="2.16.10"/><vers num="2.16.9"/><vers num="2.16.8"/><vers num="2.16.7"/><vers num="2.16.6"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1062" published="2004-12-28" seq="2004-1062" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html">20041223 Cross-Site Scripting - an industry-wide problem</ref><ref adv="1" source="MISC" url="http://www.mikx.de/index.php?p=6">http://www.mikx.de/index.php?p=6</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200412-26.xml">GLSA-200412-26</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18718">viewcvs-xss(18718)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="ViewCVS" vendor="ViewCVS"><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1063" published="2005-01-10" seq="2004-1063" severity="High" type="CVE"><desc><descript source="cve">PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/384545">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref><ref source="MISC" url="http://www.hardened-php.net/advisories/012004.txt">http://www.hardened-php.net/advisories/012004.txt</ref><ref source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml">GLSA-200412-14</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="BID" url="http://www.securityfocus.com/bid/11964">11964</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18511">php-safemodeexecdir-restriction-bypass(18511)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915">CLA-2005:915</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2">USN-99-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="OSVDB" url="http://www.osvdb.org/12412">12412</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1064" published="2005-01-10" seq="2004-1064" severity="High" type="CVE"><desc><descript source="cve">The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/384545">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref><ref source="MISC" url="http://www.hardened-php.net/advisories/012004.txt">http://www.hardened-php.net/advisories/012004.txt</ref><ref source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915">CLA-2005:915</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml">GLSA-200412-14</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2">20050318 [USN-99-1] PHP4 vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111170851228358&amp;w=2">20050324 [USN-99-2] Fixed php4 packages for USN-99-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/11964">11964</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18512">php-realpath-safemode-bypass(18512)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1065" published="2005-01-10" seq="2004-1065" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11992">PHP JPEG Image Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-687.html">Updated php packages fix security issues and bugs</ref><ref source="CONFIRM" url="http://www.php.net/release_4_3_10.php">http://www.php.net/release_4_3_10.php</ref><ref source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0412/157.html">20041216 [OpenPKG-SA-2004.053] OpenPKG Security Advisory (php)</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-032.html">RHSA-2005:032</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_02_php4_mod_php4.html">SUSE-SA:2005:002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18517">php-exifreaddata-bo(18517)</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151">MDKSA-2004:151</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="Current"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="4.0"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1066" published="2005-01-10" seq="2004-1066" severity="Low" type="CVE"><desc><descript source="cve">The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory.  NOTE: this candidate might be SPLIT into 2 separate items in the future.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18321">FreeBSD procfs linprocfs information disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11789">FreeBSD Linux ProcFS Local Kernel Denial Of Service And Information Disclosure Vulnerability</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:17.procfs.asc">FreeBSD-SA-04:17</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2 Releng"/><vers num="5.2"/><vers num="5.2.1 Release"/><vers num="5.3 Stable"/><vers num="5.3 Release"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1067" published="2005-01-10" seq="2004-1067" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18333">Cyrus IMAP Server mysasl_canon_user off-by-one buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11738">Cyrus IMAPD Multiple Remote Unspecified Vulnerabilities</ref><ref source="CONFIRM" url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref><ref source="UBUNTU" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202757008916&amp;w=2">USN-37-1</ref></refs><vuln_soft><prod name="Cyrus IMAP Server" vendor="Carnegie Mellon University"><vers num="1.4"/><vers num="1.5.19"/><vers num="2.0.12"/><vers num="2.0.16"/><vers num="2.1.7"/><vers num="2.1.9"/><vers num="2.1.10"/><vers num="2.1.16"/><vers num="2.2.0 Alpha"/><vers num="2.2.1 BETA"/><vers num="2.2.2 BETA"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1068" published="2005-01-10" seq="2004-1068" severity="Medium" type="CVE"><desc><descript source="cve">A &quot;missing serialization&quot; error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11715">Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18230">Linux kernel AF_UNIX race condition</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/381689">20041119 Addendum, recent Linux &lt;= 2.4.27 vulnerabilities</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">RHSA-2004:537</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2">20041214 [USN-38-1] Linux kernel vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html">SUSE-SA:2004:044</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1069" published="2005-01-10" seq="2004-1069" severity="Low" type="CVE"><desc><descript source="cve">Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18312">Linux Kernel sock_dgram_sendmsg race condition</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=110045613004761"> [PATCH] linux 2.9.10-rc1: Fix oops in unix_dgram_sendmsg when using</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2"> [USN-38-1] Linux kernel vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-1070" published="2005-01-10" seq="2004-1070" severity="High" type="CVE"><desc><descript source="cve">The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11646/">Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18025">Linux Kernel ELF setuid allows elevated privileges</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">Updated openmotif packages fix image vulnerability</ref><ref source="MISC" url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">RHSA-2004:549</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="BID" url="http://www.securityfocus.com/bid/11646">11646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1071" published="2005-01-10" seq="2004-1071" severity="High" type="CVE"><desc><descript source="cve">The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11646/info/">Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18025">Linux Kernel ELF setuid allows elevated privileges</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">Updated openmotif packages fix image vulnerability</ref><ref source="MISC" url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="BID" url="http://www.securityfocus.com/bid/11646">11646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1072" published="2005-01-10" seq="2004-1072" severity="High" type="CVE"><desc><descript source="cve">The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11646/info/">Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18025">Linux Kernel ELF setuid allows elevated privileges</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-537.html">Updated openmotif packages fix image vulnerability</ref><ref source="MISC" url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-275.html">RHSA-2005:275</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="BID" url="http://www.securityfocus.com/bid/11646">11646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1073" published="2005-01-10" seq="2004-1073" severity="Low" type="CVE"><desc><descript source="cve">The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11646/info/">Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18025">Linux Kernel ELF setuid allows elevated privileges</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">Updated kernel packages fix security vulnerabilities</ref><ref source="MISC" url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0190.html">RHSA-2006:0190</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="BID" url="http://www.securityfocus.com/bid/11646">11646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1074" published="2005-01-10" seq="2004-1074" severity="Low" type="CVE"><desc><descript source="cve">The binfmt functionality in the Linux kernel, when &quot;memory overcommit&quot; is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11754">Linux Kernel Local Denial Of Service And Memory Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18290">Linux kernel a.out binary denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110322596918807&amp;w=2">20041216 [USN-39-1] Linux amd64 kernel vulnerability</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=110021173607372&amp;w=2">[linux-kernel] 20041111 a.out issue</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1075" published="2005-01-10" seq="2004-1075" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18237">Zwiki link cross-site scripting</ref><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11745">Zwiki Cross-Site Scripting Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110138568212036&amp;w=2">   STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability</ref><ref source="CONFIRM" url="http://zwiki.org/925ZwikiXSSVulnerability">http://zwiki.org/925ZwikiXSSVulnerability</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-23.xml">GLSA-200412-23</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149122529761&amp;w=2">20041126 Re: STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability</ref></refs><vuln_soft><prod name="Zwiki" vendor="Zwiki"><vers num="0.10 rc1"/><vers num="0.36.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1076" published="2005-01-10" seq="2004-1076" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11756">Atari800 Emulator Multiple Local Buffer Overflow Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149441815270&amp;w=2">  Re: Atari800 - local root. (fwd)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110142899319841&amp;w=2">  Atari800 - local root.</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-609">DSA-609</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/atari800/atari800/DOC/ChangeLog?view=markup"></ref><ref source="OSVDB" url="http://www.osvdb.org/12610">12610</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13670/">13670</ref></refs><vuln_soft><prod name="Atari800" vendor="Atari800"><vers num="0.5.4"/><vers num="0.6"/><vers num="0.6.2"/><vers num="0.7"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.8.6"/><vers num="0.8.7"/><vers num="0.8.8"/><vers num="0.8.9"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9j"/><vers num="0.9.9i"/><vers num="0.9.9h"/><vers num="0.9.9g"/><vers num="0.9.9f"/><vers num="0.9.9e"/><vers num="0.9.9d"/><vers num="0.9.9c"/><vers num="0.9.9b"/><vers num="0.9.9a"/><vers num="0.9.9"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.2 pre0"/><vers num="1.2"/><vers num="1.2.1 pre0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1077" published="2004-04-26" seq="2004-1077" severity="Medium" type="CVE"><desc><descript source="cve">Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=237&amp;type=vulnerabilities">20050426 Citrix Program Neighborhood Agent Arbitrary Shortcut Creation Vulnerability</ref><ref adv="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105650">http://support.citrix.com/kb/entry.jspa?externalID=CTX105650</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15108">15108</ref></refs><vuln_soft><prod name="Citrix Program Neighborhood Agent for Win32" vendor="Citrix"><vers num="8.0"/></prod><prod name="Citrix Metaframe Presentation Server client for WinCE" vendor="Citrix"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1078" published="2004-04-26" seq="2004-1078" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=238&amp;type=vulnerabilities">20050426 Citrix Program Neighborhood Agent Buffer Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105650">http://support.citrix.com/kb/entry.jspa?externalID=CTX105650</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15108">15108</ref></refs><vuln_soft><prod name="Citrix Program Neighborhood Agent for Win32" vendor="Citrix"><vers num="8.0"/></prod><prod name="Citrix Metaframe Presentation Server client for WinCE" vendor="Citrix"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1079" published="2005-01-10" seq="2004-1079" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) ncplogin and (2) ncpmap in nwclient.c for ncpfs 2.2.4, and possibly other versions, may allow local users to gain privileges via a long -T option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11945">NCPFS Local Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18283">ncpfs nwclient.c buffer overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029563.html">20041129 ncpfs buffer overflow</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-09.xml">GLSA-200412-09</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110175523207437&amp;w=2">20041129 ncpfs buffer overflow</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded">FLSA:152904</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref></refs><vuln_soft><prod name="ncpfs" vendor="ncpfs"><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-11-30" name="CVE-2004-1080" published="2005-01-10" seq="2004-1080" severity="High" type="CVE"><desc><descript source="cve">The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the &quot;Association Context Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11763">Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18259">WINS memory pointer hijack</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/145134">Microsoft Windows Internet Naming Service (WINS) replication protocol contains a heap-based buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110150370506704&amp;w=2">  Immunity, Inc Advisor</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110150370506704&amp;w=2">20041126 Immunity, Inc Advisor</ref><ref source="MISC" url="http://www.immunitysec.com/downloads/instantanea.pdf">http://www.immunitysec.com/downloads/instantanea.pdf</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/184">20041129 Microsoft WINS Server Vulnerability</ref><ref source="MSKB" url="http://support.microsoft.com/kb/890710">890710</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx">MS04-045</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-054.shtml">P-054</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1549.html">OVAL1549</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2541.html">OVAL2541</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2734.html">OVAL2734</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3677.html">OVAL3677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4372.html">OVAL4372</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4831.html">OVAL4831</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13328/">13328</ref><ref source="OSVDB" url="http://www.osvdb.org/12378">12378</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012516">1012516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1549">oval:org.mitre.oval:def:1549</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2541">oval:org.mitre.oval:def:2541</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2734">oval:org.mitre.oval:def:2734</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3677">oval:org.mitre.oval:def:3677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4372">oval:org.mitre.oval:def:4372</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4831">oval:org.mitre.oval:def:4831</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/></prod><prod name="Small Business Server" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1081" published="2004-12-02" seq="2004-1081" severity="Low" type="CVE"><desc><descript source="cve">The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18350">macos-appkit-obtain-info(18350)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-1082" published="2004-02-03" seq="2004-1082" severity="High" type="CVE"><desc><descript source="cve">mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9571">9571</ref><ref adv="1" patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Dec/1012414.html">1012414</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18347">macos-moddigest-response-replay(18347)</ref></refs><vuln_soft><prod name="Webproxy" vendor="HP"><vers num="A.02.10"/><vers num="A.02.00"/></prod><prod name="VirtualVault" vendor="HP"><vers num="A.04.70"/><vers num="A.04.60"/><vers num="A.04.50"/></prod><prod name="Network Routing" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="2.0"/><vers num="1.1"/></prod><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.29"/><vers num="1.3.28"/><vers num="1.3.27"/><vers num="1.3.26"/><vers num="1.3.25"/><vers num="1.3.24"/><vers num="1.3.23"/><vers num="1.3.22"/><vers num="1.3.20"/><vers num="1.3.19"/><vers num="1.3.18"/><vers num="1.3.17"/><vers num="1.3.14"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.9"/><vers edition="Dev" num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.1"/><vers num="1.3"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.19"/></prod><prod name="Intuity LX" vendor="Avaya"><vers num=""/></prod><prod name="Communication Manager" vendor="Avaya"><vers num="2.0.1"/><vers num="2.0"/><vers num="1.3.1"/><vers num="1.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.5"/><vers num="3.4"/><vers num="current"/></prod><prod name="mod_digest_apple" vendor="Apple"><vers num=""/></prod><prod name="MN100" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1083" published="2004-12-03" seq="2004-1083" severity="Medium" type="CVE"><desc><descript source="cve">Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with &quot;.ht&quot; using alternate capitalization.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18348">apache-hfs-file-disclosure(18348)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1084" published="2004-12-02" seq="2004-1084" severity="Medium" type="CVE"><desc><descript source="cve">Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18349">apache-hfs-obtain-info(18349)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1085" published="2004-12-02" seq="2004-1085" severity="Low" type="CVE"><desc><descript source="cve">Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18352">macos-hitoolbox-kiosk-dos(18352)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1086" published="2004-12-02" seq="2004-1086" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18354">macos-psnormalizer-bo(18354)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1087" published="2004-12-02" seq="2004-1087" severity="Low" type="CVE"><desc><descript source="cve">Terminal for Apple Mac OS X 10.3.6 may indicate that &quot;Secure Keyboard Entry&quot; is enabled even when it is not, which could result in a false sense of security for the user.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11802/discussion/">11802</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18355">macos-terminal-secure-improper(18355)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1088" published="2004-12-02" seq="2004-1088" severity="High" type="CVE"><desc><descript source="cve">Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18353">postfix-crammd5-auth-replay(18353)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1089" published="2004-12-02" seq="2004-1089" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-049.shtml">P-049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13362/">13362</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18351">cyrus-kerberos-gain-access(18351)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11802">11802</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="5.0.1"/><vers num="4.1.3"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1090" published="2005-04-14" seq="2004-1090" severity="Medium" type="CVE"><desc><descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via &quot;a corrupt section header.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18907">midnight-commander-section-dos(18907)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1091" published="2005-04-14" seq="2004-1091" severity="Medium" type="CVE"><desc><descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18908">midnight-commander-find-dos(18908)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1092" published="2005-04-14" seq="2004-1092" severity="Medium" type="CVE"><desc><descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml">GLSA-200502-24</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18904">midnight-commander-memory-allocation(18904)</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1093" published="2005-04-14" seq="2004-1093" severity="Medium" type="CVE"><desc><descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via &quot;use of already freed memory.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18905">midnight-commander-key-dos(18905)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2004-1094" published="2005-01-10" seq="2004-1094" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products.  NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17879">RealPlayer and RealOne Player DUNZIP32.DLL buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11555">RealNetworks RealOne Player/RealPlayer Skin File Remote Stack Based Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109894226007607&amp;w=2"> High Risk Vulnerability in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109894226007607&amp;w=2">20041027 High Risk Vulnerability in RealPlayer</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/security/041026_player/EN/">http://service.real.com/help/faq/security/041026_player/EN/</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/1044.html">20041027 EEYE: RealPlayer Zipped Skin File Buffer Overflow</ref><ref source="" url="http://www.networksecurity.fi/advisories/payroll.html"></ref><ref source="" url="http://www.networksecurity.fi/advisories/multiledger.html"></ref><ref source="" url="http://www.securiteam.com/windowsntfocus/6Z00W00EAM.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/582498">VU#582498</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2057">ADV-2005-2057</ref><ref source="OSVDB" url="http://www.osvdb.org/19906">19906</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011944">1011944</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012297">1012297</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17096">17096</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17394">17394</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22737">payroll-dunzip32-bo(22737)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109894226007607&amp;w=2">20041027 High Risk Vulnerability in RealPlayer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420274/100/0/threaded">20051223 dtSearch DUNZIP32.dll Buffer Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.networksecurity.fi/advisories/dtsearch.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18194">18194</ref><ref source="" url="http://www.networksecurity.fi/advisories/mcafee-virusscan.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429361/100/0/threaded">20060330 McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1176">ADV-2006-1176</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19451">19451</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445369/100/0/threaded">20060906 IBM Lotus Notes DUNZIP32.dll Buffer Overflow Vulnerability</ref><ref source="" url="http://www.networksecurity.fi/advisories/lotus-notes.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016817">1016817</ref><ref source="SREASON" url="http://securityreason.com/securityalert/296">296</ref><ref source="SREASON" url="http://securityreason.com/securityalert/653">653</ref></refs><vuln_soft><prod name="DynaZip Library" vendor="InnerMedia"><vers num="5.00.03"/><vers num="5.00.02"/><vers num="5.00.01"/><vers num="5.00.00"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/><vers num="10.0"/><vers num="10.5_6.0.12.1053"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/></prod><prod name="MultiLedger" vendor="CheckMark"><vers num="7.0.1" prev="1"/><vers num="7.0.0"/><vers num="6.0.5"/><vers num="6.0.3"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/></prod><prod name="CheckMark Payroll" vendor="CheckMark"><vers num="3.9.6" prev="1"/><vers num="3.9.5"/><vers num="3.9.4"/><vers num="3.9.3"/><vers num="3.9.2"/><vers num="3.9.1"/><vers num="3.7.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-1095" published="2005-01-10" seq="2004-1095" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11556">ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17871">zgv image headers heap overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109886210702781&amp;w=2"> zgv image viewing heap overflows</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109898111915661&amp;w=2">  Re: zgv image viewing heap overflows</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml">GLSA-200411-12</ref><ref source="CONFIRM" url="http://www.svgalib.org/rus/zgv/">http://www.svgalib.org/rus/zgv/</ref><ref source="CONFIRM" url="http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff">http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff</ref></refs><vuln_soft><prod name="xzgv Image Viewer" vendor="zgv"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="zgv Image Viewer" vendor="zgv"><vers num="5.5"/><vers num="5.6"/><vers num="5.7"/><vers num="5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-21" name="CVE-2004-1096" published="2005-01-10" seq="2004-1096" severity="High" type="CVE"><desc><descript source="cve">Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17761">Multiple vendor antivirus .zip bypass protection</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11448">Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200410-31.xml">Archive::Zip: Virus detection evasion</ref><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:118">MDKSA-2004:118</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/492545">VU#492545</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13038/">13038</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:118">MDKSA-2004:118</ref></refs><vuln_soft><prod name="RAV AntiVirus for Mail Servers" vendor="RAV AntiVirus"><vers num="8.4.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="eTrust Antivirus Gateway" vendor="Computer Associates"><vers num="7.0"/><vers num="7.1"/></prod><prod name="RAV AntiVirus for File Servers" vendor="RAV AntiVirus"><vers num="1.0"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/><vers num="1.4"/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/></prod><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.4.6"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.79"/><vers num="3.80"/><vers num="3.81"/><vers num="3.82"/><vers num="3.83"/><vers num="3.84"/><vers num="3.85"/><vers num="3.86"/></prod><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/></prod><prod name="RAV AntiVirus Desktop" vendor="RAV AntiVirus"><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1097" published="2005-01-10" seq="2004-1097" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11574">Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17934">Cherokee Web Server format string</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-02.xml">Cherokee: Format string vulnerability</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=67667">http://bugs.gentoo.org/show_bug.cgi?id=67667</ref></refs><vuln_soft><prod name="Cherokee HTTPD" vendor="Cherokee"><vers num="0.1"/><vers num="0.1.5"/><vers num="0.1.6"/><vers num="0.2"/><vers num="0.2.5"/><vers num="0.2.6"/><vers num="0.2.7"/><vers num="0.4.6"/><vers num="0.4.7"/><vers num="0.4.8"/><vers num="0.4.17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1098" published="2005-01-10" seq="2004-1098" severity="High" type="CVE"><desc><descript source="cve">MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17940">MIME-tools boundary bypass virus protection</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11563">Roaring Penguin Software MIMEDefang Multiple Unspecified Vulnerabilities</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-06.xml">MIME-tools: Virus detection evasion</ref><ref source="MLIST" url="http://lists.roaringpenguin.com/pipermail/mimedefang/2004-October/024959.html">20041026 [Mimedefang] SECURITY: Patch for MIME-tools</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:123">MDKSA-2004:123</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:123">MDKSA-2004:123</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="MIMEDefang" vendor="Roaring Penguin"><vers num="2.4"/><vers num="2.14"/><vers num="2.20"/><vers num="2.21"/><vers num="2.38"/><vers num="2.39"/><vers num="2.41"/><vers num="2.42"/><vers num="2.43"/><vers num="2.44"/><vers num="2.45"/><vers num="4.46"/><vers num="4.47"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1099" published="2005-01-10" seq="2004-1099" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a &quot;cryptographically correct&quot; certificate with valid fields such as the username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11577">Cisco Secure Access Control Server Remote Authentication Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17936">Cisco Secure ACS for Windows and Solution Engine EAP-TLS bypass authentication</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-028.shtml">P-028: Cisco Secure Access Control Server (ACS) EAP-TLS Authentication Vulnerability</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml">Cisco Security Advisory: Vulnerability in Cisco Secure Access Control Server EAP-TLS Authentication</ref></refs><vuln_soft><prod name="Secure ACS" vendor="Cisco"><vers num="3.3 (1)"/><vers num="3.3.1"/></prod><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num=""/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1100" published="2005-01-10" seq="2004-1100" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that debug mode is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11596">TIPS MailPost APPEND Variable Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17953">MailPost append cross-site scripting</ref><ref source="CERT" url="http://www.kb.cert.org/vuls/id/107998">MailPost vulnerable to cross-site scripting in the &apos;append&apos; variable passed to the file as part of an HTTP GET request</ref><ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0410.html">http://www.procheckup.com/security_info/vuln_pr0410.html</ref></refs><vuln_soft><prod name="MailPost" vendor="TIPS"><vers num="5.1.1sv"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1101" published="2005-01-10" seq="2004-1101" severity="Medium" type="CVE"><desc><descript source="cve">mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11598">TIPS MailPost Error Message Cross-Site Scripting Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17951">MailPost slash cross-site scripting</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/596046">MailPost vulnerable to cross-site scripting via an executable requested with a trailing slash appended to the filename</ref><ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0411.html">http://www.procheckup.com/security_info/vuln_pr0411.html</ref></refs><vuln_soft><prod name="MailPost" vendor="TIPS"><vers num="5.1.1 sv"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1102" published="2005-01-10" seq="2004-1102" severity="Medium" type="CVE"><desc><descript source="cve">MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allows remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11599">TIPS MailPost Remote File Enumeration Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17954">MailPost HTTP GET information disclosure</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/306086">MailPost vulnerable file system information disclosure via HTTP GET request</ref><ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0408.html">http://www.procheckup.com/security_info/vuln_pr0408.html</ref></refs><vuln_soft><prod name="MailPost" vendor="TIPS"><vers num="5.1.1 sv"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1103" published="2005-01-10" seq="2004-1103" severity="Medium" type="CVE"><desc><descript source="cve">MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11595">TIPS MailPost Remote Debug Mode Information Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17952">MailPost debug mode information disclosure</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/858726">MailPost discloses sensitive system information when operating in debug mode</ref><ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0409.html">http://www.procheckup.com/security_info/vuln_pr0409.html</ref></refs><vuln_soft><prod name="MailPost" vendor="TIPS"><vers num="5.1.1 sv"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1104" published="2004-12-31" seq="2004-1104" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty &quot;href&quot; attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11565">Microsoft Internet Explorer HTML Form Base A Tag Status Bar Spoofing Weakness</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17938">Microsoft Internet Explorer A HREF status bar spoofing</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/702086">Multiple web browsers do not properly interpret BASE and FORM elements when displaying URLs in the status bar</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/379903">20041030 Re: New URL spoofing bug in Microsoft Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded">20060218 Re: Internet Explorer Phishing mouseover issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded">20060223 Re: Internet Explorer Phishing mouseover issue</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11273">11273</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1105" published="2005-01-10" seq="2004-1105" severity="Medium" type="CVE"><desc><descript source="cve">Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17988">Nortel Contivity VPN Client information disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11623">Nortel Contivity VPN Client Username Enumeration Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/830214">Nortel Networks Contivity VPN Client information leakage vulnerability</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/0291.html">Full-Disclosure] Nortel Networks Contivity VPN Client information leakage vulnerability</ref><ref source="MISC" url="http://www.nii.co.in/vuln/contivity.html">http://www.nii.co.in/vuln/contivity.html</ref><ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-626N7F">http://www.kb.cert.org/vuls/id/CRDY-626N7F</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel Networks"><vers num="4.91"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-1106" published="2005-01-10" seq="2004-1106" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via &quot;specially formed URLs,&quot; possibly via the include parameter in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11602">Gallery Unspecified Remote HTML Injection Vulnerability</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17948">Gallery script cross-site scripting</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-10.xml">Gallery: Cross-site scripting vulnerability</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-642">DSA-642</ref><ref source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=142&amp;mode=thread&amp;order=0&amp;thold=0">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=142&amp;mode=thread&amp;order=0&amp;thold=0</ref><ref source="MISC" url="http://g3cko.info/gallery2-4.patch">http://g3cko.info/gallery2-4.patch</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Gallery" vendor="Gallery Project"><vers num="1.4 pl2"/><vers num="1.4 pl1"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3 pl2"/><vers num="1.4.3 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1107" published="2005-01-10" seq="2004-1107" severity="Low" type="CVE"><desc><descript source="cve">dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11616">Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17986">Gentoo Portage dispatch-conf script symlink attack</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml">Portage, Gentoolkit: Temporary file vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=69147">http://bugs.gentoo.org/show_bug.cgi?id=69147</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13108/">13108</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1108" published="2005-01-10" seq="2004-1108" severity="Low" type="CVE"><desc><descript source="cve">qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11617">Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17968">Gentoolkit qpkg utility symlink attack</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml">Portage, Gentoolkit: Temporary file vulnerabilities</ref><ref adv="1" patch="1" source="Secunia" url="http://secunia.com/advisories/13108/">Gentoo Portage/Gentoolkit Insecure Temporary File Creation</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=68846">http://bugs.gentoo.org/show_bug.cgi?id=68846</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1109" published="2005-01-10" seq="2004-1109" severity="Medium" type="CVE"><desc><descript source="cve">The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11639">Kerio Personal Firewall IP Options Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17992">Kerio Personal Firewall (KPF) packet processing denial of service</ref><ref adv="1" source="Kerio" url="http://www.kerio.com/security_advisory.html">Security Advisories</ref><ref source="EEYE" url="http://www.eeye.com/html/research/advisories/AD20041109.html">AD20041109</ref></refs><vuln_soft><prod name="Personal Firewall" vendor="Kerio"><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.16"/><vers num="4.1"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1110" published="2005-01-10" seq="2004-1110" severity="Low" type="CVE"><desc><descript source="cve">The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11640">MTink Insecure Temporary File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18011">mtink temporary file symlink attack</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-17.xml">mtink: Insecure tempfile handling</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=70310">http://bugs.gentoo.org/show_bug.cgi?id=70310</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="mtink" vendor="Jean-Jacques Sarton"><vers num="0.9.32"/><vers num="0.9.33"/><vers num="0.9.52"/><vers num="0.9.53"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1111" published="2005-01-10" seq="2004-1111" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the &quot;no service dhcp&quot; command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18021">Cisco IOS DHCP denial of service</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/630104">Cisco IOS fails to properly handle malformed DHCP packets</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/11649">Cisco IOS DHCP Input Queue Blocking Denial Of Service Vulnerability</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20041110-dhcp.shtml">20041110 Cisco Security Advisory: Cisco IOS DHCP Blocked Interface Denial-of-Service</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-034.shtml">P-034</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-316A.html">TA04-316A</ref></refs><vuln_soft><prod name="7200" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst" vendor="Cisco"><vers num="7600 Sup720/MSFC3"/></prod><prod name="7300" vendor="Cisco"><vers num=""/></prod><prod name="IOS" vendor="Cisco"><vers num="12.2 (20)EW"/><vers num="12.2 (18)SW"/><vers num="12.2 (18)SV"/><vers num="12.2 (18)SE"/><vers num="12.2 (18)S"/><vers num="12.2 (18)EWA"/><vers num="12.2 (18)EW"/><vers num="12.2 (14)SZ"/></prod><prod name="7500" vendor="Cisco"><vers num=""/></prod><prod name="7600" vendor="Cisco"><vers num=""/></prod><prod name="Multiservice Platform" vendor="Cisco"><vers num="2650"/><vers num="2650XM"/><vers num="2651"/><vers num="2651XM"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1112" published="2005-01-10" seq="2004-1112" severity="Medium" type="CVE"><desc><descript source="cve">The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/><race/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11659">Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18037">Cisco Security Agent (CSA) bypass buffer overflow protection</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20041111-csa.shtml">Cisco Security Advisory: Crafted Timed Attack Evades Cisco Security Agent Protections</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-036.shtml">P-036: Crafted Timed Attack Evades Cisco Security Agent Protections</ref></refs><vuln_soft><prod name="StormWatch" vendor="Okena"><vers num="3.x"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="3.x"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1113" published="2005-01-10" seq="2004-1113" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11633">SQLgrey Postfix Greylisting Service SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17998">SQLgrey Postfix greylisting service SQL injection</ref><ref adv="1" patch="1" source="Trustix" url="http://www.trustix.org/errata/2004/0058/">Trustix Secure Linux Security Advisory #2004-0058</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=281256">http://sourceforge.net/project/shownotes.php?release_id=281256</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13135/">13135</ref></refs><vuln_soft><prod name="SQLgrey Postfix Greylisting Service" vendor="SQLgrey"><vers num="1.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2004-1114" published="2005-01-10" seq="2004-1114" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the handling of command line arguments in Skype 1.0.x.94 through 1.0.x.98 allows remote attackers to execute arbitrary code via a callto:// URL with a long non-existent username, a different vulnerability than CVE-2004-1777.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11682">Skype Technologies Skype CallTo URI Buffer Overrun Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18063">Skype callto: URI handler buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110062240706017&amp;w=2">Skype callto:// BoF technical details</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028852.html">20041116 Skype callto:// BoF technical details</ref><ref source="CONFIRM" url="http://www.skype.com/products/skype/windows/changelog.html">http://www.skype.com/products/skype/windows/changelog.html</ref><ref source="CONFIRM" url="http://www.skype.com/security/ssa-2004-02.html">http://www.skype.com/security/ssa-2004-02.html</ref><ref source="OSVDB" url="http://www.osvdb.org/11786">11786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13191">13191</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110067029422696&amp;w=2">20041115 Re: Skype callto:// BoF technical details</ref></refs><vuln_soft><prod name="Skype" vendor="Skype Technologies"><vers num="1.0.0.97"/><vers num="1.0.0.94"/><vers num="1.0.0.9"/><vers num="1.0.0.29"/><vers num="1.0.0.18"/><vers num="1.0.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1115" published="2005-01-10" seq="2004-1115" severity="High" type="CVE"><desc><descript source="cve">The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18149">SETI@home, GIMPS, ChessBrain allows elevated privileges</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml">GIMPS, SETI@home, ChessBrain: Insecure installation</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1116" published="2005-01-10" seq="2004-1116" severity="High" type="CVE"><desc><descript source="cve">The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18149">SETI@home, GIMPS, ChessBrain allows elevated privileges</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml">GIMPS, SETI@home, ChessBrain: Insecure installation</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1117" published="2005-01-10" seq="2004-1117" severity="High" type="CVE"><desc><descript source="cve">The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11700">Gentoo ChessBrain EBuild Insecure Default Permissions Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18149">SETI@home, GIMPS, ChessBrain allows elevated privileges</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml">GIMPS, SETI@home, ChessBrain: Insecure installation</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1118" published="2005-01-10" seq="2004-1118" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18190">wodFtpDLX long filename buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11721">WeOnlyDo! wodFtpDLX ActiveX Component Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110114233323417&amp;w=2">WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html">20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html">20041122 CoffeeCup FTP Clients Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="wodFtpDLX ActiveX component" vendor="WeOnlyDo"><vers num=""/><vers num="2.1.1 8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1119" published="2005-01-10" seq="2004-1119" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11730">Nullsoft Winamp IN_CDDA.dll Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18197">Winamp IN_CDDA.dll file buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123330404482&amp;w=2">Winamp - Buffer Overflow In IN_CDDA.dll</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0369.html">20041126 Re: Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched</ref><ref source="MISC" url="http://www.security-assessment.com/Papers/Winamp_IN_CDDA_Buffer_Overflow.pdf">http://www.security-assessment.com/Papers/Winamp_IN_CDDA_Buffer_Overflow.pdf</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/986504">VU#986504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13269/">13269</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110126352412395&amp;w=2">20041123 Winamp - Buffer Overflow In IN_CDDA.dll</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110146036300803&amp;w=2">20041124 Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched]</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110135574326217&amp;w=2">20041124 Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched]</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.06"/><vers num="5.05"/><vers num="5.04"/><vers num="5.03"/><vers num="5.02"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1120" published="2005-01-10" seq="2004-1120" severity="High" type="CVE"><desc><descript source="cve">Mulitple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11734">ProZilla Multiple Remote Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18210">ProZilla buffer overflow</ref><ref adv="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200411-31.xml">ProZilla: Multiple vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=70090">http://bugs.gentoo.org/show_bug.cgi?id=70090</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/382219">20041124 Prozilla Remote Exploit</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-663">DSA-663</ref></refs><vuln_soft><prod name="ProZilla Download Accelerator" vendor="ProZIlla"><vers num="1.0.0"/><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5.2"/><vers num="1.3.5.1"/><vers num="1.3.5"/><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1121" published="2004-11-01" seq="2004-1121" severity="Medium" type="CVE"><desc><descript source="cve">Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/925430">VU#925430</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11573">11573</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13047/">13047</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17909">ie-table-status-spoofing(17909)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1122" published="2005-01-10" seq="2004-1122" severity="High" type="CVE"><desc><descript source="cve">Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the &quot;Dialog Box Spoofing Vulnerability,&quot; a different vulnerability than CVE-2004-1314.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11469">Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/">Multiple Browsers Dialog Box Spoofing Test</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-10/">http://secunia.com/secunia_research/2004-10/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12892">12892</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html">APPLE-SA-2004-12-02</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1123" published="2005-01-10" seq="2004-1123" severity="Medium" type="CVE"><desc><descript source="cve">Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11802">Apple Mac OS X Multiple Remote And Local Vulnerabilities</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=159&amp;type=vulnerabilities">Apple Darwin Streaming Server DESCRIBE Null Byte Denial of Service Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18357">darwin-describe-dos(18357)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.0.1"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.1"/><vers num="4.1.3"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1124" published="2004-01-14" seq="2004-1124" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.2/SCOSA-2005.2.txt">SCOSA-2005.2</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18970">chroot-jail-security-bypass(18970)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.22/SCOSA-2005.22.txt">SCOSA-2005.22</ref><ref source="BID" url="http://www.securityfocus.com/bid/12300">12300</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13915">13915</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15339">15339</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.4"/><vers num="7.1.3"/><vers num="7.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2004-1125" published="2005-01-10" seq="2004-1125" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12070">XPDF DoImage Remote Buffer Overflow Vulnerability</ref><ref source="CONFIRM" url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patch">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patch</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041223-1.txt">http://www.kde.org/info/security/advisory-20041223-1.txt</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030241.html">20041223 [USN-48-1] xpdf, tetex-bin vulnerabilities</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2353">FLSA:2353</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2352">FLSA:2352</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-13.xml">GLSA-200501-13</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-17.xml">GLSA-200501-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-013.html">RHSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-018.html">RHSA-2005:018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-034.html">RHSA-2005:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-057.html">RHSA-2005:057</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-066.html">RHSA-2005:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-354.html">RHSA-2005:354</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18641">xpdf-gfx-doimage-bo(18641)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=172&amp;type=vulnerabilities">20041221 Multiple Vendor xpdf PDF Viewer Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=110378596500001&amp;r=1&amp;w=2">20041228 KDE Security Advisory: kpdf Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384680309105&amp;w=2">20041223 [USN-50-1] CUPS vulnerabilities</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921">CLA-2005:921</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml">GLSA-200412-25</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1">USN-50-1</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=172&amp;type=vulnerabilities">20041221 Multiple Vendor xpdf PDF Viewer Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=110378596500001&amp;r=1&amp;w=2">20041228 KDE Security Advisory: kpdf Buffer Overflow Vulnerability</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921">CLA-2005:921</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt">SCOSA-2005.42</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17277">17277</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-026.html">RHSA-2005:026</ref><ref source="IDEFENSE" url="http://http://www.idefense.com/application/poi/display?id=172&amp;type=vulnerabilities">20041221 Multiple Vendor xpdf PDF Viewer Buffer Overflow Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012646">1012646</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="3.0"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2.3"/><vers num="3.3.2"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.1.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1127" published="2005-01-10" seq="2004-1127" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11747">Open DC Hub Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18254">Open DC Hub RedirectAll buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110144606411674&amp;w=2">  Buffer Overflow in Open Dc Hub 0.7.14</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029383.html">20041124 Buffer Overflow in Open Dc Hub 0.7.14</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200411-37.xml">GLSA-200411-37</ref></refs><vuln_soft><prod name="Direct Connect Peer-to-peer Client" vendor="Open DC Hub"><vers num="0.7.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1128" published="2005-01-10" seq="2004-1128" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachement with a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11742">Youngzsoft CMailServer Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18276">CMailServer CMailCOM.dll buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2">SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.security.org.sg/vuln/cmailserver52.html">http://www.security.org.sg/vuln/cmailserver52.html</ref></refs><vuln_soft><prod name="CMailServer" vendor="YoungZSoft"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1129" published="2005-01-10" seq="2004-1129" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11742">Youngzsoft CMailServer Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18281">CMailServer fdelmail.asp and addressc.asp SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2">[SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.security.org.sg/vuln/cmailserver52.html">http://www.security.org.sg/vuln/cmailserver52.html</ref></refs><vuln_soft><prod name="CMailServer" vendor="YoungZSoft"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1130" published="2005-01-10" seq="2004-1130" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1) username, (2) name, or (3) comments.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
YoungZSoft, CMailServer, 5.2.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11742">Youngzsoft CMailServer Multiple Remote Vulnerabilities</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18280">CMailServer admin.asp cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2">[SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.security.org.sg/vuln/cmailserver52.html">http://www.security.org.sg/vuln/cmailserver52.html</ref></refs><vuln_soft><prod name="CMailServer" vendor="YoungZSoft"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1131" published="2005-02-07" seq="2004-1131" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.13/SCOSA-2005.13.txt">SCOSA-2005.13</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19243">openserver-enable-bo(19243)</ref><ref patch="1" source="Secunia" url="http://secunia.com/advisories/14176/">SCO OpenServer </ref><ref source="BID" url="http://www.securityfocus.com/bid/12474">
12474</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1133" published="2005-01-10" seq="2004-1133" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as &quot;Connection&quot; or (2) invalid parameters whose values are echoed in the resulting error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11820">Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18375">W3Who HTTP header and error message cross-site scripting</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110234486823233&amp;w=2">20041206 Multiple vulnerabilities in w3who ISAPI DLL</ref></refs><vuln_soft><prod name="w3who.dll" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1134" published="2005-01-10" seq="2004-1134" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11820">Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18377">W3Who buffer overflow</ref><ref source="MISC" url="http://www.exaprobe.com/labs/advisories/esa-2004-1206.html">http://www.exaprobe.com/labs/advisories/esa-2004-1206.html</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110234486823233&amp;w=2">20041206 Multiple vulnerabilities in w3who ISAPI DLL</ref></refs><vuln_soft><prod name="w3who.dll" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1135" published="2005-01-10" seq="2004-1135" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18296">WS_FTP Server FTP commands buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110177654524819&amp;w=2">Multiple buffer overlows in WS_FTP Server Version 5.03, 2004.10.14.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029600.html">20041129 Multiple buffer overlows in WS_FTP Server Version 5.03, 2004.10.14.</ref><ref source="MISC" url="http://www.securiteam.com/exploits/6D00L2KBPG.html">http://www.securiteam.com/exploits/6D00L2KBPG.html</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="5.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1136" published="2005-01-10" seq="2004-1136" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18309">CuteFTP reply buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11776">GlobalScape CuteFTP Multiple Command Response Buffer Overflow Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110182983622642&amp;w=2">20041129 CuteFTP 6.0 Professional Remote Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="CuteFTP" vendor="globalSCAPE"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1137" published="2005-01-10" seq="2004-1137" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11917">Linux Kernel IGMP Multiple Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2">[USN-38-1] Linux kernel vulnerabilities</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0018-igmp.txt">http://isec.pl/vulnerabilities/isec-0018-igmp.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18482">linux-igmpmarksources-dos(18482)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18481">linux-ipmcsource-code-execution(18481)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html">SUSE-SA:2004:044</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1138" published="2005-01-10" seq="2004-1138" severity="High" type="CVE"><desc><descript source="cve">VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11941">Vim Modelines Arbitrary Command Execution Variant Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110313588125609&amp;w=2"> [OpenPKG-SA-2004.052] OpenPKG Security Advisory (vim)</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200412-10.xml">Vim, gVim: Vulnerable options in modelines</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2343">FLSA:2343</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-010.html">RHSA-2005:010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-036.html">RHSA-2005:036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18503">vim-modeline-gain-privileges(18503)</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.6"/><vers num="5.7"/><vers num="5.8"/><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3.044"/><vers num="6.3.030"/><vers num="6.3.025"/><vers num="6.3.011"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1139" published="2004-12-15" seq="2004-1139" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00016.html">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml">GLSA-200412-15</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-061.shtml">P-061</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11943">11943</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13468/">13468</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18484">ethereal-dicom-dos(18484)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1140" published="2004-12-31" seq="2004-1140" severity="Medium" type="CVE"><desc><descript source="cve">Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (application hang) and possibly fill available disk space via an invalid RTP timestamp.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00016.html">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml">GLSA-200412-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-061.shtml">P-061</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13468/">13468</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11943">11943</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18485">Ethereal-rtp-dos(18485)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1141" published="2004-12-31" seq="2004-1141" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00016.html">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml">GLSA-200412-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-061.shtml">P-061</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13468/">13468</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18487">ethereal-http-dissector-dos(18487)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11943">11943</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1142" published="2004-12-15" seq="2004-1142" severity="Medium" type="CVE"><desc><descript source="cve">Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00016.html">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916">CLA-2005:916</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-613">DSA-613</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml">GLSA-200412-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-061.shtml">P-061</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13468/">13468</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11943">11943</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18488">ethereal-smb-dos(18488)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152">MDKSA-2004:152</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1143" published="2004-12-31" seq="2004-1143" severity="High" type="CVE"><desc><descript source="cve">The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2">20050110 [USN-59-1] mailman vulnerabilities</ref><ref patch="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13603/">13603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18857">mailman-weak-encryption(18857)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html">SUSE-SA:2005:007</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1b1"/><vers num="2.1"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0 beta5"/><vers num="2.0 beta4"/><vers num="2.0 beta3"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1144" published="2004-12-31" seq="2004-1144" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-689.html">RHSA-2004:689</ref><ref patch="1" source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110376890429798&amp;w=2">SUSE-SA:2004:046</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18686">linux-32bit-emulation-gain-privileges(18686)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1145" published="2004-12-15" seq="2004-1145" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.heise.de/security/dienste/browsercheck/tests/java.shtml">http://www.heise.de/security/dienste/browsercheck/tests/java.shtml</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356286722875&amp;w=2">20041220 KDE Security Advisory: Konqueror Java Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041220-1.txt">http://www.kde.org/info/security/advisory-20041220-1.txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-16.xml">GLSA-200501-16</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:154">MDKSA-2004:154</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-065.html">RHSA-2005:065</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18596">konqueror-sandbox-restriction-bypass(18596)</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/420222">VU#420222</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13586">13586</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:154">MDKSA-2004:154</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1146" published="2004-12-31" seq="2004-1146" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html">20041223 Cross-Site Scripting - an industry-wide problem</ref><ref source="MISC" url="http://www.mikx.de/index.php?p=6">http://www.mikx.de/index.php?p=6</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110332469631253&amp;w=2">20041217 [OpenPKG-SA-2004.056] OpenPKG Security Advisory (cvstrac)</ref><ref patch="1" source="CONFIRM" url="http://www.cvstrac.org/cvstrac/chngview?cn=321">http://www.cvstrac.org/cvstrac/chngview?cn=321</ref><ref patch="1" source="CONFIRM" url="http://www.cvstrac.org/cvstrac/chngview?cn=320">http://www.cvstrac.org/cvstrac/chngview?cn=320</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12017">12017</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18726">cvstrac-main-login-xss(18726)</ref></refs><vuln_soft><prod name="CVSTrac" vendor="CVSTrac"><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1147" published="2005-01-10" seq="2004-1147" severity="High" type="CVE"><desc><descript source="cve">phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11886">phpMyAdmin Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295781828323&amp;w=2">Multiple vulnerabilities in phpMyAdmin</ref><ref source="MISC" url="http://www.exaprobe.com/labs/advisories/esa-2004-1213.html">http://www.exaprobe.com/labs/advisories/esa-2004-1213.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18441">phpmyadmin-command-execute(18441)</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.4.0"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.4"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/><vers num="2.5.6 rc1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1148" published="2005-01-10" seq="2004-1148" severity="Medium" type="CVE"><desc><descript source="cve">phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11886/">phpMyAdmin Multiple Remote Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295781828323&amp;w=2">Multiple vulnerabilities in phpMyAdmin</ref><ref source="MISC" url="http://www.exaprobe.com/labs/advisories/esa-2004-1213.html">http://www.exaprobe.com/labs/advisories/esa-2004-1213.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18441">phpmyadmin-command-execute(18441)</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.4.0"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.4"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/><vers num="2.5.6 rc1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1149" published="2005-01-10" seq="2004-1149" severity="High" type="CVE"><desc><descript source="cve">Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11971">Computer Associates eTrust EZ Antivirus Local Insecure Default Installation Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=164">20041215 Computer Associates eTrust EZ Antivirus Insecure File Permission Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18502">etrust-antivirus-insecure-permissions(18502)</ref><ref source="" url="http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter"></ref></refs><vuln_soft><prod name="eTrust EZ Antivirus" vendor="Computer Associates"><vers num="7.0"/><vers num="7.0.1.4"/><vers num="7.0.1.3"/><vers num="7.0.1.2"/><vers num="7.0.1.1"/><vers num="7.0.1"/><vers num="7.0.2.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1150" published="2004-12-31" seq="2004-1150" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110684140108614&amp;w=2">20050127 NSFOCUS SA2005-01 : Buffer Overflow in WinAMP in_cdda.dll CDA Device Name</ref><ref source="MISC" url="http://www.nsfocus.com/english/homepage/research/0501.htm">http://www.nsfocus.com/english/homepage/research/0501.htm</ref><ref source="CONFIRM" url="http://www.winamp.com/player/version_history.php">http://www.winamp.com/player/version_history.php</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18840">winamp-incdda-bo(18840)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12381">12381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13781">13781</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.08c"/><vers num="5.07"/><vers num="5.06"/><vers num="5.05"/><vers num="5.04"/><vers num="5.03"/><vers num="5.02"/><vers num="5.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1151" published="2005-01-10" seq="2004-1151" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local attackers to modify kernel memory and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2">[USN-38-1] Linux kernel vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11938">Linux Kernel Sys32_NI_Syscall/Sys32_VM86_Warning Local Buffer Overflow Vulnerability</ref><ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0411.3/1467.html">[linux-kernel] 20041130 Buffer overrun in arch/x86_64/sys_ia32.c:sys32_ni_syscall()</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/cset@1.2079">http://linux.bkbits.net:8080/linux-2.6/cset@1.2079</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/gnupatch@41ae6af1cR3mJYlW6D8EHxCKSxuJiQ">http://linux.bkbits.net:8080/linux-2.6/gnupatch@41ae6af1cR3mJYlW6D8EHxCKSxuJiQ</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html">SUSE-SA:2004:044</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1152" published="2005-01-10" seq="2004-1152" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11923">Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=161&amp;type=vulnerabilities&amp;flashstatus=false">Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability</ref><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/331153.html">http://www.adobe.com/support/techdocs/331153.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18477">adobe-acrobat-maillistlspdf-bo(18477)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/253024">VU#253024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13474">13474</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers edition="UNIX" num="5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1153" published="2005-01-10" seq="2004-1153" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=163&amp;type=vulnerabilities">Adobe Reader 6.0 .ETD File Format String Vulnerability</ref><ref source="CONFIRM" url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18478">adobe-acrobat-etd-format-string(18478)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2919.html">OVAL2919</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2919">oval:org.mitre.oval:def:2919</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0"/><vers num=""/><vers num="6.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1154" published="2005-01-10" seq="2004-1154" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/11973/">Samba Directory Access Control List Remote Integer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18519">Samba MS-RPC request heap corruption</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/226184">Samba vulnerable to integer overflow processing file security descriptors</ref><ref source="CONFIRM" url="http://www.samba.org/samba/security/CAN-2004-1154.html">http://www.samba.org/samba/security/CAN-2004-1154.html</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-701">DSA-701</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-020.html">RHSA-2005:020</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt">SCOSA-2005.17</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_45_samba.html">SUSE-SA:2004:045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13453/">13453</ref><ref source="BID" url="http://www.securityfocus.com/bid/11973">11973</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=165&amp;type=vulnerabilities">20041216 Samba smbd Security Descriptor Integer Overflow Vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101643-1">101643</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57730-1">57730</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1459">oval:org.mitre.oval:def:1459</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:642">oval:org.mitre.oval:def:642</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/><vers num="2.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Samba" vendor="Samba"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.2a"/><vers num="2.2.0a"/><vers num="2.2.0"/><vers num="2.2.1a"/><vers num="2.2.2"/><vers num="2.2.3a"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7a"/><vers num="2.2.7"/><vers num="2.2.8a"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2a"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4 r1"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-1155" published="2004-12-31" seq="2004-1155" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability.  NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11855">Microsoft Internet Explorer Remote Window Hijacking Vulnerability</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">Multiple Browsers Window Injection Vulnerability Test</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13251/">13251</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22628">22628</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449917/100/0/threaded">20061025 IE7 status: 8 days after release, 3 unfixed issues</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5 preview"/><vers num="5.5"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers edition="Macintosh" num="5.2.3"/><vers edition="Windows XP SP2" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-1156" published="2004-12-31" seq="2004-1156" severity="High" type="CVE"><desc><descript source="cve">Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11854/">Mozilla Browser and Mozilla Firefox Remote Window Hijacking Vulnerability</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref><ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-13.html">http://www.mozilla.org/security/announce/mfsa2005-13.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13129/">13129</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100045.html">OVAL100045</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100045">oval:org.mitre.oval:def:100045</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="0.8"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.35"/><vers num="0.9.48"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.5"/><vers num="1.5.1"/><vers num="1.6"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.10"/><vers num="0.10.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1157" published="2005-01-10" seq="2004-1157" severity="High" type="CVE"><desc><descript source="cve">Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Secunia" url="http://secunia.com/advisories/13253/">Opera Window Injection Vulnerability</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1158" published="2005-01-10" seq="2004-1158" severity="High" type="CVE"><desc><descript source="cve">Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11853">KDE Konqueror Remote Window Hijacking Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110296048613575&amp;w=2">KDE Security Advisory: Konqueror Window Injection Vulnerability</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">Multiple Browsers Window Injection Vulnerability Test</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13254/">13254</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041213-1.txt">http://www.kde.org/info/security/advisory-20041213-1.txt</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-009.html">RHSA-2005:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13254">13254</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13560">13560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13477">13477</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13486">13486</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Konqueror" vendor="KDE"><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.5b"/><vers num="3.0.5"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.2.1"/><vers num="3.2.2.6"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry modified="2005-11-04" name="CVE-2004-1159" published="2005-01-10" reject="1" seq="2004-1159" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1122, CVE-2004-1314.  Reason: this was an out-of-band assignment duplicate intended for one issue, but the description and references inadvertently combined multiple issues.  Notes: All CVE users should consult CVE-2004-1122 and CVE-2004-1314 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1160" published="2005-01-10" seq="2004-1160" severity="High" type="CVE"><desc><descript source="cve">Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11852">Netscape Remote Window Hijacking Vulnerability</ref><ref adv="1" source="Secunia" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">Multiple Browsers Window Injection Vulnerability Test</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13402/">13402</ref></refs><vuln_soft><prod name="Netscape" vendor="Netscape"><vers num="7.0"/></prod><prod name="Navigator" vendor="Netscape"><vers num="7.0"/><vers num="7.0.2"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1161" published="2005-01-10" seq="2004-1161" severity="High" type="CVE"><desc><descript source="cve">rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11792">RSSH Remote Arbitrary Command Execution Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202047507273&amp;w=2">rssh and scponly arbitrary command execution</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200412-01.xml">rssh, scponly: Unrestricted command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581113814623&amp;w=2">20050115 Re: rssh and scponly arbitrary command execution</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="rssh" vendor="rssh"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1162" published="2005-01-10" seq="2004-1162" severity="High" type="CVE"><desc><descript source="cve">The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11791">SCPOnly Remote Arbitrary Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18362">scponly command line command execution</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-01.xml">GLSA-200412-01</ref><ref source="CONFIRM" url="http://www.sublimation.org/scponly/#relnotes">http://www.sublimation.org/scponly/#relnotes</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202047507273&amp;w=2">20041202 rssh and scponly arbitrary command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581113814623&amp;w=2">20050115 Re: rssh and scponly arbitrary command execution</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="scponly" vendor="scponly"><vers num="2.0"/><vers num="2.1"/><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/><vers num="3.5"/><vers num="3.8"/><vers num="3.9"/><vers num="3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1163" published="2005-01-10" seq="2004-1163" severity="Medium" type="CVE"><desc><descript source="cve">Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18327">Cisco CNS Network Registrar CCM denial of service</ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a008036786d.shtml">20041202 Cisco Network Registrar Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="CNS Network Registrar" vendor="Cisco"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5 .4"/><vers num="6.0.5 .3"/><vers num="6.0.5 .2"/><vers num="6.0.5"/><vers num="6.1"/><vers num="6.1.1 .3"/><vers num="6.1.1 .2"/><vers num="6.1.1 .1"/><vers num="6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1164" published="2005-01-10" seq="2004-1164" severity="Medium" type="CVE"><desc><descript source="cve">The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain &quot;unexpected packet sequence.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11793">Cisco CNS Network Registrar DNS and DHCP Server Remote Denial of Service Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18328">Cisco CNS Network Registrar lock manager denial of service</ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a008036786d.shtml">20041202 Cisco Network Registrar Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="CNS Network Registrar" vendor="Cisco"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5 .4"/><vers num="6.0.5 .3"/><vers num="6.0.5 .2"/><vers num="6.0.5"/><vers num="6.1"/><vers num="6.1.1 .3"/><vers num="6.1.1 .2"/><vers num="6.1.1 .1"/><vers num="6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1165" published="2005-01-10" seq="2004-1165" severity="High" type="CVE"><desc><descript source="cve">Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline (&quot;%0a&quot;) before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18384">Multiple Web browsers FTP command execution</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11827">KDE Konqueror FTP URI Arbitrary FTP Server Command Execution Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-631">DSA-631</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-18.xml">GLSA-200501-18</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:045">MDKSA-2005:045</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-009.html">RHSA-2005:009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-065.html">RHSA-2005:065</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245752232681&amp;w=2">20041205 7a69Adv#16 - Konqueror FTP command injection</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:045">MDKSA-2005:045</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.3.1"/></prod><prod name="kdelibs" vendor="KDE"><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-21" name="CVE-2004-1166" published="2004-12-31" seq="2004-1166" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline (&quot;%0a&quot;) before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11826">Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18384">Multiple Web browsers FTP command execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110253463305359&amp;w=2">20041207 7a69Adv#15 - Internet Explorer FTP command injection</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx">MS06-042</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3212">ADV-2006-3212</ref><ref source="OSVDB" url="http://www.osvdb.org/12299">12299</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012444">1012444</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13404">13404</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:462">oval:org.mitre.oval:def:462</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489500/100/0/threaded">20080313 Rapid7 Advisory R7-0032: Microsoft Internet Explorer FTP Command Injection Vulnerability</ref><ref source="" url="http://www.rapid7.com/advisories/R7-0032.jsp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28208">28208</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0870">ADV-2008-0870</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29346">29346</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1167" published="2005-01-10" seq="2004-1167" severity="Medium" type="CVE"><desc><descript source="cve">mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11835">Gentoo MirrorSelect Local Insecure File Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18382">mirrorselect symlink attack</ref><ref adv="1" patch="1" source="Gentoo" url="http://www.gentoo.org/security/en/glsa/glsa-200412-05.xml">mirrorselect: Insecure temporary file creation</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13392/">13392</ref></refs><vuln_soft><prod name="mirrorselect" vendor="Gentoo"><vers num="0.80"/><vers num="0.81"/><vers num="0.82"/><vers num="0.83"/><vers num="0.84"/><vers num="0.85"/><vers num="0.86"/><vers num="0.87"/><vers num="0.88"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-1168" published="2005-01-10" seq="2004-1168" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a long Overwrite header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11844">MySQL MaxDB WebDav Handler Overwrite Header Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18386">MaxDB WebDav buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2">MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2">20041207 MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-1169" published="2005-01-10" seq="2004-1169" severity="Medium" type="CVE"><desc><descript source="cve">MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11843/">MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18387">MaxDB denial of service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2">MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2">20041207 MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1170" published="2005-01-10" seq="2004-1170" severity="High" type="CVE"><desc><descript source="cve">a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11025">GNU a2ps File Name Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17127">GNU a2ps allows elevated privileges</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1026.html">[Full-Disclosure] a2ps executing shell commands from file name</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:140">MDKSA-2004:140</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html">SUSE-SA:2004:034</ref><ref source="CONFIRM" url="http://bugs.debian.org/283134">http://bugs.debian.org/283134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12375">12375</ref><ref source="MISC" url="http://www.securiteam.com/unixfocus/5MP0N2KDPA.html">http://www.securiteam.com/unixfocus/5MP0N2KDPA.html</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419765/100/0/threaded">FLSA:152870</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57649-1&amp;searchclause=">57649</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110598355226660&amp;w=2">OpenPKG-SA-2005.003</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:140">MDKSA-2004:140</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="a2ps" vendor="GNU"><vers num="4.13b"/><vers num="4.13"/></prod><prod name="Java Desktop System" vendor="Sun"><vers num="2003"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1171" published="2005-01-10" seq="2004-1171" severity="Low" type="CVE"><desc><descript source="cve">KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user&apos;s .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11866">KDE Plaintext Password Disclosure Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/305294">Shortcuts may insecurely store SMB authentication information</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110178786809694&amp;w=2"> Password Disclosure for SMB Shares in KDE&apos;s Konqueror</ref><ref source="MISC" url="http://www.sec-consult.com/index.php?id=118">http://www.sec-consult.com/index.php?id=118</ref><ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20041209-1.txt"> http://www.kde.org/info/security/advisory-20041209-1.txt</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1292.html">20041129 Password Disclosure for SMB Shares in KDE&apos;s Konqueror</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-16.xml">GLSA-200412-16</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:150">MDKSA-2004:150</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-051.shtml">P-051</ref><ref source="OSVDB" url="http://www.osvdb.org/12248">12248</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012471">1012471</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13560">13560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13477">13477</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13486">13486</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18267">kde-smb-password-plaintext(18267)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110261063201488&amp;w=2">20041209 KDE Security Advisory: plain text password exposure</ref><ref source="" url="http://www.kde.org/info/security/advisory-20041209-1.txt"></ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2004-1172" published="2005-01-10" seq="2004-1172" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11974">VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=169">20041216 Veritas Backup Exec Agent Browser Registration Request Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://www.frsirt.com/exploits/20050111.101_BXEC.cpp.php">http://www.frsirt.com/exploits/20050111.101_BXEC.cpp.php</ref><ref source="CONFIRM" url="http://seer.support.veritas.com/docs/273419.htm">http://seer.support.veritas.com/docs/273419.htm</ref><ref source="CONFIRM" url="http://seer.support.veritas.com/docs/273420.htm">http://seer.support.veritas.com/docs/273420.htm</ref><ref source="CONFIRM" url="http://seer.support.veritas.com/docs/273422.htm">http://seer.support.veritas.com/docs/273422.htm</ref><ref source="CONFIRM" url="http://seer.support.veritas.com/docs/273850.htm">http://seer.support.veritas.com/docs/273850.htm</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/907729">VU#907729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13495/">13495</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18506">netbackup-agent-browser-bo(18506)</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="8.0"/><vers num="8.5"/><vers num="8.6"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-1173" published="2004-12-31" seq="2004-1173" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110271114525795&amp;w=2">HOW TO BREAK XP SP2 POPUP BLOCKER: kick it in the nut !</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110271114525795&amp;w=2">20041210 HOW TO BREAK XP SP2 POPUP BLOCKER: kick it in the nut !</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110271016129952&amp;w=2">20041210 HOW TO BREAK XP SP2 POPUP BLOCKER: kick it in the nut !</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18444">ie-popup-blocking-bypass(18444)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1174" published="2005-04-14" seq="2004-1174" severity="Medium" type="CVE"><desc><descript source="cve">direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by &quot;manipulating non-existing file handles.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" patch="1" source="Security Tracker" url="http://securitytracker.com/alerts/2005/Jan/1012903.html">Midnight Commander Format String, Buffer Overflow, and Memory Allocation Errors May Let Remote Users Deny Service or Execute Arbitrary Code</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18909">midnight-commander-direntry-dos(18909)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012903">1012903</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1175" published="2005-04-14" seq="2004-1175" severity="High" type="CVE"><desc><descript source="cve">fish.c in midnight commander allows remote attackers execute arbitrary programs via &quot;insecure filename quoting,&quot; possibly using shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863/">Debian update for mc</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18906">Midnight Commander command execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="MISC" url="http://securitytracker.com/alerts/2005/Jan/1012903.html">http://securitytracker.com/alerts/2005/Jan/1012903.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012903">1012903</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1176" published="2005-04-14" seq="2004-1176" severity="High" type="CVE"><desc><descript source="cve">Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-639">mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13863">Debian update for mc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12263">bid 12263</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml">GLSA-200502-24</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-217.html">RHSA-2005:217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18911">midnight-commander-extfs-dos(18911)</ref><ref source="MISC" url="http://securitytracker.com/alerts/2005/Jan/1012903.html">http://securitytracker.com/alerts/2005/Jan/1012903.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012903">1012903</ref></refs><vuln_soft><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.54"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1177" published="2005-01-10" seq="2004-1177" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2">20050110 [USN-59-1] mailman vulnerabilities</ref><ref patch="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-674">DSA-674</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:015">MDKSA-2005:015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13603">13603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18854">mailman-script-driver-xss(18854)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-235.html">RHSA-2005:235</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:015">MDKSA-2005:015</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html">SUSE-SA:2005:007</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1b1"/><vers num="2.1"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0 beta5"/><vers num="2.0 beta4"/><vers num="2.0 beta3"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1179" published="2004-12-31" seq="2004-1179" severity="Low" type="CVE"><desc><descript source="cve">The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2004/dsa-615">DSA-615</ref><ref patch="1" source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-12/0645.html">20041223 [USN-49-1] debmake vulnerability</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13633/">13633</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12078">12078</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18646">debmake-debstd-symlink(18646)</ref></refs><vuln_soft><prod name="debmake" vendor="Debian"><vers num="3.6.9" prev="1"/><vers num="3.6"/><vers num="3.7.6" prev="1"/><vers num="3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1180" published="2004-02-16" seq="2004-1180" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-678">DSA-678</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:039">MDKSA-2005:039</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14309">14309</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:039">MDKSA-2005:039</ref></refs><vuln_soft><prod name="Mandrake Linux Corporate Server" vendor="MandrakeSoft"><vers num="2.1"/><vers num="2.1 X86_64"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/><vers edition="AMD64" num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="9.0"/><vers num=""/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="woody" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1181" published="2005-04-14" seq="2004-1181" severity="Medium" type="CVE"><desc><descript source="cve">htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-622">htmlheadline -- insecure temporary files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12147">bid 12147</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18737">HtmlHeadLine.sh symlink attack</ref><ref adv="1" patch="1" source="Security Tracker" url="http://www.securitytracker.com/alerts/2005/Jan/1012756.html">HtmlHeadLine.sh Unsafe Temporary Files May Let Local Users Gain Elevated Privileges</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012756">1012756</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13715">13715</ref></refs><vuln_soft><prod name="HtmlHeadline" vendor="Toshiaki Kanosue"><vers num="21.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1182" published="2004-12-31" seq="2004-1182" severity="High" type="CVE"><desc><descript source="cve">hfaxd in HylaFAX before 4.2.1, when installed with a &quot;weak&quot; hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110546971307585&amp;w=2">20050111 HylaFAX hfaxd unauthorized login vulnerability</ref><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=hylafax&amp;m=110545119911558&amp;w=2">[hylafax-announce] 20050111 **ANOUNCE** hylafax-4.2.1 released</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-21.xml">GLSA-200501-21</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:006">MDKSA-2005:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13812">13812</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:006">MDKSA-2005:006</ref></refs><vuln_soft><prod name="Hylafax" vendor="Hylafax"><vers num="4.2.0"/><vers num="4.1.8"/><vers num="4.1.7"/><vers num="4.1.6"/><vers num="4.1.5"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1 beta1"/><vers num="4.1 beta2"/><vers num="4.1 beta3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1183" published="2005-01-06" seq="2004-1183" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000920">CLA-2005:920</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-06.xml">GLSA-200501-06</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:001">MDKSA-2005:001</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:002">MDKSA-2005:002</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-019.html">RHSA-2005:019</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-035.html">RHSA-2005:035</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html">SUSE-SA:2005:001</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503635113419&amp;w=2">20050106 [USN-54-1] TIFF library tool vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13728/">13728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18782">libtiff-tiffdump-bo(18782)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12173">12173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13776">13776</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:001">MDKSA-2005:001</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:002">MDKSA-2005:002</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1184" published="2005-01-21" seq="2004-1184" severity="Medium" type="CVE"><desc><descript source="cve">The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-654">DSA-654</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml">GLSA-200502-03</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-040.html">RHSA-2005:040</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667231323871&amp;w=2">20050124 [USN-68-1] enscript vulnerabilities</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19012">enscript-epsf-command-ececution(19012)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded">FLSA:152892</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1">USN-68-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012965">1012965</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded">20060526 rPSA-2006-0083-1 enscript</ref><ref source="BID" url="http://www.securityfocus.com/bid/12329">12329</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="Enscript" vendor="GNU"><vers num="1.6.4"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1185" published="2005-01-21" seq="2004-1185" severity="High" type="CVE"><desc><descript source="cve">Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-654">DSA-654</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml">GLSA-200502-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-040.html">RHSA-2005:040</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667231323871&amp;w=2">20050124 [USN-68-1] enscript vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19029">enscript-filename-command-execution(19029)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded">FLSA:152892</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1">USN-68-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012965">1012965</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded">20060526 rPSA-2006-0083-1 enscript</ref><ref source="BID" url="http://www.securityfocus.com/bid/12329">12329</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref></refs><vuln_soft><prod name="Enscript" vendor="GNU"><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6.0"/><vers num="1.5.0"/><vers num="1.4.0"/><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1186" published="2004-12-31" seq="2004-1186" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-654">DSA-654</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml">GLSA-200502-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-040.html">RHSA-2005:040</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667231323871&amp;w=2">20050124 [USN-68-1] enscript vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19033">enscript-multiple-bo(19033)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded">FLSA:152892</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1">USN-68-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012965">1012965</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded">20060526 rPSA-2006-0083-1 enscript</ref><ref source="BID" url="http://www.securityfocus.com/bid/12329">12329</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033">MDKSA-2005:033</ref></refs><vuln_soft><prod name="Enscript" vendor="GNU"><vers num="1.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1187" published="2005-01-10" seq="2004-1187" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12076">MPlayer And Xine PNM_Get_Chunk Multiple Remote Client-Side Buffer Overflow Vulnerabilities</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=176&amp;type=vulnerabilities">Multiple Vendor Xine 0.99.2 PNM Handler PNA_TAG Heap Overflow Vulnerability</ref><ref source="CONFIRM" url="http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff">http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18640">xine-pnatag-bo(18640)</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref></refs><vuln_soft><prod name="xine" vendor="xine"><vers num="1 rc8"/><vers num="1 rc7"/><vers num="1 rc6a"/><vers num="1 rc6"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0a"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/><vers num="0.9.8"/><vers num="0.9.13"/><vers num="0.9.18"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Mplayer" vendor="Mplayer"><vers num="HEAD CVS"/><vers num="0.92 cvs"/><vers num="0.90 rc4"/><vers num="0.90 rc"/><vers num="0.90 pre"/><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.92.1"/><vers num="1.0 pre5try2"/><vers num="1.0 pre5try1"/><vers num="1.0 pre5"/><vers num="1.0 pre4"/><vers num="1.0 pre3try2"/><vers num="1.0 pre3"/><vers num="1.0 pre2"/><vers num="1.0 pre1"/></prod><prod name="xine-lib" vendor="xine"><vers num="1 rc7"/><vers num="1 rc6a"/><vers num="1 rc6"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/><vers num="0.9.8"/><vers num="0.9.13"/><vers num="0.99"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1188" published="2005-01-10" seq="2004-1188" severity="High" type="CVE"><desc><descript source="cve">The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12076/">MPlayer And Xine PNM_Get_Chunk Multiple Remote Client-Side Buffer Overflow Vulnerabilities</ref><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=177&amp;type=vulnerabilities">Multiple Vendor Xine 0.99.2 PNM Handler Negative Read Length Overflow Vulnerability</ref><ref source="CONFIRM" url="http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff">http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18638">xine-pnmgetchunk-bo(18638)</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref></refs><vuln_soft><prod name="xine" vendor="xine"><vers num="1 rc8"/><vers num="1 rc7"/><vers num="1 rc6a"/><vers num="1 rc6"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0a"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/><vers num="0.9.8"/><vers num="0.9.13"/><vers num="0.9.18"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Mplayer" vendor="Mplayer"><vers num="HEAD CVS"/><vers num="0.92 cvs"/><vers num="0.90 rc4"/><vers num="0.90 rc"/><vers num="0.90 pre"/><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.92.1"/><vers num="1.0 pre5try2"/><vers num="1.0 pre5try1"/><vers num="1.0 pre5"/><vers num="1.0 pre4"/><vers num="1.0 pre3try2"/><vers num="1.0 pre3"/><vers num="1.0 pre2"/><vers num="1.0 pre1"/></prod><prod name="xine-lib" vendor="xine"><vers num="1 rc7"/><vers num="1 rc6a"/><vers num="1 rc6"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/><vers num="0.9.8"/><vers num="0.9.13"/><vers num="0.99"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1189" published="2004-12-31" seq="2004-1189" severity="High" type="CVE"><desc><descript source="cve">The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy&apos;s history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txt</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110358420909358&amp;w=2">20041220 MITKRB5-SA-2004-004: heap overflow in libkadm5srv</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000917">CLA-2005:917</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:156">MDKSA-2004:156</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-012.html">RHSA-2005:012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-045.html">RHSA-2005:045</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0069">2004-0069</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548298407590&amp;w=2">20050110 [USN-58-1] MIT Kerberos server vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18621">kerberos-libkadm5srv-bo(18621)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:156">MDKSA-2004:156</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.5" prev="1"/><vers num="1.3.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1190" published="2005-01-10" seq="2004-1190" severity="Low" type="CVE"><desc><descript source="cve">SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SuSE" url="http://www.suse.de/de/security/2004_42_kernel.html">Online Security Support</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_42_kernel.html">SUSE-SA:2004:042</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18370">suse-scsi-firmware-overwrite(18370)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0101.html">RHSA-2006:0101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18510">18510</ref><ref source="BID" url="http://www.securityfocus.com/bid/11784">11784</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8.2"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1191" published="2005-01-10" seq="2004-1191" severity="Low" type="CVE"><desc><descript source="cve">Race condition in SuSE Linux 8.1 through 9.2, when run on SMP systems that have more than 4GB of memory, could allow local users to read unauthorized memory from &quot;foreign memory pages.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="SuSE" url="http://www.suse.de/de/security/2004_42_kernel.html">Online Security Support</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_42_kernel.html">SuSE-SA:2004:042</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18137">linux-smbrecvtrans2-memory-leak(18137)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num=""/><vers num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-1192" published="2005-01-10" seq="2004-1192" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11885/">Citadel/UX Network Data Logging Remote Format String Vulnerability</ref><ref source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-09.txt">http://www.nosystem.com.ar/advisories/advisory-09.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18429">citadel-format-string(18429)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295469430696&amp;w=2">20041213 Citadel/UX &lt;= v6.27 Remote Format String Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304986223400&amp;w=2">20041214 Re: Citadel/UX &lt;= v6.27 Remote Format String Vulnerability</ref></refs><vuln_soft><prod name="Citadel_UX" vendor="Citadel"><vers num="6.08"/><vers num="6.07"/><vers num="6.23"/><vers num="6.24"/><vers num="6.26"/><vers num="6.27"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1193" published="2005-01-10" seq="2004-1193" severity="Medium" type="CVE"><desc><descript source="cve">Prevx Home 1.0 allows local users with adminstrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel&apos;s original SDT ServiceTable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18195">Prevx Home disable protection settings</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110138413816367&amp;w=2">20041124 Re: [SIG^2 G-TEC] Prevx Home v1.0 Instrusion Prevention Features Can Be Disabled by Direct Service Table Restoration </ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110118902823639&amp;w=2">20041122 [SIG^2 G-TEC] Prevx Home v1.0 Instrusion Prevention Features Can Be Disabled by Direct Service Table Restoration</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Nov/1012294.html">http://www.securitytracker.com/alerts/2004/Nov/1012294.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012294">1012294</ref></refs><vuln_soft><prod name="Prevx Home" vendor="Prevx"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1194" published="2005-01-10" seq="2004-1194" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11750">LucasArts Star Wars Battlefront Game Server Multiple Remote Denial Of Service Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18256">Star Wars Battlefront long nickname buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132227932050&amp;w=2">20041124 Limited buffer-overflow and arbitrary memory access in Star Wars</ref></refs><vuln_soft><prod name="Star Wars Battlefront" vendor="LucasArts"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1195" published="2005-01-10" seq="2004-1195" severity="Medium" type="CVE"><desc><descript source="cve">Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11750">LucasArts Star Wars Battlefront Game Server Multiple Remote Denial Of Service Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18257">Star Wars Battlefront packet denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132227932050&amp;w=2">20041124 Limited buffer-overflow and arbitrary memory access in Star Wars Battlefront 1.1</ref></refs><vuln_soft><prod name="Star Wars Battlefront" vendor="LucasArts"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1196" published="2005-01-10" seq="2004-1196" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11758">InShop and InMail Cross-Site Scripting Vulnerabilities</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18268">Insite&apos;s InMail and inShop cross-site scripting</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13188/">13188</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140029419018&amp;w=2">20041124 XSS in Brazilian Insite products</ref></refs><vuln_soft><prod name="InMail" vendor="Insite"><vers num=""/></prod><prod name="InShop" vendor="Insite"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1197" published="2005-01-10" seq="2004-1197" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11758">InShop and InMail Cross-Site Scripting Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18268">Insite&apos;s InMail and inShop cross-site scripting</ref><ref adv="1" source="Secunia" url="http://secunia.com/advisories/13188/">Insite InMail / inShop Cross-Site Scripting Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140029419018&amp;w=2">20041124 XSS in Brazilian Insite products</ref></refs><vuln_soft><prod name="InMail" vendor="Insite"><vers num=""/></prod><prod name="InShop" vendor="Insite"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-1198" published="2004-12-31" seq="2004-1198" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18282">Multiple vendor Web browsers nested array denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11751">Microsoft Internet Explorer Infinite Array Sort Denial Of Service Vulnerability</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1221.html">[Full-Disclosure] MSIE &amp; FIREFOX flaws: </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/382257">20041125 MSIE flaws: nested array sort() loop Stack overflow exception</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1199" published="2005-01-10" seq="2004-1199" severity="Medium" type="CVE"><desc><descript source="cve">Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18282">Multiple vendor Web browsers nested array denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11759">Apple Safari Web Browser Infinite Array Sort Denial Of Service Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029458.html">20041125 More Browser flaws on MACOSX: nested array sort() loop Stack overflow exception</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="Beta2"/><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-12" name="CVE-2004-1200" published="2004-12-31" seq="2004-1200" severity="Medium" type="CVE"><desc><descript source="cve">Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18282">Multiple vendor Web browsers nested array denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11752">Mozilla Firefox Infinite Array Sort Denial Of Service Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029434.html">20041125 FIREFOX flaws: nested array sort() loop Stack overflow exception</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029491.html">20041125 MSIE &amp; FIREFOX flaws: &apos;detailed&apos; advisory and comments that you probably don&apos;t want to read anyway</ref><ref source="BID" url="http://www.securityfocus.com/bid/11760">11760</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="0.8"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.10"/><vers num="0.10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1201" published="2005-01-10" seq="2004-1201" severity="Medium" type="CVE"><desc><descript source="cve">Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11762">Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18282">Multiple vendor Web browsers nested array denial of service</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110141347502530&amp;w=2">Re: [Full-Disclosure] MSIE flaws: nested array sort() loop</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110144136213993&amp;w=2">20041125 Re: Opera flaws: nested array sort() loop Stack overflow exception</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers edition="win32" num="5.0.2"/><vers edition="Mac" num="5.0"/><vers edition="Linux" num="5.0"/><vers edition="win32" num="5.1.1"/><vers edition="win32" num="5.1.0"/><vers edition="win32" num="5.12"/><vers num="5.12"/><vers edition="win32" num="6.0"/><vers num="6.0.6"/><vers edition="win32" num="6.0.6"/><vers num="6.0"/><vers edition="win32" num="6.0.1"/><vers edition="Linux" num="6.0.1"/><vers num="6.0.1"/><vers edition="win32" num="6.0.2"/><vers edition="Linux" num="6.0.2"/><vers edition="win32" num="6.0.3"/><vers edition="Linux" num="6.0.3"/><vers edition="win32" num="6.0.4"/><vers edition="win32" num="6.0.5"/><vers edition="Linux" num="6.10"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers num="7.10"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.21"/><vers num="7.22"/><vers num="7.23"/><vers num="7.50"/><vers num="7.51"/><vers num="7.52"/><vers num="7.53"/><vers num="7.54"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1202" published="2005-01-10" seq="2004-1202" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that both the non-stealth and the debug modes are enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18272">phpCMS parser.php cross-site scripting</ref><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11765">PHPCMS Cross-Site Scripting Vulnerability</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149207123510&amp;w=2">phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref><ref patch="1" source="CONFIRM" url="http://www.phpcms.de/download/index.en.html">http://www.phpcms.de/download/index.en.html</ref><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029499.html">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref></refs><vuln_soft><prod name="phpCMS" vendor="phpCMS"><vers num="1.1.9"/><vers num="1.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1203" published="2005-01-10" seq="2004-1203" severity="Medium" type="CVE"><desc><descript source="cve">parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server&apos;s installation path.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149207123510&amp;w=2">phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18279">phpcms-parser-path-disclosure(18279)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18272">phpcms-parser-xss(18272)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029499.html">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref></refs><vuln_soft><prod name="phpCMS" vendor="phpCMS"><vers num="1.1.9"/><vers num="1.2.0"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2004-1204" published="2005-01-10" seq="2004-1204" severity="Low" type="CVE"><desc><descript source="cve">FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18264">FluxBox XMAN denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149783715867&amp;w=2">FluxBox crash vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149783715867&amp;w=2">20041126 FluxBox crash vulnerability</ref></refs><vuln_soft><prod name="Fluxbot" vendor="Fluxbox-Team"><vers num="0.9.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1205" published="2005-01-10" seq="2004-1205" severity="Medium" type="CVE"><desc><descript source="cve">codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18263">PnTresMailer information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149886306037&amp;w=2">PnTresMailer code browser 6.03 Vulnerabilities</ref></refs><vuln_soft><prod name="pnTresMailer" vendor="pnTresMailer"><vers num="6.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1206" published="2005-01-10" seq="2004-1206" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11767">PNTresMailer Directory Traversal Vulnerability</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149886306037&amp;w=2">PnTresMailer code browser 6.03 Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18263">pntresmailer-information-disclosure(18263)</ref></refs><vuln_soft><prod name="pnTresMailer" vendor="pnTresMailer"><vers num="6.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1207" published="2005-01-10" seq="2004-1207" severity="Medium" type="CVE"><desc><descript source="cve">The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109651567308405&amp;w=2">20040929 Crash in Alpha Black Zero 1.04</ref><ref source="BID" url="http://www.securityfocus.com/bid/11279">11279</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12687">12687</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17545">alphablackzero-udp-packet-dos(17545)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011454">1011454</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110180289205605&amp;w=2">20041128 Players overflow in Serious engine UDP (was Alpha Black Zero, 29 Sep 2004)</ref></refs><vuln_soft><prod name="SeriousEngine" vendor="SeriousSam"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1208" published="2005-01-10" seq="2004-1208" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11774">21-6 Productions Orbz Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18298">Orbz join packet password buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110176280402580&amp;w=2"> Buffer-overflow in Orbz 2.10</ref></refs><vuln_soft><prod name="Orbz" vendor="21-6 Productions"><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/><vers num="2.8"/><vers num="2.9"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1209" published="2005-01-10" seq="2004-1209" severity="Medium" type="CVE"><desc><descript source="cve">Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18299">Payflow Link hidden field modification</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110181288820226&amp;w=2">[SHK-001]Payflow Link Default Config may lead to Hidden Field Modification</ref></refs><vuln_soft><prod name="Payflow Link" vendor="Verisign"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1210" published="2005-01-10" seq="2004-1210" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11779">IPCop Web Administration Interface Proxy Log HTML Injection Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18301">IPCop proxylog.dat page cross-site scripting</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110197682705001&amp;w=2">20041201 [KA Advisory 0411291] IPCop Cross Site Scripting Vulnerability in proxylog.dat</ref></refs><vuln_soft><prod name="IPCop" vendor="IPCop"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1211" published="2005-01-10" seq="2004-1211" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11775">Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18318">Mercury Mail Transport System command buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110193702909991&amp;w=2">Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html">20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.</ref><ref source="" url="http://home.kabelfoon.nl/~jaabogae/han/m_401b.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/12508">12508</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13348">13348</ref></refs><vuln_soft><prod name="Mercury" vendor="David Harris"><vers edition="Win32" num="4.0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1212" published="2005-01-10" seq="2004-1212" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11795">Blog Torrent Remote Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18356">Blog Torrent btdownload.php directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110200971917165&amp;w=2">Blog Torrent preview 0.8 - arbitary file download</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&amp;r2=1.7"></ref></refs><vuln_soft><prod name="Blog Torrent preview" vendor="Blog Torrent"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-1213" published="2005-01-10" seq="2004-1213" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/11798">Advanced Guestbook Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18334">Advanced Guestbook index.php cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110206527624612&amp;w=2"> Advanced Guestbook</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110238530129498&amp;w=2">20041204 Re: Advanced Guestbook</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.2"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1214" published="2005-01-10" seq="2004-1214" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11799">Burut Kreed Game Server Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18343">Kreed message and nickname format string</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2">Multiple vulnerabilities in Kreed 1.05</ref></refs><vuln_soft><prod name="Kreed" vendor="Burut"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1215" published="2005-01-10" seq="2004-1215" severity="Medium" type="CVE"><desc><descript source="cve">Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a &quot;message too long&quot; socket error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11799">Burut Kreed Game Server Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18344">Kreed UDP packet denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2">Multiple vulnerabilities in Kreed 1.05</ref></refs><vuln_soft><prod name="Kreed" vendor="Burut"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1216" published="2005-01-10" seq="2004-1216" severity="Medium" type="CVE"><desc><descript source="cve">The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11799">Burut Kreed Game Server Multiple Remote Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18345">Kreed nickname or model type denial of server</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2">Multiple vulnerabilities in Kreed 1.05</ref></refs><vuln_soft><prod name="Kreed" vendor="Burut"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1217" published="2005-01-10" seq="2004-1217" severity="Medium" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11822">Hosting Controller FilePath Parameter File Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18363">Hosting Controller view files</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110237762807764&amp;w=2">Hosting Controller</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 1.4"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1218" published="2005-01-10" seq="2004-1218" severity="Medium" type="CVE"><desc><descript source="cve">Remote Execute 2.30 allows remote attackers to cause a denial of service (application crash) by making 7 simultaneous connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11821">Ibex Software Remote Execute Remote Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18380">Remote Execute denial of service</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/136424">Remote Execute vulnerable to denial-of-service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110238855010003&amp;w=2">DoS leading to crash of client in Remote Execute 2.30</ref></refs><vuln_soft><prod name="Remote Execute" vendor="Ibex Software"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1219" published="2005-01-10" seq="2004-1219" severity="Medium" type="CVE"><desc><descript source="cve">paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator&apos;s password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11818">PAFileDB Password Hash Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18364">paFileDB &apos;sessions&apos; method information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245123927025&amp;w=2">Multiple Vulnerabilities in paFileDB 3.1</ref><ref source="MISC" url="http://echo.or.id/adv/adv09-y3dips-2004.txt">http://echo.or.id/adv/adv09-y3dips-2004.txt</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1220" published="2005-01-10" seq="2004-1220" severity="Medium" type="CVE"><desc><descript source="cve">Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11838">Digital Illusions Multiple Games Remote Denial of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244662102167&amp;w=2">Broadcast client crash in Battlefield 1942 1.6.19 and Vietnam 1.2</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18402">Battlefield Vietnam numplayers denial of service</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18400">battlefield-numplayers-dos(18400)</ref></refs><vuln_soft><prod name="Battlefield Vietnam" vendor="Digital Illusions"><vers num="1.2"/></prod><prod name="Battlefield 1942" vendor="Digital Illusions"><vers num="1.6.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1221" published="2005-01-10" seq="2004-1221" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11848">Darryl Burgdorf WebLibs Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18399">WebLibs weblibs.pl directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245395510945&amp;w=2">Remote Web Server Text File Viewing Vulnerability in WebLibs 1.0</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13400/">13400</ref></refs><vuln_soft><prod name="WebLibs" vendor="Darryl Burgdorf"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1222" published="2005-01-10" seq="2004-1222" severity="High" type="CVE"><desc><descript source="cve">weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11848">Darryl Burgdorf WebLibs Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18399">WebLibs weblibs.pl directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245395510945&amp;w=2">Remote Web Server Text File Viewing Vulnerability in WebLibs 1.0</ref></refs><vuln_soft><prod name="WebLibs" vendor="Darryl Burgdorf"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1223" published="2005-01-10" seq="2004-1223" severity="Medium" type="CVE"><desc><descript source="cve">The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18413">F-Secure URL obtain information</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11869">F-Secure Policy Manager FSMSH.DLL CGI Application Installation Path Disclosure Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110262921306862&amp;w=2">=?iso-8859-1?Q?F-Secure_Policy_Manager_-__physical_path_disclosure?=</ref><ref source="MISC" url="http://www.oliverkarow.de/research/f-secure.txt">http://www.oliverkarow.de/research/f-secure.txt</ref></refs><vuln_soft><prod name="Policy Manager" vendor="F-Secure"><vers num="5.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1224" published="2005-01-10" seq="2004-1224" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the &quot;s&quot; keybinding, which leaves a buffer without a NULL terminator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11884">MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110279034910663&amp;w=2">Local off-by-one in mtr versions 0.55 to 0.65</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18428">mtr-mtrcurseskeyaction-offbyone-bo(18428)</ref></refs><vuln_soft><prod name="mtr" vendor="mtr"><vers num="0.55"/><vers num="0.56"/><vers num="0.57"/><vers num="0.58"/><vers num="0.59"/><vers num="0.60"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/><vers num="0.64"/><vers num="0.65"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1225" published="2005-01-10" seq="2004-1225" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11740">SugarCRM Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18325">SugarCRM record SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2">SugarSales Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00053-120104"></ref></refs><vuln_soft><prod name="SugarCRM" vendor="SugarCRM"><vers num="1.0g"/><vers num="1.0f"/><vers num="1.0"/><vers num="1.1f"/><vers num="1.1e"/><vers num="1.1d"/><vers num="1.1c"/><vers num="1.1b"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.5d"/><vers num="2.0.1a"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1226" published="2005-01-10" seq="2004-1226" severity="Medium" type="CVE"><desc><descript source="cve">SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2">  SugarSales Multiple Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18447">sugar-sales-path-disclosure(18447)</ref></refs><vuln_soft><prod name="SugarCRM" vendor="SugarCRM"><vers num="2.0.1c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1227" published="2005-01-10" seq="2004-1227" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11740">SugarCRM Multiple Input Validation Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18326">SugarCRM directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2">SugarSales Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00053-120104"></ref></refs><vuln_soft><prod name="Sugar Sales" vendor="SugarCRM"><vers num="2.0.1c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1228" published="2005-01-10" seq="2004-1228" severity="Medium" type="CVE"><desc><descript source="cve">The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2">SugarSales Multiple Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18449">sugar-sales-password-plaintext(18449)</ref></refs><vuln_soft><prod name="Sugar Sales" vendor="SugarCRM"><vers num="2.0.1c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-1229" published="2005-01-10" seq="2004-1229" severity="High" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.man.poznan.pl/~security/gg-adv.txt">http://www.man.poznan.pl/~security/gg-adv.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18582">gadu-gadu-xss(18582)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11899">11899</ref><ref source="OSVDB" url="http://www.osvdb.org/12517">12517</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13450">13450</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2">20041213 Gadu-Gadu several vulnerabilities</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1230" published="2005-01-10" seq="2004-1230" severity="Medium" type="CVE"><desc><descript source="cve">Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.man.poznan.pl/~security/gg-adv.txt">http://www.man.poznan.pl/~security/gg-adv.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18461">gadu-gadu-dcc-ctcp-obtain-files(18461)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2">20041213 Gadu-Gadu several vulnerabilities</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1231" published="2005-01-10" seq="2004-1231" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.man.poznan.pl/~security/gg-adv.txt">http://www.man.poznan.pl/~security/gg-adv.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18461">gadu-gadu-dcc-ctcp-obtain-files(18461)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2">20041213 Gadu-Gadu several vulnerabilities</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1232" published="2005-01-10" seq="2004-1232" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.man.poznan.pl/~security/gg-adv.txt">http://www.man.poznan.pl/~security/gg-adv.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18462">gadu-gadu-image-filename-bo(18462)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2">20041213 Gadu-Gadu several vulnerabilities</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1233" published="2005-01-10" seq="2004-1233" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.man.poznan.pl/~security/gg-adv.txt">http://www.man.poznan.pl/~security/gg-adv.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18465">gadu-gadu-dcc-bo(18465)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2">20041213 Gadu-Gadu several vulnerabilities</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1234" published="2004-12-31" seq="2004-1234" severity="Low" type="CVE"><desc><descript source="cve">load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-689.html">RHSA-2004:689</ref><ref patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@4076466d_SqUm4azg4_v3FIG2-X6XQ">http://linux.bkbits.net:8080/linux-2.4/cset@4076466d_SqUm4azg4_v3FIG2-X6XQ</ref><ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=142965">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=142965</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12101">12101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18687">linux-loadelfbinary-dos(18687)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.3"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0-test9"/><vers num="2.4.0-test8"/><vers num="2.4.0-test7"/><vers num="2.4.0-test6"/><vers num="2.4.0-test5"/><vers num="2.4.0-test4"/><vers num="2.4.0-test3"/><vers num="2.4.0-test2"/><vers num="2.4.0-test12"/><vers num="2.4.0-test11"/><vers num="2.4.0-test10"/><vers num="2.4.0 test1"/><vers num="2.4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1235" published="2005-04-14" seq="2004-1235" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">Updated kernel packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12190">bid 12190</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0021-uselib.txt">http://isec.pl/vulnerabilities/isec-0021-uselib.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/7806">FEDORA-2005-013</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/7805">FEDORA-2005-014</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="CONFIRM" url="http://www.securityfocus.com/advisories/7804">http://www.securityfocus.com/advisories/7804</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18800">linux-uselib-gain-privileges(18800)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512575901427&amp;w=2">20050107 Linux kernel sys_uselib local root vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/><vers num="3.0"/></prod><prod name="Network Routing" vendor="Avaya"><vers num=""/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 rc2"/><vers num="2.6.10"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Intuity" vendor="Avaya"><vers num="LX"/></prod><prod name="S8710" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation" num="3.0"/></prod><prod name="MN100" vendor="Avaya"><vers num=""/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="1.1"/><vers num="2.0"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="9.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-1236" published="2004-12-31" seq="2004-1236" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384298016120">SSRT4867</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57754-1">57754</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258905">VU#258905</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-083.shtml">P-083</ref><ref source="BID" url="http://www.securityfocus.com/bid/12099">12099</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14960">14960</ref></refs><vuln_soft><prod name="Netscape Directory Server" vendor="Netscape"><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1237" published="2005-04-14" seq="2004-1237" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">Updated kernel packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12309">bid 12309</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="8.1"/><vers num="8.2"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="9.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.6.10"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-1238" published="2004-12-31" reject="1" seq="2004-1238" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry modified="2005-10-20" name="CVE-2004-1239" published="2004-12-31" reject="1" seq="2004-1239" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry modified="2005-10-20" name="CVE-2004-1240" published="2004-12-31" reject="1" seq="2004-1240" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry modified="2005-10-20" name="CVE-2004-1241" published="2004-12-31" reject="1" seq="2004-1241" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry modified="2005-10-20" name="CVE-2004-1242" published="2004-12-31" reject="1" seq="2004-1242" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry modified="2005-10-20" name="CVE-2004-1243" published="2004-12-31" reject="1" seq="2004-1243" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1244" published="2004-02-08" seq="2004-1244" severity="High" type="CVE"><desc><descript source="cve">Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the &quot;PNG Processing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx">MS05-009</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/259890">VU#259890</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1306.html">OVAL1306</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1568.html">OVAL1568</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2379.html">OVAL2379</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19096">win-ms05kb890261-update(19096)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1306">oval:org.mitre.oval:def:1306</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1568">oval:org.mitre.oval:def:1568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2379">oval:org.mitre.oval:def:2379</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1254" published="2005-01-10" seq="2004-1254" severity="High" type="CVE"><desc><descript source="cve">WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="K-otik" url="http://www.k-otik.com/exploits/20041217.Winrar.c.php">WinRAR &lt;= 3.41 Compressed File Deletion Buffer Overflow Exploit</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/12002/info/">RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://www.frsirt.com/exploits/20041217.Winrar.c.php">http://www.frsirt.com/exploits/20041217.Winrar.c.php</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18569">winrar-zip-file-bo(18569)</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.0.0"/><vers num="3.10 beta5"/><vers num="3.10 beta3"/><vers num="3.10"/><vers num="3.11"/><vers num="3.20"/><vers num="3.40"/><vers num="3.41"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1255" published="2005-01-10" seq="2004-1255" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the expandtabs function in 2fax 3.04 allows remote attackers to execute arbitrary code via a text file that is converted to TIFF.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11980/">2Fax Tab Expansion Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/2fax.txt">2fax 3.04 expandtabs overflows s buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/10901">2fax-bpcx-bo(10901)</ref></refs><vuln_soft><prod name="2fax" vendor="2fax"><vers num="3.0 4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1256" published="2005-01-10" seq="2004-1256" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12019">ABC2MIDI Multiple Stack Buffer Overflow Vulnerabilities</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/abc2midi.txt">abc2midi 2004.12.04 event_text overflows msg buffer; event_specific overflows msg buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18574">abc2midi-eventspecific-bo(18574)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18573">abc2midi-eventtext-bo(18573)</ref></refs><vuln_soft><prod name="abcMIDI" vendor="abcMIDI"><vers num="2004-12-04"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1257" published="2005-01-10" seq="2004-1257" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12018/">ABC2MTEX Process ABC Key Field Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/abc2mtex.txt">abc2mtex 1.6.1 process_abc overflows key buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18578">abc2mtex-processabc-bo(18578)</ref></refs><vuln_soft><prod name="abc2mtex" vendor="abc2mtex"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1258" published="2005-01-10" seq="2004-1258" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the put_words function in subs.c for abcm2ps 3.7.20 allows remote attackers to execute arbitrary code via crafted ABC files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/abcm2ps.txt">abcm2ps 3.7.20 put_words overflows str buffer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12022">Jef Moine abcm2ps ABC File Remote Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18579">abcm2ps-putwords-bo(18579)</ref></refs><vuln_soft><prod name="abcm2ps" vendor="Jef Moine"><vers num="3.7.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1259" published="2005-01-10" seq="2004-1259" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/abcpp.txt">process_directive overflows token buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12021/">ABCPP Directive Handler Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18581">abcpp-handledirective-bo(18581)</ref></refs><vuln_soft><prod name="abcpp" vendor="abcpp"><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1260" published="2005-01-10" seq="2004-1260" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/abctab2ps.txt">abctab2ps 1.6.3 write_heading overflows t; _ trim_title overflows rest</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12026">abctab2ps Write_Heading Function ABC File Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12028">abctab2ps Trim_Title Function ABC File Remote Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18584">abctab2ps-trimtitle-bo(18584)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18583">abctab2ps-writeheading-bo(18583)</ref></refs><vuln_soft><prod name="abctab2ps" vendor="abctab2ps"><vers num="1.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1261" published="2005-01-10" seq="2004-1261" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/asp2php.txt">preparse() overflows token buffer; preparse() overflows temp buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18585">asp2php-preparse-bo(18585)</ref></refs><vuln_soft><prod name="asp2php" vendor="asp2php"><vers num="0.76.23"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1262" published="2005-01-10" seq="2004-1262" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the bsb_open_header function in libbsb for bsb2ppm 0.0.6 allows remote attackers to execute arbitrary code via crafted BSB pictures.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/bsb2ppm.txt"> bsb2ppm 0.0.6 overflows line buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18586">bsb2ppm-bsbopenheader-bo(18586)</ref></refs><vuln_soft><prod name="bsb2ppm" vendor="Stuart Cunningham"><vers num="0.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1263" published="2005-01-10" seq="2004-1263" severity="High" type="CVE"><desc><descript source="cve">changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious &quot;make&quot; program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11963">ChangePassword Local Privilege Escalation Vulnerability</ref><ref source="MISC" url="http://tigger.uic.edu/~jlongs2/holes/changepassword.txt">http://tigger.uic.edu/~jlongs2/holes/changepassword.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18593">changepassword-gain-privileges(18593)</ref></refs><vuln_soft><prod name="ChangePassword" vendor="ChangePassword"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1264" published="2005-01-10" seq="2004-1264" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11957">ChBg Scenario File Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/chbg.txt">chbg 1.5 simplify_path overflows res buffer</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-644">DSA-644</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:027">MDKSA-2005:027</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18595">chbg-simplifypath-bo(18595)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:027">MDKSA-2005:027</ref></refs><vuln_soft><prod name="ChBg" vendor="ChBg"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1265" published="2005-01-10" seq="2004-1265" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the readObjectChunk function in 3dsimp.cpp for the convex-tool program in Convex 3D 0.8pre1 allows remote attackers to execute arbitrary code via a crafted 3DS file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11995/">Convex 3D Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/convex3d.txt">Convex 3D 0.8pre1 readObjectChunk overflows objectname buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18601">convex-3d-readobjectchunk-bo(18601)</ref></refs><vuln_soft><prod name="Convex 3D" vendor="Alex Dunaevsky"><vers num="0.8 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1266" published="2005-01-10" seq="2004-1266" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the get_field_headers function in csv2xml.cpp for csv2xml 0.5.1 allows remote attackers to execute arbitrary code via a crafted CSV file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12027">CSV2XML Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/csv2xml.txt">csv2xml 0.5.1 get_field_headers overflows token</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18602">csv2xml-getfieldheaders-bo(18602)</ref></refs><vuln_soft><prod name="csv2xml" vendor="Jacob Rhoden"><vers num="0.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-15" name="CVE-2004-1267" published="2005-01-10" seq="2004-1267" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/cups.txt">CUPS 1.1.22 hpgltops ParseCommand overflows buf</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11968/">CUPS HPGL File Processor Buffer Overflow Vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-013.html">RHSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18604">cups-parsecommand-hpgl-bo(18604)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml">GLSA-200412-25</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1">USN-50-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.22 rc1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1268" published="2005-01-10" seq="2004-1268" severity="Low" type="CVE"><desc><descript source="cve">lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt">lppasswd ignores write errors, etc.</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-013.html">RHSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18606">cups-lppasswd-passwd-truncate(18606)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml">GLSA-200412-25</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1">USN-50-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.22 rc1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1269" published="2005-01-10" seq="2004-1269" severity="Medium" type="CVE"><desc><descript source="cve">lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt">CUPS 1.1.22 lppasswd ignores write errors, etc.</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-013.html">RHSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18608">cups-lppasswd-dos(18608)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml">GLSA-200412-25</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1">USN-50-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.22 rc1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1270" published="2005-01-10" seq="2004-1270" severity="Low" type="CVE"><desc><descript source="cve">lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><local/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt">CUPS 1.1.22 lppasswd ignores write errors, etc.</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-013.html">RHSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18609">cups-lppasswd-passwd-modify(18609)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml">GLSA-200412-25</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1">USN-50-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008">MDKSA-2005:008</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.22 rc1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1271" published="2005-01-10" seq="2004-1271" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/dxfscope.txt"> dxfscope 0.2 overflows ent_name buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11986/">DXFScope Remote Client-Side Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18558">dxfscope-dxfin-bo(18558)</ref></refs><vuln_soft><prod name="DXF file format viewer" vendor="DXFscope"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1272" published="2005-01-10" seq="2004-1272" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/elm-bolthole-filter.txt">elm/bolthole filter 2.6.1 save_embedded_address overflows address buffer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11977">Bolthole Filter Address Parsing Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18607">elm-bolthole-bo(18607)</ref></refs><vuln_soft><prod name="Filter" vendor="Bolthole"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1273" published="2005-01-10" seq="2004-1273" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/greed.txt">DownloadLoop overflows COMMAND; DownloadLoop does not check for nasty characters</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18633">greed-downloadloop-bo(18633)</ref></refs><vuln_soft><prod name="greed" vendor="greed"><vers num="0.81p"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1274" published="2005-01-10" seq="2004-1274" severity="High" type="CVE"><desc><descript source="cve">The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/greed.txt">DownloadLoop overflows COMMAND; DownloadLoop does not check for nasty characters</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18634">greed-downloadloop-command-execution(18634)</ref></refs><vuln_soft><prod name="greed" vendor="greed"><vers num="0.81p"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1275" published="2005-01-10" seq="2004-1275" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/html2hdml.txt">html2hdml 1.0.3 remove_quote overflows print_buf buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18556">html2hdml-removequote-bo(18556)</ref></refs><vuln_soft><prod name="html2hdml" vendor="html2hdml"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1276" published="2005-01-10" seq="2004-1276" severity="Low" type="CVE"><desc><descript source="cve">IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tmpnam function, before the files are opened by IglooFTP.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/iglooftp.txt">IglooFTP 0.6.1 uses fopen in /tmp</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18632">iglooftp-file-overwrites(18632)</ref></refs><vuln_soft><prod name="IglooFTP" vendor="IglooFTP"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1277" published="2005-01-10" seq="2004-1277" severity="Medium" type="CVE"><desc><descript source="cve">The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/iglooftp2.txt">IglooFTP 0.6.1 does not check for directory escapes</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18561">iglooftp-file-overwrite(18561)</ref></refs><vuln_soft><prod name="IglooFTP" vendor="IglooFTP"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1278" published="2005-01-10" seq="2004-1278" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the switch_voice function in parse.c for jcabc2ps 20040902 allows remote attackers to execute arbitrary code via a crafted ABC file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/jcabc2ps.txt">jcabc2ps switch_voice() overflows t1 buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12024">ABC2PS/JCABC2PS Voice Field Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18563">jcabc2ps-switchvoice-bo(18563)</ref></refs><vuln_soft><prod name="jcabc2ps" vendor="John Chambers"><vers num="2004-09-02"/></prod><prod name="abc2ps" vendor="abc2ps"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1279" published="2005-01-10" seq="2004-1279" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the get_file_list_stdin function in jpegtoavi 1.5 allows remote attackers to execute arbitrary code via a crafted set of JPEG files and filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11976/">JPegToAvi File List Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://tigger.uic.edu/~jlongs2/holes/jpegtoavi.txt">http://tigger.uic.edu/~jlongs2/holes/jpegtoavi.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18565">jpegtoavi-getfileliststdin-bo(18565)</ref></refs><vuln_soft><prod name="jpegtoavi" vendor="jpegtoavi"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1280" published="2005-01-10" seq="2004-1280" severity="High" type="CVE"><desc><descript source="cve">The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/junkie.txt">junkie 0.3.1 gui_popup_view_fly does not check    for nasty characters; ftp_retr does not check for directory escapes</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18567">junkie-command-execution(18567)</ref></refs><vuln_soft><prod name="junkie FTP Client" vendor="junkie"><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1281" published="2005-01-10" seq="2004-1281" severity="Medium" type="CVE"><desc><descript source="cve">The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/junkie.txt">junkie 0.3.1 gui_popup_view_fly does not check    for nasty characters; ftp_retr does not check for directory escapes</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18568">junkie-ftpretr-command-execution(18568)</ref></refs><vuln_soft><prod name="junkie FTP Client" vendor="junkie"><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1282" published="2005-01-10" seq="2004-1282" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that is not properly handled during a Reply operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/linpopup.txt">LinPopUp 1.2.0 overflows sub_string buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11997">LinPopUp Remote Buffer Overflow Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-632">DSA-632</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18627">linpopup-strexpand-bo(18627)</ref></refs><vuln_soft><prod name="LinPopUp" vendor="LinPopUp"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1283" published="2005-01-10" seq="2004-1283" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12025">Mesh Viewer Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/meshviewer.txt">Mesh Viewer 0.2.2 Mesh::type overflows s1 buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18616">mesh-type-bo(18616)</ref></refs><vuln_soft><prod name="Mesh Viewer" vendor="Mesh Viewer"><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1284" published="2005-01-10" seq="2004-1284" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/mpg123.txt">mpg123 0.59r find_next_file overflows linetmp buffer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11958">MPG123 Find Next File Remote Client-Side Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18626">mpg123-findnextfile-bo(18626)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="mpg123" vendor="mpg123"><vers num="pre0.59s"/><vers num="0.59r"/><vers num="0.59q"/><vers num="0.59p"/><vers num="0.59o"/><vers num="0.59n"/><vers num="0.59m"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1285" published="2005-01-10" seq="2004-1285" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11962">MPlayer MMST Get_Header Remote Client-Side Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/mplayer.txt">MPlayer 1.0pre5 get_header overflows data buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18631">mplayer-getdata-bo(18631)</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.92.1"/><vers num="1.0 pre5try1"/><vers num="1.0 pre5"/><vers num="1.0 pre4"/><vers num="1.0 pre3try2"/><vers num="1.0 pre3"/><vers num="1.0 pre2"/><vers num="1.0 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1286" published="2005-01-10" seq="2004-1286" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/napshare.txt">NapShare 1.2 auto_filter_extern overflows filename buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11967">NapShare Remote Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18630">napshare-autofilterextern-bo(18630)</ref></refs><vuln_soft><prod name="NapShare" vendor="NapShare"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1287" published="2005-01-10" seq="2004-1287" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/nasm.txt">NASM 0.98.38 error() overflows buff[]</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11991">NASM Error Preprocessor Directive Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18540">nasm-preprocc-bo(18540)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-381.html">RHSA-2005:381</ref></refs><vuln_soft><prod name="NASM" vendor="NASM"><vers num="0.98.38"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1288" published="2005-01-10" seq="2004-1288" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/o3read.txt"> o3read 0.0.3 parse_html overflows t buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12000/">O3Read HTML Parser Buffer Overflow Vulnerability</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-20.xml">GLSA-200501-20</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18547">o3read-parsehtml-bo(18547)</ref></refs><vuln_soft><prod name="o3read" vendor="Siag"><vers num=".3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1289" published="2005-01-10" seq="2004-1289" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/pcal.txt">pcal 4.7.1 getline overflows tmpbuf; get_holiday overflows tmp</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18552">pcal-getline-pcalutil-bo(18552)</ref></refs><vuln_soft><prod name="PCAL" vendor="PCAL"><vers num="4.1.0"/><vers num="4.3.0"/><vers num="4.5.0"/><vers num="4.6.0"/><vers num="4.7.0"/><vers num="4.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1290" published="2005-01-10" seq="2004-1290" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the process_moves function in pgn2web.c for pgn2web 0.3 allows remote attackers to execute arbitrary code via a crafted PGN file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12023">PGN2WEB Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/pcal.txt">pcal 4.7.1 getline overflows tmpbuf; get_holiday overflows tmp</ref><ref source="MISC" url="http://tigger.uic.edu/~jlongs2/holes/pgn2web.txt">http://tigger.uic.edu/~jlongs2/holes/pgn2web.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18554">pgn2web-pgn2webc-bo(18554)</ref></refs><vuln_soft><prod name="pgn2web" vendor="William Hoggarth"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1291" published="2005-01-10" seq="2004-1291" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/qwik-smtpd.txt"> qwik-smtpd overflows clientHelo buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18555">qwilmail-smtp-helo-open-relay(18555)</ref></refs><vuln_soft><prod name="qwik_smtpd" vendor="Amir Malik"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1292" published="2005-01-10" seq="2004-1292" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/ringtonetools.txt">ringtonetools 2.22 parse_emelody overflows song buffer</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-18.xml">GLSA-200503-18</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18557">ringtonetools-parseemelody-bo(18557)</ref></refs><vuln_soft><prod name="ringtonetools" vendor="Michael Kohn"><vers num="2.22"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1293" published="2005-01-10" seq="2004-1293" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/rtf2latex2e.txt">rtf2latex2e 1.0fc2 ReadFontTbl overflows buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11994">RTF2LATEX2E Stack Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18559">rtf2latex2e-reader-bo(18559)</ref></refs><vuln_soft><prod name="rtf2latex2e" vendor="rtf2latex2e"><vers num="1.0 fc2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1294" published="2005-01-10" seq="2004-1294" severity="Medium" type="CVE"><desc><descript source="cve">The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/tnftp.txt">tnftp 20030825 does not check for directory escapes</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11965">TNFTP FTP Client Directory Traversal Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18560">tnftp-mget-cmds-file-overwrite(18560)</ref></refs><vuln_soft><prod name="TNFTP" vendor="Luke Mewburn"><vers num="2003-08-25"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1295" published="2005-01-10" seq="2004-1295" severity="Low" type="CVE"><desc><descript source="cve">The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled).</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/uml-utilites.txt">uml-utilities 20030903 uml_net slip_down() fails to check permissions</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18562">umlutilities-umtnet-slipdown-dos(18562)</ref></refs><vuln_soft><prod name="uml-utilities" vendor="uml-utilities"><vers num="2003-09-03"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1296" published="2004-12-31" seq="2004-1296" severity="Low" type="CVE"><desc><descript source="cve">The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110358225615424&amp;w=2">20041220 [USN-43-1] groff utility vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286371">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286371</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286372">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18660">groff-eqn2graph-pic2graph-symlink(18660)</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038">MDKSA-2006:038</ref></refs><vuln_soft><prod name="groff" vendor="GNU"><vers num="1.18.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1297" published="2005-01-10" seq="2004-1297" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbitrary code via a crafted RTF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/unrtf.txt">unrtf 0.19.3 process_font_table overflows name buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18566">unrtf-processfonttable-convert-bo(18566)</ref></refs><vuln_soft><prod name="unrtf" vendor="Zack Smith"><vers num="0.19.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1298" published="2005-01-10" seq="2004-1298" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/vb2c.txt">vb2c 0.02 parse_sub overflows token buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12020">Michael Kohn VB2C FRM File Remote Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18605">vb2c-gettoken-bo(18605)</ref></refs><vuln_soft><prod name="VB2C" vendor="Michael Kohn"><vers num="0.02"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1299" published="2005-01-10" seq="2004-1299" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11979">Vilistextum HTML Attribute Parsing Buffer Overflow Vulnerability</ref><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/vilistextum.txt">vilistextum 2.6.6 get_attr overflows temp buffer</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18610">vilistextum-getattr-bo(18610)</ref></refs><vuln_soft><prod name="Vilistextum" vendor="Vilistextum"><vers num="2.6.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1300" published="2005-01-10" seq="2004-1300" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/xine-lib.txt">xine-lib open_aiff_file overflows buffer</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18611">xine-openaifffile-bo(18611)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011">MDKSA-2005:011</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1 rc7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1301" published="2005-01-10" seq="2004-1301" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (XLS) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/xlreader.txt">xlreader 0.9.0 overflows insert_start buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11970">XLReader Remote Client-Side Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18612">xlreader-bookformatsql-bo(18612)</ref></refs><vuln_soft><prod name="xlreader" vendor="xlreader"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1302" published="2005-01-10" seq="2004-1302" severity="High" type="CVE"><desc><descript source="cve">The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/yamt.txt">YAMT 0.5 id3tag_sort does not check for nasty characters</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11999/">YAMT ID3 Tag Sort Command Execution Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18614">yamt-id3tagsort-bo(18614)</ref><ref source="CONFIRM" url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11999">11999</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012583">1012583</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13554">13554</ref></refs><vuln_soft><prod name="YAMT" vendor="YAMT"><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1303" published="2005-01-10" seq="2004-1303" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="University of Illinois at Chicago" url="http://tigger.uic.edu/~jlongs2/holes/yanf.txt">Yanf 0.4 get() overflows buf</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11975">Yanf HTTP Response Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18615">yanf-get-bo(18615)</ref></refs><vuln_soft><prod name="Yanf" vendor="Yanf"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1304" published="2005-01-10" seq="2004-1304" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11771">File ELF Header Unspecified Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18368">File ELF Header buffer overflow</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200412-07.xml">GLSA-200412-07</ref><ref source="TRUSTIX" url="http://www.trustix.net/errata/2004/0063/">2004-0063</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Dec/1012433.html">http://www.securitytracker.com/alerts/2004/Dec/1012433.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012433">1012433</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="file" vendor="file"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="4.10"/><vers num="4.11"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1305" published="2004-12-23" seq="2004-1305" severity="Medium" type="CVE"><desc><descript source="cve">The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382854111833&amp;w=2">20041223 Microsoft Windows Kernel ANI File Parsing Crash and DOS Vulnerability</ref><ref adv="1" source="MISC" url="http://www.xfocus.net/flashsky/icoExp/">http://www.xfocus.net/flashsky/icoExp/</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx">MS05-002</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-012A.html">TA05-012A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/177584">VU#177584</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/697136">VU#697136</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1304.html">OVAL1304</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2580.html">OVAL2580</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3216.html">OVAL3216</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3957.html">OVAL3957</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval712.html">OVAL712</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18667">win-ani-ratenumber-dos(18667)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1304">oval:org.mitre.oval:def:1304</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2580">oval:org.mitre.oval:def:2580</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3216">oval:org.mitre.oval:def:3216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3957">oval:org.mitre.oval:def:3957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:712">oval:org.mitre.oval:def:712</ref></refs><vuln_soft><prod name="IP softphone" vendor="Nortel"><vers num="2050"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Symposium Agent" vendor="Nortel"><vers num=""/></prod><prod name="Symposium Network Control Center (NCC)" vendor="Nortel"><vers num=""/></prod><prod name="Symposium Express Call Center (SECC)" vendor="Nortel"><vers num=""/></prod><prod name="Symposium Web Client" vendor="Nortel"><vers num=""/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Media Processing Server" vendor="Nortel"><vers num=""/></prod><prod name="Symposium Call Center Server (SCCS)" vendor="Nortel"><vers num=""/></prod><prod name="Symposium TAPI Service Provider" vendor="Nortel"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Periphonics" vendor="Nortel"><vers num=""/></prod><prod name="MCS" vendor="Nortel"><vers num="5200 3.0"/><vers num="5100 3.0"/></prod><prod name="Symposium Web Center Portal (SWCP)" vendor="Nortel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-24" name="CVE-2004-1306" published="2004-12-31" seq="2004-1306" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383690219440&amp;w=2">20041223 Microsoft Windows winhlp32.exe Heap Overflow Vulnerability</ref><ref source="MISC" url="http://www.xfocus.net/flashsky/icoExp/">http://www.xfocus.net/flashsky/icoExp/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12092">12092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18678">win-winhlp32-bo(18678)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="Web"/><vers num="Web"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1307" published="2004-12-21" seq="2004-1307" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=173&amp;type=vulnerabilities&amp;flashstatus=true">20041221 libtiff STRIPOFFSETS Integer Overflow Vulnerability</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/539110">VU#539110</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1">101677</ref></refs><vuln_soft><prod name="CVLAN" vendor="Avaya"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Interactive Response" vendor="Avaya"><vers num="1.3"/><vers num="1.2.1"/><vers num=""/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="libTIFF" vendor="libTIFF"><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod><prod name="Intuity LX" vendor="Avaya"><vers num=""/></prod><prod name="CMS Server" vendor="Avaya"><vers num="13.0"/><vers num="12.0"/><vers num="11.0"/><vers num="9.0"/><vers num="8.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Integrated Management" vendor="Avaya"><vers num=""/></prod><prod name="MN100" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="2.0"/><vers num="1.1"/></prod><prod name="iControl Service Manager" vendor="F5"><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3"/></prod><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="10.0"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1308" published="2005-01-10" seq="2004-1308" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=174&amp;type=vulnerabilities">libtiff Directory Entry Count Integer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12075">libTIFF Heap Corruption Integer Overflow Vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-617">DSA-617</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-019.html">RHSA-2005:019</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-035.html">RHSA-2005:035</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html">SUSE-SA:2005:001</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/125598">VU#125598</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18637">libtiff-tiff-tdircount-bo(18637)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100117.html">OVAL100117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13776">13776</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000920">CLA-2005:920</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1">101677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100117">oval:org.mitre.oval:def:100117</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref></refs><vuln_soft><prod name="LibTIFF" vendor="LibTIFF"><vers num="3.4"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.4"/><vers num="3.5.5"/><vers num="3.5.7"/><vers num="3.6.0"/><vers num="3.6.1"/><vers num="3.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1309" published="2005-01-10" seq="2004-1309" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=168">Research Reports</ref><ref source="CONFIRM" url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18527">mplayer-bitmap-bo(18527)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref></refs><vuln_soft><prod name="Unix Mplayer" vendor="Mplayer"><vers num="1.0 pre5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1310" published="2005-01-10" seq="2004-1310" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=167">iDEFENSE intelligence</ref><ref source="CONFIRM" url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref><ref source="CONFIRM" url="http://www1.mplayerhq.hu/MPlayer/patches/mmst_fix_20041215.diff">http://www1.mplayerhq.hu/MPlayer/patches/mmst_fix_20041215.diff</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18526">mplayer-mmst-bo(18526)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="1.0 pre5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1311" published="2005-01-10" seq="2004-1311" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=166">iDEFENSE intelligence</ref><ref source="CONFIRM" url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref><ref source="CONFIRM" url="http://www1.mplayerhq.hu/MPlayer/patches/rtsp_fix_20041215.diff">http://www1.mplayerhq.hu/MPlayer/patches/rtsp_fix_20041215.diff</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18525">mplayer-rtsp-bo(18525)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157">MDKSA-2004:157</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="1.0 pre5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2004-1312" published="2005-01-03" seq="2004-1312" severity="High" type="CVE"><desc><descript source="cve">A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.csis.dk/default.asp?m=1&amp;a=194">http://www.csis.dk/default.asp?m=1&amp;a=194</ref><ref adv="1" patch="1" source="CONFIRM" url="http://kbase.gfi.com/showarticle.asp?id=KBID002249">http://kbase.gfi.com/showarticle.asp?id=KBID002249</ref><ref source="BID" url="http://www.securityfocus.com/bid/12148">12148</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13708">13708</ref></refs><vuln_soft><prod name="MailSecurity" vendor="GFI"><vers edition="Exchange_SMTP" num="8.0"/></prod><prod name="MailEssentials" vendor="GFI"><vers edition="Exchange_SMTP" num="10.1"/><vers edition="Exchange_SMTP" num="10.0"/><vers edition="Exchange_SMTP" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1313" published="2005-01-10" seq="2004-1313" severity="High" type="CVE"><desc><descript source="cve">The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Secunia" url="http://secunia.com/secunia_research/2004-16/">Secunia Research: My Firewall Plus Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12064">Webroot Software My Firewall Plus Local Privilege Escalation Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18622">my-firewall-plus-gain-privileges(18622)</ref></refs><vuln_soft><prod name="My Firewall Plus" vendor="Webroot Software"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1314" published="2005-01-10" seq="2004-1314" severity="High" type="CVE"><desc><descript source="cve">Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the &quot;window injection&quot; vulnerability, a different vulnerability than CVE-2004-1122.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://secunia.com/secunia_research/2004-13/advisory/">http://secunia.com/secunia_research/2004-13/advisory/</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18397">web-browser-popup-spoofing(18397)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13252/">13252</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="Beta2"/><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1315" published="2004-11-12" seq="2004-1315" severity="High" type="CVE"><desc><descript source="cve">viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110029415208724&amp;w=2">20041112 phpBB Code EXEC (v2.0.10)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=110079440800004&amp;r=1&amp;w=2">20041118 EXEC exploit in phpBB - fix</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110365752909029&amp;w=2">20041220 phpBB Worm</ref><ref adv="1" source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?t=240513">http://www.phpbb.com/phpBB/viewtopic.php?t=240513</ref><ref adv="1" patch="1" source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110143995118428&amp;w=2">GLSA-200411-32</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-356A.html">TA04-356A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/497400">VU#497400</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13239/">13239</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18052">phpbb-view-sql-injection(18052)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1316" published="2004-12-29" seq="2004-1316" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing &apos;\&apos; (backslash) character, which prevents a string from being NULL terminated.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110436284718949&amp;w=2">20041229 Heap overflow in Mozilla Browser &lt;= 1.7.3 NNTP code.</ref><ref adv="1" source="MISC" url="http://isec.pl/vulnerabilities/isec-0020-mozilla.txt">http://isec.pl/vulnerabilities/isec-0020-mozilla.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-06.html">http://www.mozilla.org/security/announce/mfsa2005-06.html</ref><ref adv="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780717916478&amp;w=2">HPSBTU01114</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-038.html">RHSA-2005:038</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18711">mozilla-nntp-bo(18711)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100052.html">OVAL100052</ref><ref source="BID" url="http://www.securityfocus.com/bid/12131">12131</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100052">oval:org.mitre.oval:def:100052</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1317" published="2004-12-27" seq="2004-1317" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425875504586&amp;w=2">20041227 [HAT-SQUAD] NetCat Remote Critical Vulnerability, Poc included</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000142.html">http://www.hat-squad.com/en/000142.html</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110429204712327&amp;w=2">20041228 Re: [HAT-SQUAD] NetCat Remote Critical Vulnerability, Poc included</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110426936423890&amp;w=2">20041228 Netcat v1.11 For Windows , New fixed version</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18681">netcat-doexec-bo(18681)</ref></refs><vuln_soft><prod name="NetCat" vendor="NetCat"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2004-1318" published="2005-01-06" seq="2004-1318" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab (&quot;%09&quot;) character, which prevents the rest of the query from being properly sanitized.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://jvn.jp/jp/JVN%23904429FE.html">http://jvn.jp/jp/JVN%23904429FE.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.namazu.org/security.html.en#xss-tab">http://www.namazu.org/security.html.en#xss-tab</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-627">DSA-627</ref><ref source="HP" url="http://www.securityfocus.com/advisories/9028">HPSBMA01212</ref><ref source="FEDORA" url="http://www.linuxsecurity.com/content/view/117604/102/">FEDORA-2004-557</ref><ref source="BID" url="http://www.securityfocus.com/bid/12053">12053</ref><ref source="OSVDB" url="http://www.osvdb.org/12516">12516</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Jan/1012802.html">1012802</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Jan/1012805.html">1012805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13600">13600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18623">namazu-tab-query-xss(18623)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Namazu" vendor="Namazu"><vers num="2.0.8"/><vers num="2.0.13"/><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1319" published="2004-12-15" seq="2004-1319" severity="Medium" type="CVE"><desc><descript source="cve">The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by &quot;AbusiveParent&quot; in Internet Explorer 6.0.2900.2180.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0167.html">20041215 MSIE DHTML Edit Control Cross Site Scripting Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-013.mspx">MS05-013</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/356600">VU#356600</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1114.html">OVAL1114</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1701.html">OVAL1701</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3464.html">OVAL3464</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3851.html">OVAL3851</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4758.html">OVAL4758</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13482/">13482</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11950">11950</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18504">ie-dhtml-xss(18504)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1114">oval:org.mitre.oval:def:1114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1701">oval:org.mitre.oval:def:1701</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3464">oval:org.mitre.oval:def:3464</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3851">oval:org.mitre.oval:def:3851</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4758">oval:org.mitre.oval:def:4758</ref></refs><vuln_soft><prod name="Optivity Telephony Manager (OTM)" vendor="Nortel"><vers num=""/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Mobile Voice Client" vendor="Nortel"><vers num="2050"/></prod><prod name="IP softphone" vendor="Nortel"><vers num="2050"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1320" published="2004-12-15" seq="2004-1320" severity="High" type="CVE"><desc><descript source="cve">Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312733624864&amp;w=2">20041215 Asante FM2008 10/100 Ethernet switch backdoor login</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11947">11947</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18521">asante-fm2008-default-account(18521)</ref></refs><vuln_soft><prod name="FM2008 Managed Ethernet Switch" vendor="Asante"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1321" published="2004-12-15" seq="2004-1321" severity="High" type="CVE"><desc><descript source="cve">The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312733624864&amp;w=2">20041215 Asante FM2008 10/100 Ethernet switch backdoor login</ref></refs><vuln_soft><prod name="FM2008 Managed Ethernet Switch" vendor="Asante"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1322" published="2004-12-15" seq="2004-1322" severity="High" type="CVE"><desc><descript source="cve">Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml">20041215 Cisco Unity Integrated with Exchange Has Default Passwords</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-060.shtml">P-060</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11954">11954</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18489">cisco-unity-exchange-default-accounts(18489)</ref></refs><vuln_soft><prod name="Unity Server" vendor="Cisco"><vers num="4.0"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.46"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1323" published="2004-12-16" seq="2004-1323" severity="Low" type="CVE"><desc><descript source="cve">Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://gleg.net/advisory_netbsd2.shtml">http://gleg.net/advisory_netbsd2.shtml</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13501/">13501</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18564">netbsd-compat-gain-privileges(18564)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1324" published="2004-12-18" seq="2004-1324" severity="Low" type="CVE"><desc><descript source="cve">The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352518211306&amp;w=2">20041218 MS Windows Media Player 9 Vulns (2)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12031">12031</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18576">mediaplayer-mp3-code-execution(18576)</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1325" published="2004-12-18" seq="2004-1325" severity="Medium" type="CVE"><desc><descript source="cve">The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352518211306&amp;w=2">20041218 MS Windows Media Player 9 Vulns (2)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12032">12032</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18587">mediaplayer-activex-information-disclosure(18587)</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1326" published="2004-12-20" seq="2004-1326" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356470029424&amp;w=2">20041219 Exploit for Ultrix 4.5 dxterm</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/exploits/20041220.ultrix_dxterm_4.5_exploit.c.php">http://www.frsirt.com/exploits/20041220.ultrix_dxterm_4.5_exploit.c.php</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12049">12049</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18613">ultrix-dxterm-bo(18613)</ref></refs><vuln_soft><prod name="dxterm" vendor="Ultrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1327" published="2004-12-31" seq="2004-1327" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356203624337&amp;w=2">20041220 Crystal FTP Pro Client Buffer Overflow</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13583/">13583</ref><ref source="BID" url="http://www.securityfocus.com/bid/12038">12038</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18594">crystal-ftp-list-bo(18594)</ref></refs><vuln_soft><prod name="Crystal FTP" vendor="Crystal Art Software"><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1328" published="2004-12-31" seq="2004-1328" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355911415320&amp;w=2">SSRT4687</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13565/">13565</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12029">12029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18577">hp-newgrp-gain-privileges(18577)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.04"/><vers num="B.11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1329" published="2004-12-20" seq="2004-1329" severity="High" type="CVE"><desc><descript source="cve">Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355931920123&amp;w=2">20041220 AIX 5.1/5.2/5.3 local root exploits</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64389&amp;apar=only">IY64389</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64277&amp;apar=only">IY64277</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12041">12041</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18620">aix-diagnostics-gain-privileges(18620)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464276/100/0/threaded">
20070330 AIX 4.3 lsmcode local root command execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464481/100/0/threaded">
20070402 Re: AIX 4.3 lsmcode local root command execution</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/701">
701</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1330" published="2004-12-31" seq="2004-1330" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355931920123&amp;w=2">20041220 AIX 5.1/5.2/5.3 local root exploits</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64358&amp;apar=only">IY64358</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64522&amp;apar=only">IY64522</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64312&amp;apar=only">IY64312</ref><ref source="MISC" url="http://www.frsirt.com/exploits/20041220.paginit.c.php">http://www.frsirt.com/exploits/20041220.paginit.c.php</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12043">12043</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18618">aix-paginit-username-bo(18618)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1331" published="2004-11-16" seq="2004-1331" severity="Low" type="CVE"><desc><descript source="cve">The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the &quot;File Download - Security Warning&quot; dialog and save arbitrary files with arbitrary extensions via the SaveAs command.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.html">20041119 Microsoft Internet Explorer 6 SP2 Vulnerabilities / Full disclosure Vs. Security by Obscurity...</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php">http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/743974">VU#743974</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13203/">13203</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11686">11686</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18181">ie-execommand-warning-bypass(18181)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3220">3220</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1332" published="2004-12-31" seq="2004-1332" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=175&amp;type=vulnerabilities&amp;flashstatus=false">20041221 Hewlett Packard HP-UX ftpd Remote Buffer Overflow Vulnerability</ref><ref patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797179710695&amp;w=2">SSRT4883</ref><ref source="MISC" url="http://securitytracker.com/id?1012650">http://securitytracker.com/id?1012650</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/647438">VU#647438</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12077">12077</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13608">13608</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18636">hp-ftpd-bo(18636)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.11i"/><vers num="11.23"/><vers num="10.24"/><vers num="10.20 SIS"/><vers num="10.20 Series 800"/><vers num="10.20 Series 700"/><vers num="10.20"/><vers num="10.10"/><vers num="10.01"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.04"/><vers num="B.11.00"/></prod><prod name="HP-UX VVOS" vendor="HP"><vers num="11.04"/><vers num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1333" published="2004-12-15" seq="2004-1333" severity="Low" type="CVE"><desc><descript source="cve">Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383108211524&amp;w=2">20041215 [USN-47-1] Linux kernel vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11956">11956</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18523">linux-vcresize-dos(18523)</ref><ref adv="1" patch="1" source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-47-1">USN-47-1</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1334" published="2004-12-15" seq="2004-1334" severity="Low" type="CVE"><desc><descript source="cve">Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html">20041215 fun with linux kernel</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383108211524&amp;w=2">20041215 [USN-47-1] Linux kernel vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11956">11956</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18522">linux-ipoptionsget-dos(18522)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1335" published="2004-12-15" seq="2004-1335" severity="Low" type="CVE"><desc><descript source="cve">Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html">20041215 fun with linux kernel</ref><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383108211524&amp;w=2">20041215 [USN-47-1] Linux kernel vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11956">11956</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18524">linux-ipoptionsget-memory-leak(18524)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1336" published="2004-12-23" seq="2004-1336" severity="Low" type="CVE"><desc><descript source="cve">The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383942014839&amp;w=2">20041223 [USN-51-1] teTeX auxiliary script vulnerability</ref><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12100">12100</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18708">xdvizilla-symlink(18708)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="tetex-bin" vendor="Debian"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1337" published="2004-12-23" seq="2004-1337" severity="High" type="CVE"><desc><descript source="cve">The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384535113035&amp;w=2">20041223 Linux 2.6  Kernel Capability LSM Module Local Privilege Elevation</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12093">12093</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18673">linux-security-module-gain-privileges(18673)</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="Security Modules" vendor="Linux"><vers num="LSM1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ia64 ppc" num="4.1"/><vers edition="ia64 ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1338" published="2004-12-23" seq="2004-1338" severity="High" type="CVE"><desc><descript source="cve">The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382230614420&amp;w=2">20041223 Oracle Trigger Abuse (#NISR2122004I)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004I.txt">http://www.ngssoftware.com/advisories/oracle23122004I.txt</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18655">oracle-triggers-gain-privileges(18655)</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="9.2.0.2"/><vers num="9.2.0.1"/><vers num="9.0.2.3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num="9.0.1.4"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1339" published="2004-12-23" seq="2004-1339" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382230614420&amp;w=2">20041223 Oracle Trigger Abuse (#NISR2122004I)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004I.txt">http://www.ngssoftware.com/advisories/oracle23122004I.txt</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18655">oracle-triggers-gain-privileges(18655)</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="9.2.0.2"/><vers num="9.2.0.1"/><vers num="9.0.2.3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num="9.0.1.4"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1340" published="2005-01-26" seq="2004-1340" severity="Low" type="CVE"><desc><descript source="cve">Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-659">DSA-659</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19087">libpamradiusauth-insecure-permission(19087)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013030">1013030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14046">14046</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1341" published="2005-04-19" seq="2004-1341" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-711">DSA-711</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20179">info2www-url-xss(20179)</ref></refs><vuln_soft><prod name="info2www" vendor="Roar Smith"><vers num="1.2.2 .9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1342" published="2005-04-27" seq="2004-1342" severity="High" type="CVE"><desc><descript source="cve">CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-715">DSA-715</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.12"/><vers num="1.11.6"/><vers num="1.11.5"/><vers num="1.11.4"/><vers num="1.11.3"/><vers num="1.11.2"/><vers num="1.11.16"/><vers num="1.11.15"/><vers num="1.11.14"/><vers num="1.11.11"/><vers num="1.11.10"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10.8"/><vers num="1.10.7"/><vers num="1.10.6"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1343" published="2004-12-31" seq="2004-1343" severity="Medium" type="CVE"><desc><descript source="cve">CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-715">DSA-715</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.12"/><vers num="1.11.6"/><vers num="1.11.5"/><vers num="1.11.4"/><vers num="1.11.3"/><vers num="1.11.2"/><vers num="1.11.16"/><vers num="1.11.15"/><vers num="1.11.14"/><vers num="1.11.11"/><vers num="1.11.10"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10.8"/><vers num="1.10.7"/><vers num="1.10.6"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1345" published="2004-06-21" seq="2004-1345" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the &quot;ESMUser&quot; role to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57581-1&amp;searchclause=security">57581</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/976470">VU#976470</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-166.shtml">O-166</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11935/">11935</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10580">10580</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16463">esm-esmuser-gain-privileges(16463)</ref></refs><vuln_soft><prod name="Enterprise Storage Manager" vendor="Sun"><vers num="2.1"/></prod><prod name="StorEdge" vendor="Sun"><vers num="3510 FC Array"/><vers num="3310 SCSI Array"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1346" published="2004-06-19" seq="2004-1346" severity="Low" type="CVE"><desc><descript source="cve">The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57598-1&amp;searchclause=security">57598</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/390742">VU#390742</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4253">ESB-2004.0463</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12104/">12104</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10747">10747</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16729">solaris-svm-dos(16729)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3465.html">OVAL3465</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3465">oval:org.mitre.oval:def:3465</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1347" published="2004-08-10" seq="2004-1347" severity="Medium" type="CVE"><desc><descript source="cve">X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57619-1&amp;searchclause=security">57619</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139504">VU#139504</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12257/">12257</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10911">10911</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16940">xdm-xdmcp-dos(16940)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101549-1">101549</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100113.html">OVAL100113</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100113">oval:org.mitre.oval:def:100113</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1348" published="2004-09-06" seq="2004-1348" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57614-1">57614</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4369">ESB-2004.0565</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3960.html">OVAL3960</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12470/">12470</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11118">11118</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17269">solaris-innamed-dynamic-dos(17269)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3960">oval:org.mitre.oval:def:3960</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1349" published="2004-10-04" seq="2004-1349" severity="Low" type="CVE"><desc><descript source="cve">gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57600-1&amp;searchclause=security">57600</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/635998">VU#635998</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1654.html">OVAL1654</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12744">12744</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17577">solaris-gzip-modify-privileges(17577)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11318">11318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1654">oval:org.mitre.oval:def:1654</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1350" published="2004-10-30" seq="2004-1350" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.pentest.co.uk/documents/ptl-2004-06.html">http://www.pentest.co.uk/documents/ptl-2004-06.html</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57606-1&amp;searchclause=security">57606</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/964401">VU#964401</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-027.shtml">P-027</ref><ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4516">ESB-2004.0691</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1012005.html">http://securitytracker.com/alerts/2004/Oct/1012005.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13036/">13036</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17920">sun-web-proxy-bo(17920)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11566">11566</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=11304">11304</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1012005">1012005</ref></refs><vuln_soft><prod name="Java Web Proxy Server" vendor="Sun"><vers num="3.6 SP4"/><vers num="3.6 SP3"/><vers num="3.6 SP2"/><vers num="3.6 SP1"/><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1351" published="2004-12-07" seq="2004-1351" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57659-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22">57659</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4597">ESB-2004.0759</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-050.shtml">P-050</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval592.html">OVAL592</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18385">solaris-inrwhod-command-execution(18385)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11840">11840</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:592">oval:org.mitre.oval:def:592</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1352" published="2004-12-01" seq="2004-1352" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4586">ESB-2004.0749</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-045.shtml">P-045</ref><ref source="MISC" url="http://securitytracker.com/alerts/2004/Dec/1012368.html">http://securitytracker.com/alerts/2004/Dec/1012368.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3400.html">OVAL3400</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13340">13340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18310">solaris-ping-bo(18310)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11782">11782</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=12168">12168</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1012368">1012368</ref><ref source="BID" url="http://www.securityfocus.com/bid/11782/">11782</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57675-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22">57675</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3400">oval:org.mitre.oval:def:3400</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1353" published="2004-10-19" seq="2004-1353" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57657-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22">57657</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4482">ESB-2004.0661</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-017.shtml">P-017</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1011789.html">http://securitytracker.com/alerts/2004/Oct/1011789.html</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4834.html">OVAL4834</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12873/">12873</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17757">solaris-ldap-rbac-gain-priv(17757)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11459">11459</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=10939">10939</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011789">1011789</ref><ref source="BID" url="http://www.securityfocus.com/bid/11459/info/">11459</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4834">oval:org.mitre.oval:def:4834</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1354" published="2004-05-14" seq="2004-1354" severity="Medium" type="CVE"><desc><descript source="cve">The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57559-1&amp;searchclause=%22category:security%22%20%20111313-02">57559</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4105">ESB-2004.0347</ref><ref patch="1" source="MISC" url="http://spoofed.org/files/text/solaris-smc-advisory.txt">http://spoofed.org/files/text/solaris-smc-advisory.txt</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1482.html">OVAL1482</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11616/">11616</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10349">10349</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16146">smc-dotdot-directory-traversal(16146)</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=6119">6119</ref><ref source="BID" url="http://www.securityfocus.com/bid/10349/info/">10349</ref><ref source="MLIST" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/focus-sun/2003-10/0032.html">[focus-sun] 20031022 Information disclosure with SMC webserver on Solaris 9</ref><ref source="BID" url="http://www.securityfocus.com/bid/8873">8873</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1482">oval:org.mitre.oval:def:1482</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1355" published="2004-04-26" seq="2004-1355" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57545-1&amp;searchclause=%22category:security%22%20%20111313-02">57545</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4057">ESB-2004.0308</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2972.html">OVAL2972</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11483/">11483</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10216">10216</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15955">solaris-tcp-ip-dos(15955)</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=5665">5665</ref><ref source="BID" url="http://www.securityfocus.com/bid/10216/info/">10216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2972">oval:org.mitre.oval:def:2972</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="9.0"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1356" published="2004-04-23" seq="2004-1356" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57470-1&amp;searchclause=%22category:security%22%20%20108528-27">57470</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4056">ESB-2004.0307</ref><ref adv="1" patch="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1684.html">OVAL1684</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11457/">11457</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10202">10202</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=5619">5619</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15946">solaris-sendfilev-dos(15946)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1684">oval:org.mitre.oval:def:1684</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1357" published="2004-04-07" seq="2004-1357" severity="Medium" type="CVE"><desc><descript source="cve">The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57538-1">57538</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/737548">VU#737548</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=4003">ESB-2004.0263</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3505.html">OVAL3505</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11316/">11316</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10080">10080</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15784">solaris-sshd-log-bypass(15784)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10080/info/">10080</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3505">oval:org.mitre.oval:def:3505</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1358" published="2004-03-12" seq="2004-1358" severity="Medium" type="CVE"><desc><descript source="cve">The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57478-1&amp;searchclause=%22category:security%22%20%20114332-08">57478</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-099.shtml">O-099</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3788">ESB-2004.0069</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9852">9852</ref><ref adv="1" patch="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3567.html">OVAL3567</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14918">solaris-patches-disable-bsm(14918)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9852/info/">9852</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3567">oval:org.mitre.oval:def:3567</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1359" published="2004-03-04" seq="2004-1359" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57508-1">57508</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3935">ESB-2004.0201</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9837/info/">9837</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1127.html">OVAL1127</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15425">solaris-uucp-multiple-bo(15425)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9837">9837</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1127">oval:org.mitre.oval:def:1127</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1360" published="2004-02-27" seq="2004-1360" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57509-1">57509</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412566">VU#412566</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3902">ESB-2004.0169</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-089.shtml">O-089</ref><ref adv="1" patch="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1732.html">OVAL1732</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10991">10991</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9759/info/">9759</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=4071">4071</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15331">solaris-covfix-gain-privileges(15331)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9759">9759</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1732">oval:org.mitre.oval:def:1732</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1361" published="2004-12-23" seq="2004-1361" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383690219440&amp;w=2">20041223 Microsoft Windows winhlp32.exe Heap Overflow Vulnerability</ref><ref source="MISC" url="http://www.xfocus.net/flashsky/icoExp/">http://www.xfocus.net/flashsky/icoExp/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12091">12091</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18678">win-winhlp32-bo(18678)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="Web"/><vers num="Web"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1362" published="2004-08-04" seq="2004-1362" severity="High" type="CVE"><desc><descript source="cve">The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with &quot;%FF&quot; encoded sequences that are improperly converted to &quot;Y&quot; characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382306006205&amp;w=2">20041223 Oracle Character Conversion Bugs (#NISR2122004G)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004G.txt">http://www.ngssoftware.com/advisories/oracle23122004G.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18657">oracle-character-conversion-gain-privileges(18657)</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435974">VU#435974</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1363" published="2004-08-04" seq="2004-1363" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382345829397&amp;w=2">20041223 Oracle extproc buffer overflow (#NISR23122004A)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004.txt">http://www.ngssoftware.com/advisories/oracle23122004.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18659">oracle-extproc-library-bo(18659)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1364" published="2004-08-04" seq="2004-1364" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382406002365&amp;w=2">20041223 Oracle extproc directory traversal (#NISR23122004B)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004B.txt">http://www.ngssoftware.com/advisories/oracle23122004B.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18658">oracle-extproc-directory-traversal(18658)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/454861/100/0/threaded">20061219 Oracle &lt;= 9i / 10g (extproc) Local/Remote Command Execution Exploit</ref><ref source="" url="http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sql"></ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1365" published="2004-08-04" seq="2004-1365" severity="Medium" type="CVE"><desc><descript source="cve">Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382471608835&amp;w=2">20041223 Oracle extproc local command execution (#NISR23122004C)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004C.txt">http://www.ngssoftware.com/advisories/oracle23122004C.txt</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18662">oracle-extproc-command-execution(18662)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1366" published="2004-08-04" seq="2004-1366" severity="Low" type="CVE"><desc><descript source="cve">Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/385323">20041223 Oracle clear text passwords (#NISR2122004D)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004D.txt">http://www.ngssoftware.com/advisories/oracle23122004D.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18661">oracle-sysman-password-plaintext(18661)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1367" published="2004-08-04" seq="2004-1367" severity="Low" type="CVE"><desc><descript source="cve">Oracle 10g Database Server, when installed with a password that contains an exclamation point (&quot;!&quot;) for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382247308064&amp;w=2">20041223 Oracle clear text passwords (#NISR2122004D)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004D.txt">http://www.ngssoftware.com/advisories/oracle23122004D.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-28" name="CVE-2004-1368" published="2004-08-04" seq="2004-1368" severity="High" type="CVE"><desc><descript source="cve">ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382264415387&amp;w=2">20041223 Oracle ISQLPlus file access vulnerability (#NISR2122004E)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004E.txt">http://www.ngssoftware.com/advisories/oracle23122004E.txt</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18656">oracle-isqlplus-file-access(18656)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435974">VU#435974</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4.1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1369" published="2004-08-04" seq="2004-1369" severity="Medium" type="CVE"><desc><descript source="cve">The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382524401468&amp;w=2">20041223 Oracle TNS Listener DoS (#NISR2122004F)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004F.txt">http://www.ngssoftware.com/advisories/oracle23122004F.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18664">oracle-tnslsnr-nsgr-dos(18664)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4 .1"/><vers num="9.0.4"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1370" published="2004-08-04" seq="2004-1370" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382596129607&amp;w=2">20041223 Oracle multiple PL/SQL injection vulnerabilities (#NISR2122004H)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004H.txt">http://www.ngssoftware.com/advisories/oracle23122004H.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18665">oracle-procedure-sql-injection(18665)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/><vers num="9.0.4"/><vers num="9.0.4 .1"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-1371" published="2004-08-04" seq="2004-1371" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382570313035&amp;w=2">20041223 Oracle wrapped procedure overflow (#NISR2122004J)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/oracle23122004J.txt">http://www.ngssoftware.com/advisories/oracle23122004J.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">TA04-245A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10871">10871</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18666">oracle-wrapped-procedure-bo(18666)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/316206">VU#316206</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1">101782</ref></refs><vuln_soft><prod name="Enterprise Manager Grid Control" vendor="Oracle"><vers num="10g 10.1.0.2"/></prod><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.0.1"/><vers num="9.0i"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="10g 9.0.4.1"/><vers num="10g 9.0.4"/></prod><prod name="Enterprise Manager Database Control" vendor="Oracle"><vers num="10g 10.1.2"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Standard 9.0.2"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0"/><vers num="Standard 8.1.7"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 8.1.7"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 8.1.7"/><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Enterprise 8.1.7 .4"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.0.5 .0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 1"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num=""/></prod><prod name="Oracle" vendor="Oracle"><vers num="9i Application Server"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4 .0"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1 .0.2"/><vers num="Standard 9.0.4 .0"/><vers num="Personal 10.1 .0.2"/><vers num="Personal 9.0.4 .0"/><vers num="Enterprise 10.1.0.2"/><vers num="Enterprise 9.0.4 .0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/><vers num="11i 11.5.2"/><vers num="11i 11.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1372" published="2004-09-01" seq="2004-1372" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382730431065&amp;w=2">20041223 IBM DB2 rec2xml buffer overflow vulnerability (#NISR2122004J)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/db223122004K.txt">http://www.ngssoftware.com/advisories/db223122004K.txt</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382462924162&amp;w=2">20041223 IBM DB2 generate_distfile buffer overflow vulnerability (#NISR2122004L)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/db223122004L.txt">http://www.ngssoftware.com/advisories/db223122004L.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11089">11089</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18682">db2-rec2xml-bo(18682)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18663">db2-generatedistfile-bo(18663)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="AIX" num="8.1"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1373" published="2004-12-23" seq="2004-1373" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382975516003&amp;w=2">20041223 SHOUTcast remote format string vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886444014745&amp;w=2">20050219 exwormshoucast  part of PTjob project: SHOUTcast v1.9.4 remote</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-04.xml">GLSA-200501-04</ref><ref source="MISC" url="http://securitytracker.com/id?1012675">http://securitytracker.com/id?1012675</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12096">12096</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18669">shoutcast-format-string(18669)</ref></refs><vuln_soft><prod name="Shoutcast Server" vendor="NullSoft"><vers edition="Win32" num="1.9.4"/><vers edition="Mac OS X" num="1.9.4"/><vers edition="Linux" num="1.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1374" published="2004-12-18" seq="2004-1374" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://gleg.net/advisory_netbsd2.shtml">http://gleg.net/advisory_netbsd2.shtml</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1375" published="2004-12-23" seq="2004-1375" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384155209555&amp;w=2">SSRT4699</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-085.shtml">P-085</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12098">12098</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18674">hp-sam-gain-privileges(18674)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.04"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1376" published="2004-12-30" seq="2004-1376" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461358930103&amp;w=2">20041230 7a69Adv#17 - Internet Explorer FTP download path disclosure</ref><ref adv="1" source="MISC" url="http://www.7a69ezine.org/node/view/176">http://www.7a69ezine.org/node/view/176</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13704">13704</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1377" published="2004-12-27" seq="2004-1377" severity="Low" type="CVE"><desc><descript source="cve">The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-02.xml">GLSA-200501-02</ref><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html">http://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13641">13641</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12108">12108</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12109">12109</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18671">gnu-a2ps-fixpsin-symlink(18671)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18672">gnu-a2ps-psmanupin-symlink(18672)</ref></refs><vuln_soft><prod name="a2ps" vendor="GNU"><vers num="4.13b"/><vers num="4.13"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="TurboLinux Server" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Turbolinux Home" vendor="Turbolinux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1378" published="2004-09-21" seq="2004-1378" severity="Medium" type="CVE"><desc><descript source="cve">The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109583829122679&amp;w=2">20040920 Possible DoS attack against jabberd 1.4.3 and jadc2s 0.9.0</ref><ref source="MLIST" url="http://mail.jabber.org/pipermail/jabberd/2004-September/002004.html">20040919 [jabberd] Jabberd 1.4 critical bug</ref><ref patch="1" source="CONFIRM" url="http://devel.amessage.info/jabberd14/">http://devel.amessage.info/jabberd14/</ref><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html">http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-31.xml">GLSA-200409-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11231">11231</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17466">jabberd-xml-dos(17466)</ref><ref source="OSVDB" url="http://www.osvdb.org/10257">10257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011383">1011383</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011384">1011384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12636">12636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17467">jadc2s-xml-dos(17467)</ref></refs><vuln_soft><prod name="jabberd" vendor="JabberStudio"><vers num="1.4.3"/><vers num="1.4.2a"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod><prod name="jadc2s" vendor="JabberStudio"><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1379" published="2004-09-16" seq="2004-1379" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/375482/2004-09-02/2004-09-08/0">20040906 XSA-2004-5: heap overflow in DVD subpicture decoder</ref><ref adv="1" patch="1" source="CONFIRM" url="http://xinehq.de/index.php/security/XSA-2004-5">http://xinehq.de/index.php/security/XSA-2004-5</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-657">DSA-657</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml">GLSA-200409-30</ref><ref patch="1" source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.320308">SSA:2004-266</ref><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/131bd7c4-64a3-11d9-829a-000a95bc6fae.html">http://www.vuxml.org/freebsd/131bd7c4-64a3-11d9-829a-000a95bc6fae.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11205">11205</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17423">xine-dvd-subpicture-bo(17423)</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="0.9.8"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/></prod><prod name="xine" vendor="xine"><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0a"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1380" published="2004-10-20" seq="2004-1380" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the &quot;Dialog Box Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12712">12712</ref><ref adv="1" source="MISC" url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/">http://secunia.com/multiple_browsers_dialog_box_spoofing_test/</ref><ref adv="1" source="MISC" url="http://secunia.com/multiple_browsers_form_field_focus_test/">http://secunia.com/multiple_browsers_form_field_focus_test/</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-05.html">http://www.mozilla.org/security/announce/mfsa2005-05.html</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18864">web-browser-modal-spoofing(18864)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100050.html">OVAL100050</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100050">oval:org.mitre.oval:def:100050</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num=""/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1381" published="2004-10-20" seq="2004-1381" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12712">12712</ref><ref adv="1" source="MISC" url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/">http://secunia.com/multiple_browsers_dialog_box_spoofing_test/</ref><ref adv="1" source="MISC" url="http://secunia.com/multiple_browsers_form_field_focus_test/">http://secunia.com/multiple_browsers_form_field_focus_test/</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-05.html">http://www.mozilla.org/security/announce/mfsa2005-05.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17789">web-browser-inactive-info-disclosure(17789)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100053.html">OVAL100053</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100053">oval:org.mitre.oval:def:100053</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num=""/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1382" published="2004-12-31" seq="2004-1382" severity="Low" type="CVE"><desc><descript source="cve">The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-636">DSA-636</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:159">MDKSA-2004:159</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-261.html">RHSA-2005:261</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899903129801&amp;w=2">20041028 [USN-4-1] Standard C library script vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:159">MDKSA-2004:159</ref></refs><vuln_soft><prod name="glibc" vendor="GNU"><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.10"/><vers num="2.3.1"/><vers num="2.3"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.9"/><vers num="2.1.3.10"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1.6"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1383" published="2004-12-31" seq="2004-1383" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml">GLSA-200501-08</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11952">11952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18498">phpgroupware-projectid-sql-injection(18498)</ref></refs><vuln_soft><prod name="PHPGroupWare" vendor="PHPGroupWare"><vers num="0.9.16.003"/><vers num="0.9.16.002"/><vers num="0.9.16.000"/><vers num="0.9.16 RC1"/><vers num="0.9.14.007"/><vers num="0.9.14.006"/><vers num="0.9.14.005"/><vers num="0.9.14.003"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1384" published="2004-12-31" seq="2004-1384" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml">GLSA-200501-08</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11952">11952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18496">phpgroupware-index-preferences-xss(18496)</ref></refs><vuln_soft><prod name="PHPGroupWare" vendor="PHPGroupWare"><vers num="0.9.16.003"/><vers num="0.9.16.002"/><vers num="0.9.16.000"/><vers num="0.9.16 RC1"/><vers num="0.9.14.007"/><vers num="0.9.14.006"/><vers num="0.9.14.005"/><vers num="0.9.14.003"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1385" published="2004-12-31" seq="2004-1385" severity="Medium" type="CVE"><desc><descript source="cve">phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml">GLSA-200501-08</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18497">phpgroupware-path-disclosure(18497)</ref></refs><vuln_soft><prod name="PHPGroupWare" vendor="PHPGroupWare"><vers num="0.9.16.003"/><vers num="0.9.16.002"/><vers num="0.9.16.000"/><vers num="0.9.16 RC1"/><vers num="0.9.14.007"/><vers num="0.9.14.006"/><vers num="0.9.14.005"/><vers num="0.9.14.003"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1386" published="2004-12-31" seq="2004-1386" severity="High" type="CVE"><desc><descript source="cve">TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=97">http://tikiwiki.org/tiki-read_article.php?articleId=97</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml">GLSA-200501-12</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-084.shtml">P-084</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12110">12110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18691">tikiwiki-image-command-execution(18691)</ref><ref source="OSVDB" url="http://www.osvdb.org/12628">12628</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012700">1012700</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8.4"/><vers num="1.8.3"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.4"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1387" published="2004-12-31" seq="2004-1387" severity="Low" type="CVE"><desc><descript source="cve">The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627775326772&amp;w=2">20050119 [USN-65-1] Apache utility script vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13925">13925</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18993">apache-checkforensic-symlink(18993)</ref><ref source="MLIST" url="http://lists.debian.org/debian-apache/2005/01/msg00076.html">[debian-apache] 20050119 Bug#290974: marked as done (apache: Temporary usage bugs that can be used in symlink attacks)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-65-1">USN-65-1</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1388" published="2004-12-31" seq="2004-1388" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110677341711505&amp;w=2">20050126 DMA[2005-0125a] - &apos;berlios gpsd format string vulnerability&apos;</ref><ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt</ref><ref patch="1" source="MLIST" url="http://lists.berlios.de/pipermail/gpsd-announce/2005-January/000018.html">[Gpsd-announce] 20050127 Announcing release 2.8 of gpsd</ref><ref source="CONFIRM" url="http://www.mail-archive.com/debian-bugs-closed@lists.debian.org/msg02103.html">http://www.mail-archive.com/debian-bugs-closed@lists.debian.org/msg02103.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19079">gpsd-format-string(19079)</ref></refs><vuln_soft><prod name="GPS Daemon" vendor="BerliOS"><vers num="2.7"/><vers num="1.26"/><vers num="1.25"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.98"/><vers num="1.97"/><vers num="1.96"/><vers num="1.95"/><vers num="1.94"/><vers num="1.93"/><vers num="1.92"/><vers num="1.91"/><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="1.5" CVSS_impact_subscore="10.0" CVSS_score="6.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2004-1389" published="2004-12-31" seq="2004-1389" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://seer.support.veritas.com/docs/271727.htm">http://seer.support.veritas.com/docs/271727.htm</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/685456">VU#685456</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-020.shtml">P-020</ref><ref source="BID" url="http://www.securityfocus.com/bid/11494">11494</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12901/">12901</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17811">nebackup-bpjavasusvc-gain-privileges(17811)</ref></refs><vuln_soft><prod name="NetBackup Enterprise Server" vendor="Veritas"><vers num="5.1"/></prod><prod name="NetBackup BusinesServer" vendor="Veritas"><vers num="3.4.0"/><vers num="3.4.1"/><vers num="4.5.0"/></prod><prod name="NetBackup DataCenter" vendor="Veritas"><vers num="3.4.0"/><vers num="3.4.1"/><vers num="4.5.0"/></prod><prod name="NetBackup Server" vendor="Veritas"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1390" published="2004-12-31" seq="2004-1390" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0155.html">20040903 [RLSA_01-2004] QNX PPPoEd local root vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/961686">VU#961686</ref><ref source="BID" url="http://www.securityfocus.com/bid/11104">11104</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17280">Qnx-rtp-pppoed-flags-bo(17280)</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.2.0A"/><vers num="6.2.0"/><vers num="6.1.0"/><vers num="4.25"/><vers num="2.4"/></prod><prod name="RTP" vendor="QNX"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1391" published="2004-12-31" seq="2004-1391" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0155.html">20040903 [RLSA_01-2004] QNX PPPoEd local root vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/577566">VU#577566</ref><ref source="BID" url="http://www.securityfocus.com/bid/11105">11105</ref><ref source="OSVDB" url="http://www.osvdb.org/9661">9661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17284">qnx-rtp-mount-command-execute(17284)</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.1.0"/><vers num="6.1.0A"/><vers num="6.2.0"/><vers num="6.2.1A"/><vers num="6.2.1B"/><vers num="6.3.0"/></prod><prod name="RTP" vendor="QNX"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1392" published="2004-12-31" seq="2004-1392" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109898213806099&amp;w=2">20041027 PHP4 cURL functions bypass open_basedir</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2344">FLSA:2344</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-405.html">RHSA-2005:405</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625060220934&amp;w=2">20050120 [USN-66-1] PHP vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11557">11557</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011984">1011984</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17900">php-openbasedir-restriction-bypass(17900)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-406.html">RHSA-2005:406</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1393" published="2004-12-31" seq="2004-1393" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57474-1">57474</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3806">ESB-2004.0085</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/379390">VU#379390</ref><ref source="OSVDB" url="http://www.osvdb.org/3786">3786</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10730/">10730</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14998">solaris-tcsetattr-dos(14998)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9548">9548</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1394" published="2004-12-31" seq="2004-1394" severity="Medium" type="CVE"><desc><descript source="cve">The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57453-1">57453</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3800">ESB-2004.0079</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10755/">10755</ref><ref source="OSVDB" url="http://www.osvdb.org/3764">3764</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14988">solaris-pfexec-gain-privileges(14988)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9534/">9534</ref><ref source="BID" url="http://www.securityfocus.com/bid/9534">9534</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008893">1008893</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1395" published="2004-12-31" seq="2004-1395" severity="Medium" type="CVE"><desc><descript source="cve">The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not &quot;Operation would block.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029932.html">20041213 Socket unreacheable in the Lithtech engine (new protocol)</ref><ref patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/lithsock-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/11902">11902</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13446/">13446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18456">lithtech-engine-communication-dos(18456)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038095.html">20051021 F.E.A.R. 1.01 likes lithsock</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17317">17317</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297515500671&amp;w=2">20041213 Socket unreacheable in the Lithtech engine (new protocol)</ref></refs><vuln_soft><prod name="Contract Jack" vendor="Monolith Productions"><vers num="1.1"/></prod><prod name="Tron" vendor="Monolith Productions"><vers num="2.0.1.42"/><vers num="2.0.1.0"/></prod><prod name="No One Lives Forever 2" vendor="Monolith Productions"><vers num="1.3"/><vers num="1.0.004"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1396" published="2004-12-31" seq="2004-1396" severity="Low" type="CVE"><desc><descript source="cve">Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297310503541&amp;w=2">20041213 Winamp 5.07 (latest version) Remote Crash + other stupid shizle</ref><ref source="CONFIRM" url="http://forums.winamp.com/showthread.php?s=&amp;threadid=202007">http://forums.winamp.com/showthread.php?s=&amp;threadid=202007</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/372968">VU#372968</ref><ref source="BID" url="http://www.securityfocus.com/bid/11909">11909</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18466">winamp-mp4-m4a-dos(18466)</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Dec/1012525.html">1012525</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18467">winamp-nsa-nsv-dos(18467)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110303988101973&amp;w=2">20041213 Winamp 5.07 (latest version) Remote Crash + other</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.07"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1397" published="2004-12-31" seq="2004-1397" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305173302388&amp;w=2">20041214 STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/11924">11924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13441/">13441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18458">usemodwiki-wiki-xss(18458)</ref></refs><vuln_soft><prod name="UseModWiki" vendor="UseMod"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1398" published="2004-12-31" seq="2004-1398" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via format string specifiers in the extension argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305083706943&amp;w=2">20041214 Possible local root vulnerability in Roxio Toast on Mac OS X</ref><ref source="BID" url="http://www.securityfocus.com/bid/11926">11926</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18472">roxio-toast-tdixsupport-format-string(18472)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049452.html">20060913 [NETRAGARD-20060822 SECURITY ADVISORY] [ APPLE COMPUTER CORPORATION KEXTLOAD VULNERABILITY + ROXIO TOAST TITANUM 7 HELPER APP - LOCAL ROOT COMROMISE]</ref><ref source="" url="http://www.netragard.com/pdfs/research/apple-kext-tools-20060822.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20031">20031</ref></refs><vuln_soft><prod name="Toast" vendor="Roxio"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1399" published="2004-12-31" seq="2004-1399" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304269031484&amp;w=2">20041214 phpBB Attachment Mod Directory Traversal HTTP POST Injection</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11893">11893</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13421/">13421</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18437">attachment-mod-directory-traversal(18437)</ref></refs><vuln_soft><prod name="Attachment Mod" vendor="Opentools"><vers num="2.3.10"/><vers num="2.3.9"/><vers num="2.3.8"/><vers num="2.3.7"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1400" published="2004-12-31" seq="2004-1400" severity="High" type="CVE"><desc><descript source="cve">The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304839629822&amp;w=2">20041214 ASP Calendar Vulnerability &lt;www.ashiyane.com&gt;</ref><ref source="BID" url="http://www.securityfocus.com/bid/11931">11931</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18474">asp-calendar-gain-access(18474)</ref></refs><vuln_soft><prod name="ASP Calendar" vendor="Active Server Corner"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1401" published="2004-12-31" seq="2004-1401" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305802005220&amp;w=2">20041214 ASP-rider is vulnerable to sql injection attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/11933">11933</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13470/">13470</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18479">asp-rider-verify-sql-injection(18479)</ref></refs><vuln_soft><prod name="ASP-Rider" vendor="ASP-Rider"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1402" published="2004-12-31" seq="2004-1402" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314454810163&amp;w=2">20041215 iwebnegar is vulnerable to all kind of sql injections</ref><ref source="BID" url="http://www.securityfocus.com/bid/11946">11946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18505">iwebnegar-sql-injection(18505)</ref></refs><vuln_soft><prod name="iWebNegar" vendor="iWebNegar"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1403" published="2004-12-31" seq="2004-1403" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110313585810712&amp;w=2">20041215 STG Security Advisory: [SSA-20041214-14] GNUBoard PHP injection vulnerability</ref><ref source="MISC" url="http://sir.co.kr/?doc=bbs/gnuboard.php&amp;bo_table=pds&amp;page=1&amp;wr_id=1871">http://sir.co.kr/?doc=bbs/gnuboard.php&amp;bo_table=pds&amp;page=1&amp;wr_id=1871</ref><ref source="BID" url="http://www.securityfocus.com/bid/11948">11948</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13479/">13479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18494">gnuboard-doc-index-file-include(18494)</ref></refs><vuln_soft><prod name="GNUBoard" vendor="SIR"><vers num="3.39"/><vers num="3.38"/><vers num="3.37"/><vers num="3.36"/><vers num="3.35"/><vers num="3.34"/><vers num="3.33"/><vers num="3.32"/><vers num="3.31"/><vers num="3.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1404" published="2004-12-31" seq="2004-1404" severity="High" type="CVE"><desc><descript source="cve">Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321557806215&amp;w=2">20041216 STG Security Advisory: [SSA-20041215-18] Vulnerability of uploading files with multiple extensions in phpBB Attachment Mod</ref><ref patch="1" source="CONFIRM" url="http://www.opentools.de/board/viewtopic.php?t=3590">http://www.opentools.de/board/viewtopic.php?t=3590</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11893">11893</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13421/">13421</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18438">attachment-mod-file-upload(18438)</ref></refs><vuln_soft><prod name="Attachment Mod" vendor="Opentools"><vers num="2.3.10"/><vers num="2.3.9"/><vers num="2.3.8"/><vers num="2.3.7"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1405" published="2004-12-31" seq="2004-1405" severity="High" type="CVE"><desc><descript source="cve">MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321710420059&amp;w=2">20041216 STG Security Advisory: [SSA-20041215-19] Vulnerability of uploading files with multiple extensions in MediaWiki</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11985">11985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13478/">13478</ref><ref patch="1" source="MISC" url="http://wikipedia.sourceforge.net/">http://wikipedia.sourceforge.net/</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-08" name="CVE-2004-1406" published="2004-12-31" seq="2004-1406" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321654705580&amp;w=2">20041216 [MaxPatrol] SQL-injection in Ikonboard 3.1.x</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11982">11982</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13513">13513</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18533">ikonboard-ikonboard-sql-injection(18533)</ref></refs><vuln_soft><prod name="ikonboard" vendor="Ikonboard.com"><vers num="3.1.3"/><vers num="3.1.2a"/><vers num="3.1.1"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1407" published="2004-12-31" seq="2004-1407" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.security.org.sg/vuln/singapore0910.html">http://www.security.org.sg/vuln/singapore0910.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11990">11990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18528">singapore-thumb-directory-traversal(18528)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18532">singapore-adminclass-directory-traversal(18532)</ref></refs><vuln_soft><prod name="Image Gallery Web Application" vendor="singapore"><vers num="0.9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1408" published="2004-12-31" seq="2004-1408" severity="High" type="CVE"><desc><descript source="cve">The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11990">11990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18531">singapore-adminclass-file-upload(18531)</ref></refs><vuln_soft><prod name="Image Gallery Web Application" vendor="singapore"><vers num="0.9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1409" published="2004-12-31" seq="2004-1409" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11990">11990</ref></refs><vuln_soft><prod name="Image Gallery Web Application" vendor="singapore"><vers num="0.9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1410" published="2004-12-31" seq="2004-1410" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330741828726&amp;w=2">20041217 Gadu-Gadu, another two bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/11998">11998</ref><ref source="OSVDB" url="http://www.osvdb.org/12524">12524</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13450">13450</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num="6.0 build155"/><vers num="6.0 build154"/><vers num="6.0 build153"/><vers num="6.0 build152"/><vers num="6.0 build151"/><vers num="6.0 build150"/><vers num="6.0 build149"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1411" published="2004-12-31" seq="2004-1411" severity="Low" type="CVE"><desc><descript source="cve">Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330741828726&amp;w=2">20041217 Gadu-Gadu, another two bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/11998">11998</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18580">gadu-gadu-image-dos(18580)</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num="6.0 build155"/><vers num="6.0 build154"/><vers num="6.0 build153"/><vers num="6.0 build152"/><vers num="6.0 build151"/><vers num="6.0 build150"/><vers num="6.0 build149"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1412" published="2004-12-31" seq="2004-1412" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352428607171&amp;w=2">20041218 Multiple Vulnerabilities In Kayako eSupport v2.x</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00056-12182004">http://www.gulftech.org/?node=research&amp;article_id=00056-12182004</ref><ref source="BID" url="http://www.securityfocus.com/bid/12037">12037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18571">kayako-index-xss(18571)</ref></refs><vuln_soft><prod name="eSupport" vendor="Kayako"><vers num="2.3"/><vers num="2.2.5"/><vers num="2.2"/><vers num="2.1.8"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1413" published="2004-12-31" seq="2004-1413" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352428607171&amp;w=2">20041218 Multiple Vulnerabilities In Kayako eSupport v2.x</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00056-12182004">http://www.gulftech.org/?node=research&amp;article_id=00056-12182004</ref><ref source="BID" url="http://www.securityfocus.com/bid/12037">12037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18572">kayako-sql-injection(18572)</ref></refs><vuln_soft><prod name="eSupport" vendor="Kayako"><vers num="2.3"/><vers num="2.2.5"/><vers num="2.2"/><vers num="2.1.8"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1414" published="2004-12-31" seq="2004-1414" severity="Medium" type="CVE"><desc><descript source="cve">Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110357519312200&amp;w=2">20041220 Gadu-Gadu Remote DoS (all versions)</ref><ref source="MISC" url="http://www.soltysiak.com/gg-dos.txt">http://www.soltysiak.com/gg-dos.txt</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num="6.1 build156"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1415" published="2004-12-31" seq="2004-1415" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110375900916558&amp;w=2">20041222 2Bgal : 2.4 &amp; 2.5.1 SQL injection Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12083">12083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13620">13620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18645">2bgal-dispalbum-sql-injection(18645)</ref></refs><vuln_soft><prod name="2Bgal" vendor="ben3w"><vers num="2.4"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-1416" published="2004-12-31" seq="2004-1416" severity="Medium" type="CVE"><desc><descript source="cve">pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref sig="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110374765215675&amp;w=2">20041222 Realone2.0 </ref><ref source="OSVDB" url="http://www.osvdb.org/12660">12660</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110374765215675&amp;w=2">20041222 Realone2.0 &apos;pnxr3260.dll&apos; Lets Remote Users IE  Browser Crash</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2800.1106"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="6.0.11.868"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1417" published="2004-12-31" seq="2004-1417" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383119525592&amp;w=2">20041223 Cross Site Scripting In PsychoStats 2.2.4 Beta &amp;&amp; Earlier</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00057-12222004">http://www.gulftech.org/?node=research&amp;article_id=00057-12222004</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13619/">13619</ref><ref patch="1" source="MISC" url="http://www.psychostats.com/forums/viewtopic.php?t=11022">http://www.psychostats.com/forums/viewtopic.php?t=11022</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12089">12089</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18651">psychostats-login-xss(18651)</ref></refs><vuln_soft><prod name="PsychoStats" vendor="PsychoStats"><vers num="2.2.4 beta"/><vers num="2.2.2 beta"/><vers num="2.2.1 beta"/><vers num="2.2 beta"/><vers num="2.1 beta"/><vers num="2.0.1 beta"/><vers num="2.0 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1418" published="2004-12-31" seq="2004-1418" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384387332443&amp;w=2">20041223 WPkontakt message parsing error</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12097">12097</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18685">wpkontakt-email-command-execution(18685)</ref></refs><vuln_soft><prod name="WPKontakt" vendor="Wirtualna Polska"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-15" name="CVE-2004-1419" published="2004-12-31" seq="2004-1419" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110391024404947&amp;w=2">20041224 STG Security Advisory: [SSA-20041220-16] PHP source injection and cross-site scripting vulnerabilities in ZeroBoard</ref><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030224.html">20041223 STG Security Advisory: [SSA-20041220-16] PHP source injection and cross-site scripting vulnerabilities in ZeroBoard</ref><ref source="BID" url="http://www.securityfocus.com/bid/12103">12103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18679">zeroboard-write-file-include(18679)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18677">zeroboard-outlogin-file-include(18677)</ref><ref source="OSVDB" url="http://www.osvdb.org/12580">12580</ref><ref source="OSVDB" url="http://www.osvdb.org/12581">12581</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012677">1012677</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13649">13649</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1420" published="2004-12-31" seq="2004-1420" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2">20041228 Multiple WHM Autopilot Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12119">12119</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13673">13673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18700">whm-autopilot-header-xss(18700)</ref></refs><vuln_soft><prod name="AutoPilot" vendor="WHM"><vers num="2.4.6.5"/><vers num="2.4.6"/><vers num="2.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1421" published="2004-12-31" seq="2004-1421" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2">20041228 Multiple WHM Autopilot Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12119">12119</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13673">13673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18699">whm-autopilot-php-file-include(18699)</ref><ref source="OSVDB" url="http://www.osvdb.org/12695">
12695</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012707">
1012707</ref></refs><vuln_soft><prod name="WHM AutoPilot" vendor="WHM"><vers num="2.4.6.5"/><vers num="2.4.6"/><vers num="2.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1422" published="2004-12-31" seq="2004-1422" severity="Medium" type="CVE"><desc><descript source="cve">WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2">20041228 Multiple WHM Autopilot Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12119">12119</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13673">13673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18701">whm-autopilot-information-disclosure(18701)</ref></refs><vuln_soft><prod name="WHM AutoPilot" vendor="WHM"><vers num="2.4.6.5"/><vers num="2.4.6"/><vers num="2.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-30" name="CVE-2004-1423" published="2004-12-31" seq="2004-1423" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110434580716205&amp;w=2">20041229 php-Calendar File Include Vulnerability [ Command Exec ]</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00060-12292004">http://www.gulftech.org/?node=research&amp;article_id=00060-12292004</ref><ref source="BID" url="http://www.securityfocus.com/bid/12127">12127</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18710">php-calendar-file-include(18710)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449397/100/0/threaded">20061021 Virtual Law Office (phpc_root_path) Remote File Include Vulnerability</ref><ref source="" url="http://www.milw0rm.com/exploits/2608"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=296020&amp;group_id=46800"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20657">20657</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4145">ADV-2006-4145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22516">22516</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017107">1017107</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29710">vlo-phpcrootpath-file-include(29710)</ref></refs><vuln_soft><prod name="PHP-Calendar" vendor="PHP-Calendar"><vers num="0.10"/><vers num="0.9.1"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1424" published="2004-12-31" seq="2004-1424" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425409614735&amp;w=2">20041227 Multiple Vulnerabilities in Moodle</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110444531816566&amp;w=2">20041230 Re: Multiple Vulnerabilities in Moodle</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12120">12120</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13694">13694</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18702">moodle-view-search-xss(18702)</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1425" published="2004-12-31" seq="2004-1425" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425409614735&amp;w=2">20041227 Multiple Vulnerabilities in Moodle</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110444531816566&amp;w=2">20041230 Re: Multiple Vulnerabilities in Moodle</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12120">12120</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18550">moodle-directory-traversal(18550)</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1426" published="2004-12-31" seq="2004-1426" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110442847614890&amp;w=2">20041230 KorWeblog php injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12132">12132</ref></refs><vuln_soft><prod name="KorWeblog" vendor="KorWeblog"><vers num="1.6.1"/><vers num="1.6.2cvs"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1427" published="2004-12-31" seq="2004-1427" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110442847614890&amp;w=2">20041230 KorWeblog php injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12132">12132</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13700">13700</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18717">korweblog-install-file-include(18717)</ref></refs><vuln_soft><prod name="KorWeblog" vendor="KorWeblog"><vers num="1.6.1"/><vers num="1.6.2cvs"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1428" published="2004-12-31" seq="2004-1428" severity="Medium" type="CVE"><desc><descript source="cve">ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451582011666&amp;w=2">20041231 ArGoSoft FTP Server reveals valid usernames and allows for brute</ref><ref source="MISC" url="http://www.lovebug.org/argosoft_advisory.txt">http://www.lovebug.org/argosoft_advisory.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12139">12139</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18721">argosoft-information-disclosure(18721)</ref><ref source="" url="http://www.argosoft.com/ftpserver/changelist.aspx"></ref><ref source="OSVDB" url="http://www.osvdb.org/11335">11335</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012744">1012744</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13063">13063</ref></refs><vuln_soft><prod name="FTP server" vendor="ArGoSoft"><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1.9"/><vers num="1.4.1.8"/><vers num="1.4.1.7"/><vers num="1.4.1.6"/><vers num="1.4.1.5"/><vers num="1.4.1.4"/><vers num="1.4.1.3"/><vers num="1.4.1.2"/><vers num="1.4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1429" published="2004-12-31" seq="2004-1429" severity="High" type="CVE"><desc><descript source="cve">ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451582011666&amp;w=2">20041231 ArGoSoft FTP Server reveals valid usernames and allows for brute</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18722">argosoft-bruteforce(18722)</ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.4.2.4" prev="1"/><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1.9"/><vers num="1.4.1.8"/><vers num="1.4.1.7"/><vers num="1.4.1.6"/><vers num="1.4.1.5"/><vers num="1.4.1.4"/><vers num="1.4.1.3"/><vers num="1.4.1.2"/><vers num="1.4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1430" published="2004-12-31" seq="2004-1430" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arbitrary SQL code via the gameid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451448630711&amp;w=2">20041231 SQL Injection Vulnerability In IBProArcade</ref><ref source="BID" url="http://www.securityfocus.com/bid/12138">12138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13260">13260</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18720">ibproarcade-gameid-sql-injection(18720)</ref></refs><vuln_soft><prod name="ipbProArcade" vendor="ipbProArcade"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1431" published="2004-12-31" seq="2004-1431" severity="Medium" type="CVE"><desc><descript source="cve">FormMail.php 5.0, and possibly other versions, allows remote attackers to read arbitrary files via a full pathname in the ar_file (auto-reply) parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110460092827419&amp;w=2">20041231 Jacks FormMail.php remote file access vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12145">12145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10815">10815</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18724">jack-formmail-arfile-view-files(18724)</ref></refs><vuln_soft><prod name="Jack&apos;s FormMail.php" vendor="Joe Lumbroso"><vers num="5.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1432" published="2004-12-31" seq="2004-1432" severity="Medium" type="CVE"><desc><descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or (2) ICMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/918920">VU#918920</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/969344">VU#969344</ref><ref source="BID" url="http://www.securityfocus.com/bid/10768">10768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12117">12117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16760">cisco-ons-ip-dos(16760)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16761">cisco-ons-icmp-dos(16761)</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0 (0)"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="2.3 (5)"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2.0"/><vers num="3.1.0"/><vers num="3.0"/><vers num="2.3 (5)"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1433" published="2004-12-31" seq="2004-1433" severity="Medium" type="CVE"><desc><descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/486224">VU#486224</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/800384">VU#800384</ref><ref source="BID" url="http://www.securityfocus.com/bid/10768">10768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12117">12117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16762">cisco-ons-tcp-dos(16762)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16764">cisco-ons-udp-dos(16764)</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0 (0)"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="2.3 (5)"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2.0"/><vers num="3.1.0"/><vers num="3.0"/><vers num="2.3 (5)"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1434" published="2004-12-31" seq="2004-1434" severity="Medium" type="CVE"><desc><descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/548968">VU#548968</ref><ref source="BID" url="http://www.securityfocus.com/bid/10768">10768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12117">12117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16765">cisco-ons-snmp-dos(16765)</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0 (0)"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="2.3 (5)"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2.0"/><vers num="3.1.0"/><vers num="3.0"/><vers num="2.3 (5)"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1435" published="2004-12-31" seq="2004-1435" severity="Medium" type="CVE"><desc><descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of TCP connections with an invalid response instead of the final ACK (TCP-ACK).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/277048">VU#277048</ref><ref source="BID" url="http://www.securityfocus.com/bid/10768">10768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12117">12117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16763">cisco-ons-tcp-ack-dos(16763)</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0 (0)"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="2.3 (5)"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2.0"/><vers num="3.1.0"/><vers num="3.0"/><vers num="2.3 (5)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1436" published="2004-12-31" seq="2004-1436" severity="High" type="CVE"><desc><descript source="cve">The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/760432">VU#760432</ref><ref source="BID" url="http://www.securityfocus.com/bid/10768">10768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12117">12117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16766">cisco-ons-tl1-auth-bypass(16766)</ref></refs><vuln_soft><prod name="ONS 15454SDH" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0 (0)"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="2.3 (5)"/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15454 Optical Transport Platform" vendor="Cisco"><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.5"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2.0"/><vers num="3.1.0"/><vers num="3.0"/><vers num="2.3 (5)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1437" published="2004-12-31" seq="2004-1437" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-19.xml">GLSA-200407-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10797">10797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16807">pavuk-digest-auth-bo(16807)</ref></refs><vuln_soft><prod name="Pavuk" vendor="Pavuk"><vers num="0.9pl28i"/><vers num="0.928r2"/><vers num="0.928r1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1438" published="2004-12-31" seq="2004-1438" severity="Low" type="CVE"><desc><descript source="cve">The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200407-20.xml">GLSA-200407-20</ref><ref source="CONFIRM" url="http://svn.collab.net/repos/svn/tags/1.0.6/CHANGES">http://svn.collab.net/repos/svn/tags/1.0.6/CHANGES</ref><ref patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Jul/1010779.html">http://www.securitytracker.com/alerts/2004/Jul/1010779.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10800">10800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16803">subversion-modauthzsvn-restriction-bypass(16803)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010779">1010779</ref><ref source="SREASON" url="http://securityreason.com/securityalert/60">60</ref></refs><vuln_soft><prod name="Subversion" vendor="Subversion"><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1439" published="2004-12-31" seq="2004-1439" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.security.org.sg/vuln/bjd361.html">http://www.security.org.sg/vuln/bjd361.html</ref><ref source="BUGTRAQ" url="http://www.ir3ip.net/pipermail/bugtraq/2004-September/009960.html">20040910 BlackJumboDog FTP Server version 3.6.1 Buffer Overflow [Exploit included]</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/714584">VU#714584</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10834">10834</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12203">12203</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16842">blackjumbodog-long-string-bo(16842)</ref></refs><vuln_soft><prod name="Black JumboDog" vendor="SapporoWorks"><vers num="3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1440" published="2004-12-31" seq="2004-1440" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109167869528138&amp;w=2">20040804 CORE-2004-0705: Vulnerabilities in PuTTY and PSCP</ref><ref source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html</ref><ref source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-modpow.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-modpow.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-04.xml">GLSA-200408-04 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10850">10850</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12212/">12212</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16885">putty-code-execution(16885)</ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.54"/><vers num="0.53b"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/><vers num="0.49"/><vers num="0.48"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1441" published="2004-12-31" seq="2004-1441" severity="High" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0642.html">20040715 XSS in Board Power forum</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/744590">VU#744590</ref><ref source="BID" url="http://www.securityfocus.com/bid/10734">10734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16698">boardpower-icq-xss(16698)</ref></refs><vuln_soft><prod name="Board Power" vendor="Board Power"><vers num="2.04PF"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1442" published="2004-12-31" seq="2004-1442" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error emssages such as &quot;DTWP001E.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/197318">VU#197318</ref><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/DMOA-5VNPEL">http://www.kb.cert.org/vuls/id/DMOA-5VNPEL</ref><ref source="BID" url="http://www.securityfocus.com/bid/9488">9488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10709/">10709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14925">ibm-netdata-db2wwwcomponent-xss(14925)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0019.html">20040126 Secunia Research: IBM Net.Data Macro Name Cross-Site Scripting Vulnerability</ref><ref source="" url="http://secunia.com/secunia_research/2004-1/advisory/"></ref><ref source="OSVDB" url="http://www.osvdb.org/3712">3712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008845">1008845</ref></refs><vuln_soft><prod name="Net.Data" vendor="IBM"><vers num="7.2"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1443" published="2004-12-31" seq="2004-1443" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-07.xml">GLSA-200408-07</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10845">10845</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12202/">12202</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16866">imp-html-viewer-xss(16866)</ref><ref source="" url="http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.106&amp;r2=1.389.2.109&amp;ty=h"></ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="3.2.4"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.3"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1444" published="2004-12-31" seq="2004-1444" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://packetstormsecurity.nl/0406-exploits/roundUP.txt">http://packetstormsecurity.nl/0406-exploits/roundUP.txt</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml">GLSA-200408-09</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11801/">11801</ref><ref patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Jun/1010415.html">http://www.securitytracker.com/alerts/2004/Jun/1010415.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10495">10459</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16350">roundup-get-view-file(16350)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010415">1010415</ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=961511&amp;group_id=31577&amp;atid=402788"></ref></refs><vuln_soft><prod name="Roundup" vendor="Roundup"><vers num="0.6.11"/><vers num="0.5.9"/><vers num="0.5.8 Stable"/><vers num="0.5.7"/><vers num="0.5.6"/><vers num="0.5.5"/><vers num="0.5.4"/><vers num="0.5.3"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1445" published="2004-12-31" seq="2004-1445" severity="Low" type="CVE"><desc><descript source="cve">A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-11.xml">GLSA-200408-11</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12127/">12127</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10784">10784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16768">nessus-adduser-race-condition(16768)</ref></refs><vuln_soft><prod name="Nessus" vendor="Nessus"><vers num="2.1.0"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1446" published="2004-12-31" seq="2004-1446" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.juniper.net/support/security/alerts/screenos-sshv1-2.txt">http://www.juniper.net/support/security/alerts/screenos-sshv1-2.txt</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/749870">VU#749870</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12208/">12208</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10854">10854</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16876">netscreen-screenos-sshv1-dos(16876)</ref></refs><vuln_soft><prod name="NetScreen ScreenOS" vendor="Juniper"><vers num="5.0"/><vers num="4.0.3 r4"/><vers num="4.0.3 r3"/><vers num="4.0.3 r2"/><vers num="4.0.3 r1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 r9"/><vers num="4.0.1 r8"/><vers num="4.0.1 r7"/><vers num="4.0.1 r6"/><vers num="4.0.1 r5"/><vers num="4.0.1 r4"/><vers num="4.0.1 r3"/><vers num="4.0.1 r2"/><vers num="4.0.1 r10"/><vers num="4.0.1 r1"/><vers num="4.0.1"/><vers num="4.0 r9"/><vers num="4.0 r8"/><vers num="4.0 r7"/><vers num="4.0 r6"/><vers num="4.0 r5"/><vers num="4.0 r4"/><vers num="4.0 r3"/><vers num="4.0 r2"/><vers num="4.0 r12"/><vers num="4.0 r11"/><vers num="4.0 r10"/><vers num="4.0 r1"/><vers edition="DIAL" num="4.0"/><vers num="4.0"/><vers num="3.1.1 r2"/><vers num="3.1 r9"/><vers num="3.1 r8"/><vers num="3.1 r7"/><vers num="3.1 r6"/><vers num="3.1 r5"/><vers num="3.1 r4"/><vers num="3.1 r3"/><vers num="3.1 r2"/><vers num="3.1 r12"/><vers num="3.1 r11"/><vers num="3.1 r10"/><vers num="3.1 r1"/><vers num="3.1"/><vers num="3.0.3 r8"/><vers num="3.0.3 r7"/><vers num="3.0.3 r6"/><vers num="3.0.3 r5"/><vers num="3.0.3 r4"/><vers num="3.0.3 r3"/><vers num="3.0.3 r2"/><vers num="3.0.3 r1.1"/><vers num="3.0.3 r1"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1 r7"/><vers num="3.0.1 r6"/><vers num="3.0.1 r5"/><vers num="3.0.1 r4"/><vers num="3.0.1 r3"/><vers num="3.0.1 r2"/><vers num="3.0.1 r1"/><vers num="3.0.1"/><vers num="3.0 r4"/><vers num="3.0 r3"/><vers num="3.0 r2"/><vers num="3.0 r1"/><vers num="3.0"/><vers num="2.10 r4"/><vers num="2.10 r3"/><vers num="2.8 r1"/><vers num="2.8"/><vers num="2.7.1 r3"/><vers num="2.7.1 r2"/><vers num="2.7.1 r1"/><vers num="2.7.1"/><vers num="2.6.1 r9"/><vers num="2.6.1 r8"/><vers num="2.6.1 r7"/><vers num="2.6.1 r6"/><vers num="2.6.1 r5"/><vers num="2.6.1 r4"/><vers num="2.6.1 r3"/><vers num="2.6.1 r2"/><vers num="2.6.1 r12"/><vers num="2.6.1 r11"/><vers num="2.6.1 r10"/><vers num="2.6.1 r1"/><vers num="2.6.1"/><vers num="2.6"/><vers num="2.5 r6"/><vers num="2.5 r2"/><vers num="2.5 r1"/><vers num="2.5"/><vers num="2.1 r7"/><vers num="2.1 r6"/><vers num="2.1"/><vers num="2.0.1 r8"/><vers num="1.73 r2"/><vers num="1.73 r1"/><vers num="1.66 r2"/><vers num="1.66"/><vers num="1.64"/><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1447" published="2004-12-31" seq="2004-1447" severity="Medium" type="CVE"><desc><descript source="cve">Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/370852">20040804 vulnerabilities in JetboxOne CMS</ref><ref source="MISC" url="http://echo.or.id/adv/adv03-y3dips-2004.txt">http://echo.or.id/adv/adv03-y3dips-2004.txt</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/586720">VU#586720</ref><ref source="BID" url="http://www.securityfocus.com/bid/10858">10858</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12230">12230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16898">jetbox-one-plaintext-password(16898)</ref><ref source="OSVDB" url="http://www.osvdb.org/8325">8325</ref></refs><vuln_soft><prod name="Jetbox One CMS" vendor="Jetbox"><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1448" published="2004-12-31" seq="2004-1448" severity="Medium" type="CVE"><desc><descript source="cve">Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/370852">20040804 vulnerabilities in JetboxOne CMS</ref><ref source="MISC" url="http://echo.or.id/adv/adv03-y3dips-2004.txt">http://echo.or.id/adv/adv03-y3dips-2004.txt</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/417408">VU#417408</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12230/">12230</ref><ref source="BID" url="http://www.securityfocus.com/bid/10859">10859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16900">jetbox-one-file-upload(16900)</ref></refs><vuln_soft><prod name="Jetbox One CMS" vendor="Jetbox"><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1449" published="2004-12-31" seq="2004-1449" severity="Low" type="CVE"><desc><descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user&apos;s hard drive by obscuring a file upload control and tricking the user into dragging text into that control.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=206859#c0">http://bugzilla.mozilla.org/show_bug.cgi?id=206859#c0</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="0.7"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1450" published="2004-12-31" seq="2004-1450" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=239122">http://bugzilla.mozilla.org/show_bug.cgi?id=239122</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1451" published="2004-12-31" seq="2004-1451" severity="Low" type="CVE"><desc><descript source="cve">Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=228176">http://bugzilla.mozilla.org/show_bug.cgi?id=228176</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/security/known-vulnerabilities.html">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10419/">10419</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1452" published="2004-12-31" seq="2004-1452" severity="High" type="CVE"><desc><descript source="cve">Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-15.xml">GLSA-200408-15</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10951">10951</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12296/">12296</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16993">gentoo-tomcat-gain-privileges(16993)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/><vers num="1.2"/><vers num="1.1a"/><vers num="0.7"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1453" published="2004-12-31" seq="2004-1453" severity="Low" type="CVE"><desc><descript source="cve">GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-16.xml">GLSA-200408-16</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=59526">http://bugs.gentoo.org/show_bug.cgi?id=59526</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-261.html">RHSA-2005:261</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10963">10963</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12306">12306</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17006">glibc-suid-info-disclosure(17006)</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-256.html">RHSA-2005:256</ref></refs><vuln_soft><prod name="glibc" vendor="GNU"><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.1"/><vers num="2.3"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.9"/><vers num="2.1.3.10"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1.6"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1454" published="2004-12-31" seq="2004-1454" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040818-ospf.shtml">20040818 Cisco IOS Malformed OSPF Packet Causes Reload</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-199.shtml">O-199</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/989406">VU#989406</ref><ref source="BID" url="http://www.securityfocus.com/bid/10971">10971</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12322">12322</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17033">cisco-ios-ospf-dos(17033)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3 XE"/><vers num="12.3 XC"/><vers num="12.3 XB"/><vers num="12.3 XA"/><vers num="12.3 T"/><vers num="12.3 BW"/><vers num="12.3 B"/><vers num="12.3 (9)"/><vers num="12.3 (7.7)"/><vers num="12.3 (7)T"/><vers num="12.3 (6a)"/><vers num="12.3 (6)"/><vers num="12.3 (5c)"/><vers num="12.3 (5b)"/><vers num="12.3 (5a)b"/><vers num="12.3 (5a)"/><vers num="12.3 (5)B1"/><vers num="12.3 (5)"/><vers num="12.3 (4)XQ"/><vers num="12.3 (4)XK"/><vers num="12.3 (4)XH"/><vers num="12.3 (4)XG1"/><vers num="12.3 (4)XD2"/><vers num="12.3 (4)XD1"/><vers num="12.3 (4)XD"/><vers num="12.3 (4)T4"/><vers num="12.3 (4)T3"/><vers num="12.3 (4)T2"/><vers num="12.3 (4)T1"/><vers num="12.3 (4)T"/><vers num="12.3 (4)EO1"/><vers num="12.3 (3e)"/><vers num="12.3 (2)XC3"/><vers num="12.3 (2)XC2"/><vers num="12.3 (2)XC1"/><vers num="12.3 (2)T3"/><vers num="12.3 (1a)"/><vers num="12.3"/><vers num="12.2 (18)SW"/><vers num="12.2 (18)SV"/><vers num="12.2 (18)SE"/><vers num="12.2 (18)S"/><vers num="12.2 (18)EW"/><vers num="12.2 (15)ZO"/><vers num="12.2 (15)ZN"/><vers num="12.2 (15)ZL1"/><vers num="12.2 (15)ZL"/><vers num="12.2 (15)ZK"/><vers num="12.2 (15)ZJ3"/><vers num="12.2 (15)ZJ2"/><vers num="12.2 (15)ZJ1"/><vers num="12.2 (15)ZJ"/><vers num="12.2 (15)T5"/><vers num="12.2 (15)T"/><vers num="12.2 (15)MC1"/><vers num="12.2 (15)CX"/><vers num="12.2 (15)BZ"/><vers num="12.2 (15)BX"/><vers num="12.2 (15)BC1"/><vers num="12.2 (15)BC"/><vers num="12.2 (15)B"/><vers num="12.2 (14)SZ2"/><vers num="12.2 (14)SZ1"/><vers num="12.2 (14)SZ"/><vers num="12.2 (13)ZH"/><vers num="12.2 (13)ZG"/><vers num="12.2 (13)ZF"/><vers num="12.2 (13)ZE"/><vers num="12.2 (13)ZD"/><vers num="12.2 (11)YV"/><vers num="12.2 (11)YU"/><vers num="12.0 (23)SZ"/><vers num="12.0 (23)SX"/><vers num="12.0 (22)SY"/><vers num="12.0 (22)S5"/><vers num="12.0 (22)S4"/><vers num="12.0 (22)S"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1455" published="2004-12-31" seq="2004-1455" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109284737628045&amp;w=2">20040817 Open Security Group Advisory #6</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-18.xml">GLSA-200408-18 </ref><ref source="SECUNIA" url="http://secunia.com/advisories/12194/">12194</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10890">10890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16930">xine-vcd-identifier-bo(16930)</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1 rc5 r2"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc2"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1456" published="2004-12-31" seq="2004-1456" severity="High" type="CVE"><desc><descript source="cve">filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109173359428253&amp;w=2">20040805 CVStrac Remote Arbitrary Code Execution exploit</ref><ref source="CONFIRM" url="http://www.cvstrac.org/cvstrac/tktview?tn=339">http://www.cvstrac.org/cvstrac/tktview?tn=339</ref><ref patch="1" source="CONFIRM" url="http://www.cvstrac.org/cvstrac/chngview?cn=316">http://www.cvstrac.org/cvstrac/chngview?cn=316</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/770816">VU#770816</ref><ref source="BID" url="http://www.securityfocus.com/bid/10878">10878</ref><ref source="OSVDB" url="http://www.osvdb.org/8373">8373</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12090/">12090</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16929">cvstrac-command-execute(16929)</ref></refs><vuln_soft><prod name="CVSTrac" vendor="CVSTrac"><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1457" published="2004-12-31" seq="2004-1457" severity="Medium" type="CVE"><desc><descript source="cve">The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/432097">VU#432097</ref><ref patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10093576.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10093576.htm</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10727">10727</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12067/">12067</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16697">novell-bordermanger-ikenlm-dos(16697)</ref></refs><vuln_soft><prod name="Bordermanager" vendor="Novell"><vers num="3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1458" published="2004-12-31" seq="2004-1458" severity="Medium" type="CVE"><desc><descript source="cve">The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/11047">11047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17115">ciscosecure-csadmin-http-dos(17115)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-203.shtml">O-203</ref><ref source="OSVDB" url="http://osvdb.org/9182">9182</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12386/">12386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17114">ciscosecure-csadmin-tcp-dos(17114)</ref></refs><vuln_soft><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Secure Access Control Server" vendor="Cisco"><vers num="3.2 (2) build 15"/><vers num="3.3 (1)"/><vers num="3.3"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1)"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1459" published="2004-12-31" seq="2004-1459" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/11047">11047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17116">ciscosecure-leap-radius-dos(17116)</ref></refs><vuln_soft><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Secure Access Control Server" vendor="Cisco"><vers num="3.3 (1)"/><vers num="3.3"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1)"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1460" published="2004-12-31" seq="2004-1460" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/11047">11047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17117">ciscosecure-nds-blank-authentication(17117)</ref></refs><vuln_soft><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Secure Access Control Server" vendor="Cisco"><vers num="3.3 (1)"/><vers num="3.3"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1)"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1461" published="2004-12-31" seq="2004-1461" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/11047">11047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17118">ciscosecure-csadmin-auth-bypass(17118)</ref></refs><vuln_soft><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Secure Access Control Server" vendor="Cisco"><vers num="3.3 (1)"/><vers num="3.3"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1)"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1462" published="2004-12-31" seq="2004-1462" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="https://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801">https://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml">GLSA-200408-25</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10805">10805</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=8194">8194</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16833">moinmoin-acl-gain-privileges(16833)</ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.11"/><vers num="0.10"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1463" published="2004-12-31" seq="2004-1463" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801">http://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml">GLSA-200408-25</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10801">10801</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=8195">8195</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16832">moinmoin-pageeditor-gain-privilege(16832)</ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.11"/><vers num="0.10"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-30" name="CVE-2004-1464" published="2004-12-31" seq="2004-1464" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml">20040827 Cisco Telnet Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/384230">VU#384230</ref><ref source="BID" url="http://www.securityfocus.com/bid/11060">11060</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1011079.html">http://www.securitytracker.com/alerts/2004/Aug/1011079.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12395/">12395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17131">cisco-ios-telnet-dos(17131)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011079">1011079</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3 YD"/><vers num="12.3 XU"/><vers num="12.3 XT"/><vers num="12.3 XR"/><vers num="12.3 XQ"/><vers num="12.3 XN"/><vers num="12.3 XM"/><vers num="12.3 XL"/><vers num="12.3 XK"/><vers num="12.3 XJ"/><vers num="12.3 XI"/><vers num="12.3 XH"/><vers num="12.3 XG"/><vers num="12.3 XF"/><vers num="12.3 XE"/><vers num="12.3 XD"/><vers num="12.3 XC"/><vers num="12.3 XB"/><vers num="12.3 XA"/><vers num="12.3 T"/><vers num="12.3 JA"/><vers num="12.3 BW"/><vers num="12.3 BC"/><vers num="12.3 B"/><vers num="12.3 (9)"/><vers num="12.3 (7.7)"/><vers num="12.3 (7)T"/><vers num="12.3 (6a)"/><vers num="12.3 (6)"/><vers num="12.3 (5c)"/><vers num="12.3 (5b)"/><vers num="12.3 (5a)b"/><vers num="12.3 (5a)"/><vers num="12.3 (5)B1"/><vers num="12.3 (5)"/><vers num="12.3 (4)XQ"/><vers num="12.3 (4)XK"/><vers num="12.3 (4)XH"/><vers num="12.3 (4)XG1"/><vers num="12.3 (4)XD2"/><vers num="12.3 (4)XD1"/><vers num="12.3 (4)XD"/><vers num="12.3 (4)T4"/><vers num="12.3 (4)T3"/><vers num="12.3 (4)T2"/><vers num="12.3 (4)T1"/><vers num="12.3 (4)T"/><vers num="12.3 (4)EO1"/><vers num="12.3 (3e)"/><vers num="12.3 (2)XC3"/><vers num="12.3 (2)XC2"/><vers num="12.3 (2)XC1"/><vers num="12.3 (2)T3"/><vers num="12.3 (1a)"/><vers num="12.3"/><vers num="12.2 ZQ"/><vers num="12.2 ZP"/><vers num="12.2 ZO"/><vers num="12.2 ZN"/><vers num="12.2 ZL"/><vers num="12.2 ZK"/><vers num="12.2 ZJ"/><vers num="12.2 ZI"/><vers num="12.2 ZH"/><vers num="12.2 ZG"/><vers num="12.2 ZF"/><vers num="12.2 ZE"/><vers num="12.2 ZD"/><vers num="12.2 ZC"/><vers num="12.2 ZB"/><vers num="12.2 ZA"/><vers num="12.2 YZ"/><vers num="12.2 YY"/><vers num="12.2 YX"/><vers num="12.2 YW"/><vers num="12.2 YV"/><vers num="12.2 YU"/><vers num="12.2 YT"/><vers num="12.2 YS"/><vers num="12.2 YR"/><vers num="12.2 YQ"/><vers num="12.2 YP"/><vers num="12.2 YO"/><vers num="12.2 YN"/><vers num="12.2 YM"/><vers num="12.2 YL"/><vers num="12.2 YK"/><vers num="12.2 YJ"/><vers num="12.2 YH"/><vers num="12.2 YG"/><vers num="12.2 YF"/><vers num="12.2 YE"/><vers num="12.2 YD"/><vers num="12.2 YC"/><vers num="12.2 YB"/><vers num="12.2 YA"/><vers num="12.2 XW"/><vers num="12.2 XU"/><vers num="12.2 XT"/><vers num="12.2 XS"/><vers num="12.2 XR"/><vers num="12.2 XQ"/><vers num="12.2 XN"/><vers num="12.2 XM"/><vers num="12.2 XL"/><vers num="12.2 XK"/><vers num="12.2 XJ"/><vers num="12.2 XI"/><vers num="12.2 XH"/><vers num="12.2 XG"/><vers num="12.2 XF"/><vers num="12.2 XE"/><vers num="12.2 XD"/><vers num="12.2 XC"/><vers num="12.2 XB15"/><vers num="12.2 XB"/><vers num="12.2 XA"/><vers num="12.2 T"/><vers num="12.2 SZ"/><vers num="12.2 SY"/><vers num="12.2 SXD"/><vers num="12.2 SXB"/><vers num="12.2 SXA"/><vers num="12.2 SX"/><vers num="12.2 SW"/><vers num="12.2 SV"/><vers num="12.2 SU"/><vers num="12.2 SE"/><vers num="12.2 SA"/><vers num="12.2 S"/><vers num="12.2 PI"/><vers num="12.2 PB"/><vers num="12.2 MX"/><vers num="12.2 MC"/><vers num="12.2 MB"/><vers num="12.2 JK"/><vers num="12.2 JA"/><vers num="12.2 EW"/><vers num="12.2 DX"/><vers num="12.2 DD"/><vers num="12.2 DA"/><vers num="12.2 CY"/><vers num="12.2 CX"/><vers num="12.2 BZ"/><vers num="12.2 BY"/><vers num="12.2 BX"/><vers num="12.2 BW"/><vers num="12.2 BC"/><vers num="12.2 B"/><vers num="12.2 12.2XU"/><vers num="12.2 (9)S"/><vers num="12.2 (8)ZB7"/><vers num="12.2 (8)YY3"/><vers num="12.2 (8)YY"/><vers num="12.2 (8)YW3"/><vers num="12.2 (8)YW2"/><vers num="12.2 (8)YD"/><vers num="12.2 (8)T10"/><vers num="12.2 (8)T"/><vers num="12.2 (8)JA"/><vers num="12.2 (8)BC1"/><vers num="12.2 (7a)"/><vers num="12.2 (7.4)S"/><vers num="12.2 (7)DA"/><vers num="12.2 (7)"/><vers num="12.2 (6c)"/><vers num="12.2 (6.8)T1a"/><vers num="12.2 (6.8)T0a"/><vers num="12.2 (5d)"/><vers num="12.2 (5)CA1"/><vers num="12.2 (5)"/><vers num="12.2 (4)YB"/><vers num="12.2 (4)YA8"/><vers num="12.2 (4)YA7"/><vers num="12.2 (4)YA1"/><vers num="12.2 (4)YA"/><vers num="12.2 (4)XW1"/><vers num="12.2 (4)XW"/><vers num="12.2 (4)XM2"/><vers num="12.2 (4)XM"/><vers num="12.2 (4)XL4"/><vers num="12.2 (4)XL"/><vers num="12.2 (4)T6"/><vers num="12.2 (4)T3"/><vers num="12.2 (4)T"/><vers num="12.2 (4)MX1"/><vers num="12.2 (4)MX"/><vers num="12.2 (4)MB3"/><vers num="12.2 (4)MB12"/><vers num="12.2 (4)JA1"/><vers num="12.2 (4)JA"/><vers num="12.2 (4)BX"/><vers num="12.2 (4)BC1a"/><vers num="12.2 (4)BC1"/><vers num="12.2 (4)B4"/><vers num="12.2 (4)B3"/><vers num="12.2 (4)B2"/><vers num="12.2 (4)B1"/><vers num="12.2 (4)B"/><vers num="12.2 (4)"/><vers num="12.2 (3d)"/><vers num="12.2 (3.4)BP"/><vers num="12.2 (3)"/><vers num="12.2 (24)"/><vers num="12.2 (23a)"/><vers num="12.2 (23.6)"/><vers num="12.2 (23)SW"/><vers num="12.2 (23)"/><vers num="12.2 (22)S"/><vers num="12.2 (21b)"/><vers num="12.2 (21a)"/><vers num="12.2 (21)"/><vers num="12.2 (20)S2"/><vers num="12.2 (20)S1"/><vers num="12.2 (20)S"/><vers num="12.2 (2.2)T"/><vers num="12.2 (2)YC"/><vers num="12.2 (2)XU2"/><vers num="12.2 (2)XU"/><vers num="12.2 (2)XT3"/><vers num="12.2 (2)XT"/><vers num="12.2 (2)XN"/><vers num="12.2 (2)XK2"/><vers num="12.2 (2)XK"/><vers num="12.2 (2)XJ1"/><vers num="12.2 (2)XJ"/><vers num="12.2 (2)XI2"/><vers num="12.2 (2)XI1"/><vers num="12.2 (2)XI"/><vers num="12.2 (2)XH3"/><vers num="12.2 (2)XH2"/><vers num="12.2 (2)XH"/><vers num="12.2 (2)XG"/><vers num="12.2 (2)XF"/><vers num="12.2 (2)XC1"/><vers num="12.2 (2)XB4"/><vers num="12.2 (2)XB3"/><vers num="12.2 (2)XB15"/><vers num="12.2 (2)XB14"/><vers num="12.2 (2)XB11"/><vers num="12.2 (2)XB"/><vers num="12.2 (2)XA5"/><vers num="12.2 (2)XA1"/><vers num="12.2 (2)XA"/><vers num="12.2 (2)T4"/><vers num="12.2 (2)DD3"/><vers num="12.2 (2)BY2"/><vers num="12.2 (2)BY"/><vers num="12.2 (2)BX"/><vers num="12.2 (2)B"/><vers num="12.2 (1d)"/><vers num="12.2 (1b)DA1"/><vers num="12.2 (1b)"/><vers num="12.2 (19)b"/><vers num="12.2 (18.2)"/><vers num="12.2 (18)SW"/><vers num="12.2 (18)SV"/><vers num="12.2 (18)SE"/><vers num="12.2 (18)S"/><vers num="12.2 (18)EW"/><vers num="12.2 (17d)SXB"/><vers num="12.2 (17d)"/><vers num="12.2 (17b)SXA"/><vers num="12.2 (17a)SXA"/><vers num="12.2 (17)a"/><vers num="12.2 (17)"/><vers num="12.2 (16f)"/><vers num="12.2 (16.5)S"/><vers num="12.2 (16.1)B"/><vers num="12.2 (16)BX"/><vers num="12.2 (16)B1"/><vers num="12.2 (16)B"/><vers num="12.2 (15.1)S"/><vers num="12.2 (15)ZO"/><vers num="12.2 (15)ZN"/><vers num="12.2 (15)ZL1"/><vers num="12.2 (15)ZL"/><vers num="12.2 (15)ZK"/><vers num="12.2 (15)ZJ3"/><vers num="12.2 (15)ZJ2"/><vers num="12.2 (15)ZJ1"/><vers num="12.2 (15)ZJ"/><vers num="12.2 (15)YS/1.2(1)"/><vers num="12.2 (15)T5"/><vers num="12.2 (15)T"/><vers num="12.2 (15)SL1"/><vers num="12.2 (15)MC1"/><vers num="12.2 (15)CX"/><vers num="12.2 (15)BZ"/><vers num="12.2 (15)BX"/><vers num="12.2 (15)BC1"/><vers num="12.2 (15)BC"/><vers num="12.2 (15)B"/><vers num="12.2 (14.5)T"/><vers num="12.2 (14.5)"/><vers num="12.2 (14)ZA8"/><vers num="12.2 (14)ZA2"/><vers num="12.2 (14)ZA"/><vers num="12.2 (14)SZ2"/><vers num="12.2 (14)SZ1"/><vers num="12.2 (14)SZ"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY03"/><vers num="12.2 (14)SY"/><vers num="12.2 (14)SX1"/><vers num="12.2 (14)S"/><vers num="12.2 (13e)"/><vers num="12.2 (13a)"/><vers num="12.2 (13.03)B"/><vers num="12.2 (13)ZL"/><vers num="12.2 (13)ZK"/><vers num="12.2 (13)ZJ"/><vers num="12.2 (13)ZH3"/><vers num="12.2 (13)ZH"/><vers num="12.2 (13)ZG"/><vers num="12.2 (13)ZF"/><vers num="12.2 (13)ZE"/><vers num="12.2 (13)ZD"/><vers num="12.2 (13)ZC"/><vers num="12.2 (13)T1"/><vers num="12.2 (13)MC1"/><vers num="12.2 (13)JA1"/><vers num="12.2 (12i)"/><vers num="12.2 (12h)"/><vers num="12.2 (12g)"/><vers num="12.2 (12b)"/><vers num="12.2 (12.05)T"/><vers num="12.2 (12.05)S"/><vers num="12.2 (12.05)"/><vers num="12.2 (12.02)T"/><vers num="12.2 (12.02)S"/><vers num="12.2 (12)DA3"/><vers num="12.2 (11)YZ2"/><vers num="12.2 (11)YX1"/><vers num="12.2 (11)YV"/><vers num="12.2 (11)YU"/><vers num="12.2 (11)YP1"/><vers num="12.2 (11)T9"/><vers num="12.2 (11)T3"/><vers num="12.2 (11)T"/><vers num="12.2 (11)JA1"/><vers num="12.2 (11)JA"/><vers num="12.2 (11)BC3c"/><vers num="12.2 (10g)"/><vers num="12.2 (10)DA2"/><vers num="12.2 (1.4)S"/><vers num="12.2 (1.1)PI"/><vers num="12.2 (1.1)"/><vers num="12.2 (1)XS1"/><vers num="12.2 (1)XS"/><vers num="12.2 (1)XQ"/><vers num="12.2 (1)XH"/><vers num="12.2 (1)XE3"/><vers num="12.2 (1)XE2"/><vers num="12.2 (1)XE"/><vers num="12.2 (1)XD4"/><vers num="12.2 (1)XD3"/><vers num="12.2 (1)XD1"/><vers num="12.2 (1)XD"/><vers num="12.2 (1)XA"/><vers num="12.2 (1)T"/><vers num="12.2 (1)S"/><vers num="12.2 (1)DX"/><vers num="12.2 (1)"/><vers num="12.2" prev="1"/><vers num="12.3(5)"/><vers num="12.2(7b)"/><vers num="12.2(4)T1"/><vers num="12.2(2)T1"/><vers num="12.2(2)T"/><vers num="12.2(19)"/><vers num="12.2(17a)"/><vers num="12.2(15)ZJ"/><vers num="12.2(15)T9"/><vers num="12.2(15)T8"/><vers num="12.2(15)T7"/><vers num="12.2(13)T9"/><vers num="12.2(13)T"/><vers num="12.2(13)"/><vers num="12.2(12c)"/><vers num="12.2(12)"/><vers num="12.2(11)YV"/><vers num="12.2(11)T8"/><vers num="12.2(11)T2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1465" published="2004-12-31" seq="2004-1465" severity="Low" type="CVE"><desc><descript source="cve">Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109416099301369&amp;w=2">20040901 WinZip Unspecified Buffer Overflows May Let Remote or Local Users Execute Arbitrary Code</ref><ref patch="1" source="CONFIRM" url="http://www.winzip.com/wz90sr1.htm">http://www.winzip.com/wz90sr1.htm</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-211.shtml">O-211</ref><ref patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011132.html">http://www.securitytracker.com/alerts/2004/Sep/1011132.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11092">11092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17192">winzip-code-execution(17192)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17197">winzip-command-line-bo(17197)</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011132">1011132</ref></refs><vuln_soft><prod name="WinZip" vendor="WinZip"><vers num="9.0"/><vers num="8.1 SR1"/><vers num="8.1"/><vers num="8.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2004-1466" published="2004-12-31" seq="2004-1466" severity="High" type="CVE"><desc><descript source="cve">The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0757.html">20040817 Gallery 1.4.4 save_photos.php PHP Insertion Proof of Concept</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=134&amp;mode=thread&amp;order=0&amp;thold=0">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=134&amp;mode=thread&amp;order=0&amp;thold=0</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-05.xml">GLSA-200409-05</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10968">10968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17021">gallery-savephotos-file-upload(17021)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1467" published="2004-12-31" seq="2004-1467" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/372603">20040822 Multiple Cross Site Scripting Vulnerabilities in eGroupWare</ref><ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=401807">http://sourceforge.net/forum/forum.php?forum_id=401807</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-06.xml">GLSA-200409-06</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11013">11013</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17078">egroupware-mult-modules-xss(17078)</ref></refs><vuln_soft><prod name="eGroupWare" vendor="eGroupWare"><vers num="1.0.3"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1468" published="2004-12-31" seq="2004-1468" severity="High" type="CVE"><desc><descript source="cve">The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/77_e.html">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/77_e.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-15.xml">GLSA-200409-15</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11122">1122</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12488/">12488</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17293">usermin-web-mail-command-execution(17293)</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="1.080"/><vers num="1.070"/><vers num="1.060"/><vers num="1.051"/><vers num="1.040"/><vers num="1.030"/><vers num="1.020"/><vers num="1.010"/><vers num="1.000"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.1.50"/><vers num="1.1.40"/><vers num="1.1.30"/><vers num="1.1.21"/><vers num="1.1.10"/><vers num="1.1.00"/><vers num="1.0.90"/><vers num="1.0.80"/><vers num="1.0.70"/><vers num="1.0.60"/><vers num="1.0.50"/><vers num="1.0.20"/><vers num="1.0.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1469" published="2004-12-31" seq="2004-1469" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517782910407&amp;w=2">20040914 SUS 2.0.2 local root vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-09-01">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-09-01</ref><ref source="CONFIRM" url="http://pdg.uow.edu.au/sus/CHANGES">http://pdg.uow.edu.au/sus/CHANGES</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-17.xml">GLSA-200409-17</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11176">11176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17361">sus-log-format-string(17361)</ref></refs><vuln_soft><prod name="SUS" vendor="Peter D. Gray"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1470" published="2004-12-31" seq="2004-1470" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.snipsnap.org/space/start">http://www.snipsnap.org/space/start</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml">GLSA-200409-23</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11180">11180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17364">snipsnap-response-splitting(17364)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109518773223511&amp;w=2">20040914 ADVISORY: http response splitting in snipsnap</ref></refs><vuln_soft><prod name="SnipSnap" vendor="SnipSnap"><vers num="0.5.2a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2004-1471" published="2004-12-31" seq="2004-1471" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.</descript></desc><impacts><impact source="nvd">Failed exploit attempts will likely cause a denial of service condition.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref><ref adv="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:14.cvs.asc">FreeBSD-SA-04:14</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10499">10499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16365">cvs-wrapper-format-string(16365)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0 Releng"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2"/><vers num="2.1.7.1"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/><vers num="4.10 pre"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="2.0"/><vers num="1.3"/><vers num="Current"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.5"/><vers num="3.4"/><vers num="current"/></prod><prod name="CVS" vendor="CVS"><vers num="1.12.8"/><vers num="1.12.7"/><vers num="1.12.5"/><vers num="1.12.2"/><vers num="1.12.1"/><vers num="1.11.16"/><vers num="1.11.15"/><vers num="1.11.14"/><vers num="1.11.11"/><vers num="1.11.10"/><vers num="1.11.6"/><vers num="1.11.5"/><vers num="1.11.4"/><vers num="1.11.3"/><vers num="1.11.2"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10.8"/><vers num="1.10.7"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1472" published="2004-12-31" seq="2004-1472" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/441078">VU#441078</ref><ref source="BID" url="http://www.securityfocus.com/bid/11237">11237</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17469">symantec-firewallvpn-udp-dos(17469)</ref><ref source="OSVDB" url="http://www.osvdb.org/10204">10204</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12635">12635</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref></refs><vuln_soft><prod name="Nexland Pro400 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security" vendor="Symantec"><vers num="360R"/><vers num="360"/><vers num="320"/></prod><prod name="Nexland Pro800 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro100 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland ISB SOHO Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland WaveBase Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="200R"/><vers num="200"/><vers num="100"/></prod><prod name="Nexland Pro800turbo Firewall Appliance" vendor="Symantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1473" published="2004-12-31" seq="2004-1473" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref><ref adv="1" patch="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/329230">VU#329230</ref><ref source="BID" url="http://www.securityfocus.com/bid/11237">11237</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17470">symantec-udp-obtain-info(17470)</ref><ref source="OSVDB" url="http://www.osvdb.org/10205">10205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12635">12635</ref></refs><vuln_soft><prod name="Nexland WaveBase Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 320" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro800turbo Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="200R"/><vers num="200"/><vers num="100"/></prod><prod name="Nexland Pro400 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland ISB SOHO Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 360R" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro100 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro800 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 360" vendor="Symantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1474" published="2004-12-31" seq="2004-1474" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall&apos;s configuration file.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref><ref adv="1" patch="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/173910">VU#173910</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11237">11237</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17470">symantec-udp-obtain-info(17470)</ref><ref source="OSVDB" url="http://www.osvdb.org/10206">10206</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12635">12635</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17471">symantec-default-snmp(17471)</ref></refs><vuln_soft><prod name="Nexland WaveBase Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 320" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro800turbo Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="200R"/><vers num="200"/><vers num="100"/></prod><prod name="Nexland Pro400 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland ISB SOHO Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 360R" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro100 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Nexland Pro800 Firewall Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Gateway Security 360" vendor="Symantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1475" published="2004-12-31" seq="2004-1475" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/375485/2004-09-02/2004-09-08/0">20040907 XSA-2004-4: multiple string overflows</ref><ref source="CONFIRM" url="http://xinehq.de/index.php/security/XSA-2004-4">http://xinehq.de/index.php/security/XSA-2004-4</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-18.xml">GLSA-200408-18</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml">GLSA-200409-30</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11206">11206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17430">xine-videocd-mrl-bo(17430)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17432">xine-subtitle-bo(17432)</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="0.99"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3"/><vers num="1 rc2"/></prod><prod name="xine" vendor="xine"><vers num="0.9.18"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3"/><vers num="1 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1476" published="2004-12-31" seq="2004-1476" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/375485/2004-09-02/2004-09-08/0">20040907 XSA-2004-4: multiple string overflows</ref><ref adv="1" patch="1" source="CONFIRM" url="http://xinehq.de/index.php/security/XSA-2004-4">http://xinehq.de/index.php/security/XSA-2004-4</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml">GLSA-200409-30</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11206">11206</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="Personal 9.2"/><vers num="Personal 9.1"/><vers edition="x86_64" num="Personal 9.0"/><vers num="Personal 9.0"/><vers num="Personal 8.2"/><vers num="8.1"/><vers num="8.0"/></prod><prod name="xine-lib" vendor="xine"><vers num="0.99"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3"/><vers num="1 rc2"/></prod><prod name="xine" vendor="xine"><vers num="0.9.18"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3"/><vers num="1 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1477" published="2004-12-31" seq="2004-1477" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user&apos;s session.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/668206">VU#668206</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11245">11245</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12638/">12638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17483">jrun-management-console-xss(17483)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2">20040923 New Macromedia Security Zone Bulletins Posted</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-1478" published="2004-12-31" seq="2004-1478" severity="High" type="CVE"><desc><descript source="cve">JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user&apos;s HTTP session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2">20040923 New Macromedia Security Zone Bulletins Posted</ref><ref patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/584958">VU#584958</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11245">11245</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12638/">12638</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17481">jrun-jsessionid-hijack(17481)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="6.1"/><vers num="6.0"/></prod><prod name="Cosminexus Server" vendor="Hitachi"><vers num="Web 01-01_2"/><vers num="Web 01-01_1"/></prod><prod name="Cosminexus Enterprise" vendor="Hitachi"><vers edition="Standard" num="01_02_2"/><vers edition="Standard" num="01_01_1"/><vers edition="Enterprise" num="01_02_2"/><vers edition="Enterprise" num="01_01_1"/></prod><prod name="ColdFusion MX J2EE" vendor="Macromedia"><vers num="6.1"/></prod><prod name="JRun" vendor="Macromedia"><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry modified="2005-10-28" name="CVE-2004-1479" published="2004-12-31" reject="1" seq="2004-1479" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0928.  Reason: This candidate is a duplicate of CVE-2004-0928.  Notes: All CVE users should reference CVE-2004-0928 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1480" published="2004-12-31" seq="2004-1480" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBST01071">SSRT4794 </ref><ref patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011407.html">http://www.securitytracker.com/alerts/2004/Sep/1011407.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11249">11249</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17490">hp-storageworks-restriction-bypass(17490)</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011407">1011407</ref></refs><vuln_soft><prod name="StorageWorks Command View XP" vendor="HP"><vers num="1.60.00"/><vers num="1.53.05a"/><vers num="1.53.01a"/><vers num="1.53.00"/><vers num="1.52.00"/><vers num="1.51.00"/><vers num="1.40.04"/><vers num="1.40.01"/><vers num="1.30.00"/><vers num="1.11.1"/><vers num="1.11.02"/><vers num="1.11"/><vers num="1.8 B"/><vers num="1.8 A"/><vers num="1.8"/><vers num="1.7 B"/><vers num="1.7 A"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-1481" published="2004-12-31" seq="2004-1481" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.service.real.com/help/faq/security/040928_player/EN/">http://www.service.real.com/help/faq/security/040928_player/EN/</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11309">11309</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12672">12672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17549">realplayer-rm-code-execution(17549)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109708374115061&amp;w=2">20041001 EEYE: RealPlayer pnen3260.dll Heap Overflow</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Enterprise" num="Any"/><vers num="8.0"/><vers edition="Mac OS" num="10.0 beta"/><vers edition="Linux" num="10.0"/><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/><vers num="10.0"/><vers edition="Win32" num="8.0"/><vers edition="Unix" num="8.0"/><vers edition="Mac OS" num="8.0"/></prod><prod name="Helix Player" vendor="RealNetworks"><vers edition="Linux" num="1.0"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers edition="Mac OS X" num="9.0.0.297"/><vers edition="Mac OS X" num="9.0.0.288"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1482" published="2004-12-31" seq="2004-1482" severity="High" type="CVE"><desc><descript source="cve">The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-13.xml">GLSA-200410-13</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11355">11355</ref><ref source="OSVDB" url="http://www.osvdb.org/10596">10596</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12770/">12770</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17672">bnc-backspace-command-execution(17672)</ref></refs><vuln_soft><prod name="BNC" vendor="BNC"><vers num="2.8.8"/><vers num="2.6.2"/><vers num="2.6"/><vers num="2.4.8"/><vers num="2.4.6"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1483" published="2004-12-31" seq="2004-1483" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="CONFIRM" url="ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/sym_clientless_vpn_5/updates/hf3-readme.txt">ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/sym_clientless_vpn_5/updates/hf3-readme.txt</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/760256">VU#760256</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12254/">12254</ref><ref source="BID" url="http://www.securityfocus.com/bid/10903">10903</ref><ref source="OSVDB" url="http://www.osvdb.org/8508">8508</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16933">symantec-clientless-file-browsers(16933)</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1484" published="2004-12-31" seq="2004-1484" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-07.txt">http://www.nosystem.com.ar/advisories/advisory-07.txt</ref><ref adv="1" source="CONFIRM" url="http://www.dest-unreach.org/socat/advisory/socat-adv-1.html">http://www.dest-unreach.org/socat/advisory/socat-adv-1.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-26.xml">GLSA-200410-26</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12936/">12936</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11505">11505</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17822">socat-format-string(17822)</ref></refs><vuln_soft><prod name="socat" vendor="socat"><vers num="1.4.0.2"/><vers num="1.4.0.1"/><vers num="1.4.0.0"/><vers num="1.3.2.2"/><vers num="1.3.2.1"/><vers num="1.3.2.0"/><vers num="1.3.1.0"/><vers num="1.3.0.1"/><vers num="1.3.0.0"/><vers num="1.2.0.0"/><vers num="1.1.0.1"/><vers num="1.1.0.0"/><vers num="1.0.4.2"/><vers num="1.0.4.1"/><vers num="1.0.4.0"/><vers num="1.0.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1485" published="2004-12-31" seq="2004-1485" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11527">11527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17878">inetutils-tftp-dns-bo(17878)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882085912915&amp;w=2">20041026 inetutils tftp client, DNS resolving bofs</ref></refs><vuln_soft><prod name="InetUtils" vendor="GNU"><vers num="1.4.2"/></prod><prod name="tftp" vendor="tftp"><vers num="0.38"/><vers num="0.36"/><vers num="0.34"/><vers num="0.32"/><vers num="0.29"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1486" published="2004-12-31" seq="2004-1486" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109893515704267&amp;w=2">SSRT3526</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11507">11507</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12946">12946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17867">hp-cluster-serviceguard-gain-privileges(17867)</ref></refs><vuln_soft><prod name="Cluster Object Manager" vendor="HP"><vers num="B.03.00.01"/><vers num="B.03.00.00"/><vers num="B.02.02.02"/><vers num="B.02.02.00"/><vers num="B.02.01.02"/><vers num="B.01.04"/><vers num="A.01.03"/></prod><prod name="Serviceguard" vendor="HP"><vers num="A.11.16.00"/><vers num="A.11.15.00"/><vers num="A.11.14"/><vers num="A.11.13"/></prod><prod name="Serviceguard for Linux" vendor="HP"><vers num="A.11.15.04"/><vers num="A.11.14.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1487" published="2005-04-27" seq="2004-1487" severity="Medium" type="CVE"><desc><descript source="cve">wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a &quot;..&quot; that resolves to the IP address of the malicious server, which bypasses wget&apos;s filtering for &quot;..&quot; sequences.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Debian.org" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755">wget: Server responses &amp;c written to the tty verbatim (escape sequences, control characters, ...)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11871">bid 11871</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18420">wget to create modify and overwrite files</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110269474112384&amp;w=2">20041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012472">1012472</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1">USN-145-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-771.html">RHSA-2005:771</ref></refs><vuln_soft><prod name="wget" vendor="GNU"><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1488" published="2005-04-27" seq="2004-1488" severity="Medium" type="CVE"><desc><descript source="cve">wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Debian.org" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755">wget: Server responses &amp;c written to the tty verbatim (escape sequences, control characters, ...)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/11871">bid 11871</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18421">wget allows terminal parts to be overwritten</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110269474112384&amp;w=2">20041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012472">1012472</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1">USN-145-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-771.html">RHSA-2005:771</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_16_sr.html">SUSE-SR:2006:016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20960">
20960</ref></refs><vuln_soft><prod name="wget" vendor="GNU"><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1489" published="2004-12-31" seq="2004-1489" severity="Low" type="CVE"><desc><descript source="cve">Opera 7.54 and earlier does not properly limit an applet&apos;s access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html">20041119 Java Vulnerabilities in Opera 7.54</ref><ref source="CONFIRM" url="http://www.opera.com/linux/changelogs/754u1/">http://www.opera.com/linux/changelogs/754u1/</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/><vers num="7.53"/><vers num="7.52"/><vers num="7.51"/><vers num="7.50B1"/><vers num="7.50"/><vers num="7.23"/><vers num="7.22"/><vers num="7.21"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.10"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="Linux" num="6.10"/><vers edition="win32" num="6.0.6"/><vers num="6.0.6"/><vers edition="win32" num="6.0.5"/><vers edition="win32" num="6.0.4"/><vers edition="win32" num="6.0.3"/><vers edition="Linux" num="6.0.3"/><vers edition="win32" num="6.0.2"/><vers edition="Linux" num="6.0.2"/><vers edition="win32" num="6.0.1"/><vers edition="Linux" num="6.0.1"/><vers num="6.0.1"/><vers edition="win32" num="6.0"/><vers num="6.0"/><vers edition="win32" num="5.12"/><vers num="5.12"/><vers edition="win32" num="5.1.1"/><vers edition="win32" num="5.1.0"/><vers edition="Mac" num="5.0"/><vers edition="Linux" num="5.0"/><vers edition="win32" num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1490" published="2004-12-31" seq="2004-1490" severity="Low" type="CVE"><desc><descript source="cve">Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-19/advisory/">http://secunia.com/secunia_research/2004-19/advisory/</ref><ref source="CONFIRM" url="http://www.opera.com/linux/changelogs/754u1/">http://www.opera.com/linux/changelogs/754u1/</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11883">11883</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12981">12981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18423">opera-file-type-spoofing(18423)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/><vers num="7.53"/><vers num="7.52"/><vers num="7.51"/><vers num="7.50B1"/><vers num="7.50"/><vers num="7.23"/><vers num="7.22"/><vers num="7.21"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.10"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="Linux" num="6.10"/><vers edition="win32" num="6.0.6"/><vers num="6.0.6"/><vers edition="win32" num="6.0.5"/><vers edition="win32" num="6.0.4"/><vers edition="win32" num="6.0.3"/><vers edition="Linux" num="6.0.3"/><vers edition="win32" num="6.0.2"/><vers edition="Linux" num="6.0.2"/><vers edition="win32" num="6.0.1"/><vers edition="Linux" num="6.0.1"/><vers num="6.0.1"/><vers edition="win32" num="6.0"/><vers num="6.0"/><vers edition="win32" num="5.12"/><vers num="5.12"/><vers edition="win32" num="5.1.1"/><vers edition="win32" num="5.1.0"/><vers edition="Mac" num="5.0"/><vers edition="Linux" num="5.0"/><vers edition="win32" num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1491" published="2004-12-31" seq="2004-1491" severity="Medium" type="CVE"><desc><descript source="cve">Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.opera.com/linux/changelogs/754u2/">http://www.opera.com/linux/changelogs/754u2/</ref><ref adv="1" source="MISC" url="http://www.zone-h.org/advisories/read/id=6503">http://www.zone-h.org/advisories/read/id=6503</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref><ref adv="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2005-Mar/0007.html">SUSE-SR:2005:008</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11901">11901</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13447/">13447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18457">pera-kfmclient-command-execution(18457)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="Personal 9.2"/><vers num="Personal 9.2"/><vers edition="x86_64" num="Personal 9.1"/><vers num="Personal 9.1"/><vers edition="x86_64" num="Personal 9.0"/><vers num="Personal 9.0"/><vers num="Personal 8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1492" published="2004-12-31" seq="2004-1492" severity="Medium" type="CVE"><desc><descript source="cve">Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11550">11550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13008">13008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17908">master-of-orion-size-dos(17908)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889705116038&amp;w=2">20041027 Crashs in Master of Orion III 1.2.5</ref></refs><vuln_soft><prod name="Master of Orion III" vendor="Quicksilver"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1493" published="2004-12-31" seq="2004-1493" severity="Medium" type="CVE"><desc><descript source="cve">Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889705116038&amp;w=2">20041027 Crashs in Master of Orion III 1.2.5</ref><ref adv="1" source="MISC" url="http://packetstormsecurity.nl/0410-advisories/masterOrionIII.txt">http://packetstormsecurity.nl/0410-advisories/masterOrionIII.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11550">11550</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13008">13008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17884">master-of-orion-nickname-dos(17884)</ref></refs><vuln_soft><prod name="Master of Orion III" vendor="Quicksilver"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1494" published="2004-12-31" seq="2004-1494" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109933696831725&amp;w=2">20041101 XDICT Buffer OverRun Vulnerability,funny :-)</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028241.html">20041101 XDICT Buffer OverRun Vulnerability,funny :-)</ref><ref adv="1" source="MISC" url="http://secway.org/Advisory/Ad20041026EN.txt">http://secway.org/Advisory/Ad20041026EN.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17929">xdict-screen-fetch-bo(17929)</ref></refs><vuln_soft><prod name="XDICT" vendor="Kingsoft"><vers num="2002"/><vers num="2003"/><vers num="2004"/><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1495" published="2004-12-31" seq="2004-1495" severity="Low" type="CVE"><desc><descript source="cve">The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109941351432699&amp;w=2">20041102 Medium Risk Vulnerability in WinRAR</ref><ref source="CONFIRM" url="http://www.rarlabs.com/rarnew.htm">http://www.rarlabs.com/rarnew.htm</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11581">11581</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13070">13070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17937">winrar-repair-archive(17937)</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.40"/><vers num="3.20"/><vers num="3.11"/><vers num="3.10 beta5"/><vers num="3.10 beta3"/><vers num="3.10"/><vers num="3.0.0"/><vers num="2.90"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1496" published="2004-12-31" seq="2004-1496" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) &quot;..\&quot; (dot dot backslash), (2) &quot;../&quot; (dot dot slash), (3) &quot;/%2E%2E%5C&quot; (encoded dot dot backslash), or (4) &quot;%2E%2E%2F&quot; (encoded dot dot slash).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943267328552&amp;w=2">20041102 Multiple Vulnerabilities in Web Forums Server</ref></refs><vuln_soft><prod name="Web Forums Server" vendor="MiniHttpServer.net"><vers num="1.6"/><vers num="2.0 Power Pack"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1497" published="2004-12-31" seq="2004-1497" severity="Medium" type="CVE"><desc><descript source="cve">Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943267328552&amp;w=2">20041102 Multiple Vulnerabilities in Web Forums Server</ref></refs><vuln_soft><prod name="Web Forums Server" vendor="MiniHttpServer.net"><vers num="1.6"/><vers num="2.0 Power Pack"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1498" published="2004-12-31" seq="2004-1498" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943858026542&amp;w=2">20041102 [Hat-Squad] SQL injection and XSS Vulnerabilities in HELM</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000077.html">http://www.hat-squad.com/en/000077.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11586">11586</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13079">13079</ref></refs><vuln_soft><prod name="Helm Control Panel" vendor="WebHost Automation"><vers num="3.1.19"/><vers num="3.1.18"/><vers num="3.1.17"/><vers num="3.1.16"/><vers num="3.1.15"/><vers num="3.1.14"/><vers num="3.1.13"/><vers num="3.1.12"/><vers num="3.1.11"/><vers num="3.1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1499" published="2004-12-31" seq="2004-1499" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943858026542&amp;w=2">20041102 [Hat-Squad] SQL injection and XSS Vulnerabilities in HELM</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000077.html">http://www.hat-squad.com/en/000077.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11586">11586</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13079">13079</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17943">helm-subject-xss(17943)</ref></refs><vuln_soft><prod name="Helm Control Panel" vendor="WebHost Automation"><vers num="3.1.19"/><vers num="3.1.18"/><vers num="3.1.17"/><vers num="3.1.16"/><vers num="3.1.15"/><vers num="3.1.14"/><vers num="3.1.13"/><vers num="3.1.12"/><vers num="3.1.11"/><vers num="3.1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-1500" published="2004-12-31" seq="2004-1500" severity="Low" type="CVE"><desc><descript source="cve">Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109969394601331&amp;w=2">20041105 In-game format string bug in the Lithtech engine</ref><ref source="BID" url="http://www.securityfocus.com/bid/11610">11610</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13116/">13116</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17972">lithtech-format-string(17972)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17317">17317</ref><ref source="" url="http://aluigi.altervista.org/adv/lithfs-adv.txt"></ref></refs><vuln_soft><prod name="Contract Jack" vendor="Monolith Productions"><vers num="1.1"/></prod><prod name="Shogo" vendor="Monolith Productions"><vers num="2.2"/></prod><prod name="Blood" vendor="Monolith Productions"><vers num="2.2.1"/></prod><prod name="Tron" vendor="Monolith Productions"><vers num="2.0.1.42"/></prod><prod name="Global Operations" vendor="Monolith Productions"><vers num="2.1"/><vers num="2.0"/></prod><prod name="Kiss Psycho Circus" vendor="Monolith Productions"><vers num="1.13"/></prod><prod name="Alien versus Predator" vendor="Monolith Productions"><vers num="2.1.0.9.6"/></prod><prod name="Legends of Might and Magic" vendor="Monolith Productions"><vers num="1.1"/></prod><prod name="Sanity" vendor="Monolith Productions"><vers num="1.0"/></prod><prod name="Purge Jihad" vendor="Freeform Interactive"><vers num="2.2.1"/></prod><prod name="No One Lives Forever" vendor="Monolith Productions"><vers num="2.1.3"/><vers num="1.0.004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1501" published="2004-12-31" seq="2004-1501" severity="Medium" type="CVE"><desc><descript source="cve">The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109976745017459&amp;w=2">20041106 Resources consumption in 602 Lan Suite 2004.0.04.0909</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17977">602pro-mail-post-dos(17977)</ref></refs><vuln_soft><prod name="602LAN Suite" vendor="Software602"><vers num="2004.0.04.0909" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1502" published="2004-12-31" seq="2004-1502" severity="Medium" type="CVE"><desc><descript source="cve">The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy&apos;s network interface, which causes a loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109976745017459&amp;w=2">20041106 Resources consumption in 602 Lan Suite 2004.0.04.0909</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17979">602pro-telnet-loopback-dos(17979)</ref></refs><vuln_soft><prod name="602LAN Suite" vendor="Software602"><vers num="2004.0.04.0909" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1503" published="2004-12-31" seq="2004-1503" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109994063331773&amp;w=2">20041108 DOS against Java JNDI/DNS</ref><ref source="BID" url="http://www.securityfocus.com/bid/11619">11619</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13142">13142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17990">sun-jre-dns-dos(17990)</ref></refs><vuln_soft><prod name="J2RE" vendor="Sun"><vers num="1.5.0"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1504" published="2004-12-31" seq="2004-1504" severity="Medium" type="CVE"><desc><descript source="cve">The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110004150430309&amp;w=2">20041109 Vulnerabilities in JAF CMS</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv08-y3dips-2004.txt">http://echo.or.id/adv/adv08-y3dips-2004.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18006">jaf-cms-path-disclosure(18006)</ref></refs><vuln_soft><prod name="JAF CMS" vendor="Salims Softhouse"><vers edition="RC" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1505" published="2004-12-31" seq="2004-1505" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110004150430309&amp;w=2">20041109 Vulnerabilities in JAF CMS</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv08-y3dips-2004.txt">http://echo.or.id/adv/adv08-y3dips-2004.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11627">11627</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13104">13104</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17983">jaf-cms-file-inlcude(17983)</ref></refs><vuln_soft><prod name="JAF CMS" vendor="Salims Softhouse"><vers edition="RC" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1506" published="2004-12-31" seq="2004-1506" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2">20041109 Multiple Vulnerabilities in WebCalendar</ref><ref source="BID" url="http://www.securityfocus.com/bid/11651">11651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13164">13164</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18026">webcalendar-img-src-xss(18026)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1507" published="2004-12-31" seq="2004-1507" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2">20041109 Multiple Vulnerabilities in WebCalendar</ref><ref source="BID" url="http://www.securityfocus.com/bid/11651">11651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13164">13164</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18027">webcalendar-response-splitting(18027)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1508" published="2004-12-31" seq="2004-1508" severity="High" type="CVE"><desc><descript source="cve">init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2">20041109 Multiple Vulnerabilities in WebCalendar</ref><ref source="BID" url="http://www.securityfocus.com/bid/11651">11651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13164">13164</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18028">webcalendar-init-file-include(18028)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1509" published="2004-12-31" seq="2004-1509" severity="Medium" type="CVE"><desc><descript source="cve">validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2">20041109 Multiple Vulnerabilities in WebCalendar</ref><ref source="BID" url="http://www.securityfocus.com/bid/11651">11651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13164">13164</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18029">webcalendar-encodedlogin-path-disclosure(18029)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1510" published="2004-12-31" seq="2004-1510" severity="High" type="CVE"><desc><descript source="cve">WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2">20041109 Multiple Vulnerabilities in WebCalendar</ref><ref source="BID" url="http://www.securityfocus.com/bid/11651">11651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13164">13164</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18030">webcalendar-scripts-gain-access(18030)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1511" published="2004-12-31" seq="2004-1511" severity="Medium" type="CVE"><desc><descript source="cve">Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certian link sent in a chat window.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110014517703092&amp;w=2">20041110 Hotfoon Ver 4.0 Highv Risk</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13173">13173</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18038">hotfoon-url-command-execution(18038)</ref></refs><vuln_soft><prod name="Hotfoon" vendor="Hotfoon Corporation"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1512" published="2004-12-31" seq="2004-1512" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2">20041110 04WebServer Three Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2">20041115 Re: 04WebServer Three Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.security.org.sg/vuln/04webserver142.html">http://www.security.org.sg/vuln/04webserver142.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11652">11652</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13159/">13159</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18033">04webserver-error-xss(18033)</ref><ref source="" url="http://www.soft3304.net/04WebServer/Security.html"></ref></refs><vuln_soft><prod name="04WebServer" vendor="Soft3304"><vers num="1.42"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1513" published="2004-12-31" seq="2004-1513" severity="Medium" type="CVE"><desc><descript source="cve">04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2">20041110 04WebServer Three Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2">20041115 Re: 04WebServer Three Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/04webserver142.html">http://www.security.org.sg/vuln/04webserver142.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11652">11652</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13159/">13159</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18034">04webserver-web-log-spoofing(18034)</ref><ref source="" url="http://www.soft3304.net/04WebServer/Security.html"></ref></refs><vuln_soft><prod name="04WebServer" vendor="Soft3304"><vers num="1.42"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1514" published="2004-12-31" seq="2004-1514" severity="Medium" type="CVE"><desc><descript source="cve">04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2">20041110 04WebServer Three Vulnerabilities</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2">20041115 Re: 04WebServer Three Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/04webserver142.html">http://www.security.org.sg/vuln/04webserver142.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11652">11652</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13159/">13159</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18036">04webserver-dos-devices-dos(18036)</ref><ref source="" url="http://www.soft3304.net/04WebServer/Security.html"></ref></refs><vuln_soft><prod name="04WebServer" vendor="Soft3304"><vers num="1.42"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1515" published="2004-12-31" seq="2004-1515" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110019198507100&amp;w=2">20041111 SQL injection in vBulletin forums (last10.php)</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0 RC4"/><vers num="3.0.0 can4"/><vers num="3.0.0 Beta 2"/><vers num="3.0.0"/><vers num="3.0 beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1516" published="2004-12-31" seq="2004-1516" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110022027420583&amp;w=2">20041111 security hole (http response splitting) in phpwebsite</ref><ref patch="1" source="CONFIRM" url="http://phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_id=863&amp;ANN_user_op=view">http://phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_id=863&amp;ANN_user_op=view</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200411-35.xml">GLSA-200411-35</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11673">11673</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13172/">13172</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18046">phpwebsite-response-splitting(18046)</ref></refs><vuln_soft><prod name="phpWebsite" vendor="phpWebsite"><vers num="0.9.3.4"/><vers num="0.9.3.3"/><vers num="0.9.3.2"/><vers num="0.9.3.1"/><vers num="0.9.3"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1517" published="2004-12-31" seq="2004-1517" severity="High" type="CVE"><desc><descript source="cve">Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extenstions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110020607924001&amp;w=2">20041111 Zone Labs IMsecure Active Link Filter Bypass</ref><ref adv="1" patch="1" source="CONFIRM" url="http://download.zonelabs.com/bin/free/securityAlert/16.html">http://download.zonelabs.com/bin/free/securityAlert/16.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11662">11662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13169">13169</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18042">imsecure-active-link-bypass(18042)</ref></refs><vuln_soft><prod name="IMsecure" vendor="Zone Labs"><vers num="1.0.2.0"/><vers num="1.0.1.0"/><vers num="1.0.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1518" published="2004-12-31" seq="2004-1518" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110021385926870&amp;w=2">20041111 [waraxe-2004-SA#037 - Sql injection bug in Phorum 5.0.12 and older versions]</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028609.html">20041111 [waraxe-2004-SA#037 - Sql injection bug in Phorum 5.0.12 and older versions]</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11660">11660</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13174">13174</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18045">phorum-followphp-sql-injection(18045)</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.9"/><vers num="5.0.7 BETA"/><vers num="5.0.3 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1519" published="2004-12-31" seq="2004-1519" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18053">phpbugtracker-bug-sql-injection(18053)</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=11718">11718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18079">phpbugtracker-project-sql-injection(18079)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037345428403&amp;w=2">20041112 SQL Injection in phpBT (bug.php - Add)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110029315521568&amp;w=2">20041112 SQL Injection in phpBT (bug.php)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037408101974&amp;w=2">20041112 SQL Injection in phpBT (bug.php) add project</ref></refs><vuln_soft><prod name="phpBugTracker" vendor="Benjamin Curtis"><vers num="0.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1520" published="2004-12-31" seq="2004-1520" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037283803560&amp;w=2">20041112 IPSwitch-IMail-8.13 Stack Overflow in the DELETE Command</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11675">11675</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13200">13200</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18058">ipswitch-delete-bo(18058)</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="8.13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1521" published="2004-12-31" seq="2004-1521" severity="Medium" type="CVE"><desc><descript source="cve">Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed &quot;Converted&quot; headers.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037078519691&amp;w=2">20041113 Eudora 6.2 attachment spoof</ref><ref adv="1" source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110053102601655&amp;w=2">20041113 Eudora 6.2 attachment spoof</ref><ref adv="1" source="MISC" url="http://packetstormsecurity.nl/0411-exploits/eudora62014.txt">http://packetstormsecurity.nl/0411-exploits/eudora62014.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18064">eudora-base64-attach-spoof-variant(18064)</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="6.2.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1522" published="2004-12-31" seq="2004-1522" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110053709800174&amp;w=2">20041114 Format string bug in Army Men RTS</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028757.html">20041114 Format string bug in Army Men RTS</ref><ref source="BID" url="http://www.securityfocus.com/bid/11679">11679</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13186">13186</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18065">army-men-rts-format-string(18065)</ref></refs><vuln_soft><prod name="Army Men Real Time Strategy Game" vendor="3DO"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1523" published="2004-12-31" seq="2004-1523" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11683">11683</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13207">13207</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18083">hired-team-format-string(18083)</ref></refs><vuln_soft><prod name="Hired Team: Trial" vendor="New Media Generation"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1524" published="2004-12-31" seq="2004-1524" severity="Medium" type="CVE"><desc><descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11683">11683</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13207">13207</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18085">hired-team-udp-dos(18085)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref></refs><vuln_soft><prod name="Hired Team: Trial" vendor="New Media Generation"><vers num="2.2"/><vers num="2.1"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1525" published="2004-12-31" seq="2004-1525" severity="Medium" type="CVE"><desc><descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11683">11683</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13207">13207</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18086">hired-team-status-dos(18086)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref></refs><vuln_soft><prod name="Hired Team: Trial" vendor="New Media Generation"><vers num="2.2"/><vers num="2.1"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1526" published="2004-12-31" seq="2004-1526" severity="High" type="CVE"><desc><descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/13207">13207</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref></refs><vuln_soft><prod name="Hired Team: Trial" vendor="New Media Generation"><vers num="2.2"/><vers num="2.1"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1527" published="2004-12-31" seq="2004-1527" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker&apos;s domain name is within the target&apos;s domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html">http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/11680">11680</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13208">13208</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18073">ie-path-cookie-overwrite(18073)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110053968530613&amp;w=2">20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1528" published="2004-12-31" seq="2004-1528" severity="Medium" type="CVE"><desc><descript source="cve">The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11693">11693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13213">13213</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18105">event-calendar-path-disclosure(18105)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref><ref source="" url="http://www.waraxe.us/index.php?modname=sa&amp;id=38"></ref></refs><vuln_soft><prod name="PHP-Nuke Event Calendar" vendor="Rob Sutton"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1529" published="2004-12-31" seq="2004-1529" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11693">11693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13213">13213</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18107">event-calendar-comment-xss(18107)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18106">event-calendar-xss(18106)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref><ref source="" url="http://www.waraxe.us/index.php?modname=sa&amp;id=38"></ref></refs><vuln_soft><prod name="PHP-Nuke Event Calendar" vendor="Rob Sutton"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1530" published="2004-12-31" seq="2004-1530" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11693">11693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13213">13213</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18104">event-calendar-sql-injection(18104)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref><ref source="" url="http://www.waraxe.us/index.php?modname=sa&amp;id=38"></ref></refs><vuln_soft><prod name="PHP-Nuke Event Calendar" vendor="Rob Sutton"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1531" published="2004-12-31" seq="2004-1531" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://forums.invisionpower.com/index.php?showtopic=154916">http://forums.invisionpower.com/index.php?showtopic=154916</ref><ref source="BID" url="http://www.securityfocus.com/bid/11703">11703</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13245">13245</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18164">invisionpowerboard-sql-injection(18164)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110079592702417&amp;w=2">20041118 [MaxPatrol] SQL-injection in Invision Power Board 2.x</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454805209191&amp;w=2">20050425 SQL-injections in Invision Power Board v2.0.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111462421824202&amp;w=2">20050427 Re: SQL-injections in Invision Power Board v2.0.1</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1532" published="2004-12-31" seq="2004-1532" severity="High" type="CVE"><desc><descript source="cve">AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11704">11704</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18163">appserv-default-account(18163)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110079586328430&amp;w=2">20041118 AppServ 2.5.x and Prior Exploit</ref></refs><vuln_soft><prod name="AppServ" vendor="AppServ Open Project"><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1533" published="2004-12-31" seq="2004-1533" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.digitalmapping.sk.ca/pop3srv/Update.asp">http://www.digitalmapping.sk.ca/pop3srv/Update.asp</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11705">11705</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13248">13248</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18161">dms-pop3-username-bo(18161)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110081437508585&amp;w=2">20041118 Buffer overlow in DMS POP3 Server for Windows 2000/XP 1.5.3 build</ref></refs><vuln_soft><prod name="POP3 Server" vendor="Digital Mappings Systems"><vers num="1.5.3 build37"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1534" published="2004-12-31" seq="2004-1534" severity="Medium" type="CVE"><desc><descript source="cve">ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://download.zonelabs.com/bin/free/securityAlert/18.html">http://download.zonelabs.com/bin/free/securityAlert/18.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11706">11706</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13244/">13244</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18159">zonealarm-adblock-dos(18159)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110088808402495&amp;w=2">20041118 Zone Labs Ad-Blocking Instability</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="5.5"/></prod><prod name="ZoneAlarm Pro" vendor="Zone Labs"><vers num="5.0.590.015"/><vers num="4.5.538.001"/><vers num="4.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1535" published="2004-12-31" seq="2004-1535" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18151">phpbb-admincashphp-file-include(18151)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110075903308817&amp;w=2">20041118 Vulnerabilities in forum phpBB2 with Cash_Mod (all ver.)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082153702843&amp;w=2">20041118 Re: Vulnerabilities in forum phpBB2 with Cash_Mod (all ver.)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="RC4"/><vers num="RC3"/><vers num="RC2"/><vers num="RC1"/><vers num="RC1 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1536" published="2004-12-31" seq="2004-1536" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11719">11719</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012292">1012292</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13260">13260</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18180">ibproarcade-category-sql-injection(18180)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110098512318132&amp;w=2">20041120 IpbProArace 2.5.x SQL injection.</ref></refs><vuln_soft><prod name="ipbProArcade" vendor="ipbProArcade"><vers num="2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1537" published="2004-12-31" seq="2004-1537" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11725">11725</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13262">13262</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18204">phpkit-popup-xss(18204)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110117116115493&amp;w=2">20041122 PHPKIT SQL Injection, XSS</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers num="1.6.03"/><vers num="1.6.02"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1538" published="2004-12-31" seq="2004-1538" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11725">11725</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13262">13262</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18205">phpkit-include-sql-injection(18205)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110117116115493&amp;w=2">20041122 PHPKIT SQL Injection, XSS</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers num="1.6.03"/><vers num="1.6.02"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1539" published="2004-12-31" seq="2004-1539" severity="Medium" type="CVE"><desc><descript source="cve">Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11724">11724</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13273">13273</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18196">halo-long-reply-dos(18196)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110114770406920&amp;w=2">20041122 Broadcast client crash in Halo 1.05</ref></refs><vuln_soft><prod name="Halo Combat Evolved" vendor="Gearbox Software"><vers num="1.31"/><vers num="1.5"/><vers num="1.4"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1540" published="2004-12-31" seq="2004-1540" severity="Medium" type="CVE"><desc><descript source="cve">ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11723">11723</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012298">1012298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13278">13278</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18202">zyxel-configuration-reset(18202)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110116413414615&amp;w=2">20041121 Router ZyXEL Prestige 650 HW http remote admin.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110135136811344&amp;w=2">20041124 Re: Router ZyXEL Prestige 650 HW http remote admin.</ref><ref source="OSVDB" url="http://www.osvdb.org/12108">12108</ref></refs><vuln_soft><prod name="Prestige" vendor="ZyXEL"><vers num="650R"/><vers num="650HW_31"/><vers num="650HW"/><vers num="650H"/><vers num="645R A1"/></prod><prod name="ZyNOS" vendor="ZyXEL"><vers num="3.40"/><vers num="IS.5"/><vers num="IS.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1541" published="2004-12-31" seq="2004-1541" severity="High" type="CVE"><desc><descript source="cve">SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11731">11731</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13275/">13275</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18201">securecrt-folder-command-execution(18201)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110129164332226&amp;w=2">20041123 SecureCRT - Remote Command Execution</ref></refs><vuln_soft><prod name="SecureCRT" vendor="Van Dyke Technologies"><vers num="4.1.8"/><vers num="4.1.7"/><vers num="4.1.6"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1542" published="2004-12-31" seq="2004-1542" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11735">11735</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13289">13289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18211">soldier-fortune-bo(18211)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110124208811327&amp;w=2">20041123 Broadcast memory corruption in Soldier of Fortune II 1.03</ref></refs><vuln_soft><prod name="Soldier Of Fortune" vendor="Raven Software"><vers num="2.1.0.3"/><vers num="2.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1543" published="2004-12-31" seq="2004-1543" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029342.html">20041124 STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/11744">11744</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13286">13286</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18234">korweblog-viewimg-directory-traversal(18234)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132543805873&amp;w=2">20041124 STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability</ref></refs><vuln_soft><prod name="KorWeblog" vendor="KorWeblog"><vers num="1.6.2cvs"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1544" published="2004-12-31" seq="2004-1544" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11746">11746</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13285/">13285</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18236">jspwiki-query-xss(18236)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110135663220831&amp;w=2">20041124 STG Security Advisory: [SSA-20041122-11] JSPWiki XSS vulnerability</ref></refs><vuln_soft><prod name="JSPWiki" vendor="JSPWiki"><vers num="2.1.122"/><vers num="2.1.121"/><vers num="2.1.120"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1545" published="2004-12-31" seq="2004-1545" severity="Medium" type="CVE"><desc><descript source="cve">UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0448.html">20041215 STG Security Advisory: [SSA-20041215-15] Vulnerability of uploading files with multiple extensions in MoniWiki</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11951">11951</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13478">13478</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18493">moniwiki-file-upload(18493)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314544711884&amp;w=2">20041215 STG Security Advisory: [SSA-20041215-15] Vulnerability of uploading files with multiple extensions in MoniWiki</ref><ref source="" url="http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniwiki&amp;only_with_tag=HEAD&amp;r1=text&amp;tr1=1.17&amp;r2=text&amp;tr2=1.16&amp;f=h"></ref></refs><vuln_soft><prod name="MoniWiki" vendor="MoniWiki"><vers num="1.0.9.1"/><vers num="1.0.9"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1546" published="2004-12-31" seq="2004-1546" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://xforce.iss.net/xforce/xfdb/17477">20040922 Remote buffer overflow in MDaemon IMAP and SMTP server</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026770.html">20040922 Remote buffer overflow in MDaemon IMAP and SMTP server</ref><ref source="BID" url="http://www.securityfocus.com/bid/11238">11238</ref><ref source="MISC" url="http://www.securitylab.ru/48146.html">http://www.securitylab.ru/48146.html</ref><ref source="OSVDB" url="http://www.osvdb.org/10223">10223</ref><ref source="OSVDB" url="http://www.osvdb.org/10224">10224</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17476">mdaemon-imap-list-bo(17476)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109591179510781&amp;w=2">20040922 Remote buffer overflow in MDaemon IMAP and SMTP server</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-1547" published="2004-12-31" seq="2004-1547" severity="Medium" type="CVE"><desc><descript source="cve">The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11244">11244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12642/">12642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17482">activepost-long-filename-dos(17482)</ref><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/actp-adv.txt">http://aluigi.altervista.org/adv/actp-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011406">1011406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/5/">12642</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref></refs><vuln_soft><prod name="ActivePost Standard" vendor="ONNURI INFOTEK"><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-1548" published="2004-12-31" seq="2004-1548" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11244">11244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12642/">12642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17488">activepost-dotdot-directory-traversal(17488)</ref><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/actp-adv.txt">http://aluigi.altervista.org/adv/actp-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011406">1011406</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref></refs><vuln_soft><prod name="ActivePost Standard" vendor="ONNURI INFOTEK"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-1549" published="2004-12-31" seq="2004-1549" severity="Medium" type="CVE"><desc><descript source="cve">The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11244">11244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12642/">12642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17486">activepost-plaintext-password(17486)</ref><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/actp-adv.txt">http://aluigi.altervista.org/adv/actp-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011406">1011406</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref></refs><vuln_soft><prod name="ActivePost Standard" vendor="ONNURI INFOTEK"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1550" published="2004-12-31" seq="2004-1550" severity="High" type="CVE"><desc><descript source="cve">Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613135105800&amp;w=2">20040924 Motorola Wireless Router WR850G Authentication Circumvention</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026791.html">20040923 Motorola Wireless Router WR850G Authentication Circumvention</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11241">11241</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17474">motorola-wr850g-gain-access(17474)</ref></refs><vuln_soft><prod name="WR850G" vendor="Motorola"><vers num="4.0.3 firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1551" published="2004-12-31" seq="2004-1551" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613031414184&amp;w=2">20040925 New XSS vulnerabilities in paFileDB 3.1 final</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17504">pafiledb-pafiledb-xss(17504)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1552" published="2004-12-31" seq="2004-1552" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109604910025090&amp;w=2">20040923 aspWebCalendar /aspWebAlbum: SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/11246">11246</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12651">12651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17506">aspwebcalendar-sql-injection(17506)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3546">
3546</ref><ref source="BID" url="http://www.securityfocus.com/bid/23098">
23098</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1093">
ADV-2007-1093</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24622">
24622</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33157">
aspwebcalendar-calendar-sql-injection(33157)</ref></refs><vuln_soft><prod name="aspWebCalendar" vendor="Full Revolution"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1553" published="2004-12-31" seq="2004-1553" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109604910025090&amp;w=2">20040923 aspWebCalendar /aspWebAlbum: SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/11246">11246</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17507">aspwebalbum-sql-injection(17507)</ref></refs><vuln_soft><prod name="aspWebAlbum" vendor="Full Revolution"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1554" published="2004-12-31" seq="2004-1554" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109635806703748&amp;w=2">20040926 @lex Guestbook (PHP) Include file</ref><ref adv="1" source="MISC" url="http://packetstormsecurity.nl/0410-exploits/alexPHP.txt">http://packetstormsecurity.nl/0410-exploits/alexPHP.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11260">11260</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17516">@lex-guestbook-file-include(17516)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011432">1011432</ref></refs><vuln_soft><prod name="alex guestbook" vendor="alexPHPTeam"><vers num="3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1555" published="2004-12-31" seq="2004-1555" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630777608244&amp;w=2">20040926 SQL injection in BroadBoard Instant ASP Message Board</ref><ref source="BID" url="http://www.securityfocus.com/bid/11250">11250</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12658">12658</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17502">broadboard-forgotasp-sql-injection(17502)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17500">broadboard-profileasp-sql-injection(17500)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17501">broadboard-reg2asp-sql-injection(17501)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17498">broadboard-searchasp-sql-injection(17498)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011419">1011419</ref></refs><vuln_soft><prod name="ASP Message Board" vendor="BroadBoard Instant"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1556" published="2004-12-31" seq="2004-1556" severity="Medium" type="CVE"><desc><descript source="cve">MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630333230707&amp;w=2">20040927 MyWebServer 1.0.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/11254">11254</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12689">12689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17519">mywebserver-mult-connections-dos(17519)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011461">1011461</ref></refs><vuln_soft><prod name="MyWebServer" vendor="MyWebServer"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1557" published="2004-12-31" seq="2004-1557" severity="Medium" type="CVE"><desc><descript source="cve">MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630333230707&amp;w=2">20040927 MyWebServer 1.0.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/11254">11254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17520">mywebserver-admin-access(17520)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011461">1011461</ref></refs><vuln_soft><prod name="MyWebServer" vendor="MyWebServer"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-30" name="CVE-2004-1558" published="2004-12-31" seq="2004-1558" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630699829536&amp;w=2">20040927 [Hat-Squad] Remote Buffer overflow Vulnerability in YahooPOPS</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000075.html">http://www.hat-squad.com/en/000075.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11256">11256</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17515">ypops-pop3-bo(17515)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17518">ypops-smtp-bo(17518)</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Sep/1011426.html">1011426</ref><ref source="" url="http://dbeusee.home.comcast.net/history.html"></ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-October/001089.html">[VIM] 20061020 vendor ACK for old YPOPs! issue</ref><ref source="OSVDB" url="http://www.osvdb.org/10366">10366</ref><ref source="OSVDB" url="http://www.osvdb.org/10367">10367</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12660">12660</ref></refs><vuln_soft><prod name="YPOPs" vendor="YPOPs"><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.4.3"/><vers num="0.4.4"/><vers num="0.4.5"/><vers num="0.4.6"/><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1559" published="2004-12-31" seq="2004-1559" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109641484723194&amp;w=2">20040927 Multiple XSS Vulnerabilities in Wordpress 1.2</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11268">11268</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12683">12683</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17532">wordpress-multiple-scripts-xss(17532)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011440">1011440</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1560" published="2004-12-31" seq="2004-1560" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109650760210411&amp;w=2">20040928 MSSQL 7.0 DoS</ref><ref source="MISC" url="http://packetstormsecurity.nl/0410-exploits/mssql.7.0.dos.c">http://packetstormsecurity.nl/0410-exploits/mssql.7.0.dos.c</ref><ref source="BID" url="http://www.securityfocus.com/bid/11265">11265</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011434">1011434</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12680">12680</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17542">mssql-data-buffer-dos(17542)</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1561" published="2004-12-31" seq="2004-1561" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/iceexec-adv.txt"></ref><ref adv="1" source="SecuriTeam.com" url="http://www.securiteam.com/exploits/6X00315BFM.html">ICECast Remote Code Execution</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11271">11271</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12666/">12666</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17538">icecast-http-bo(17538)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674593230539&amp;w=2">20041002 Re:2. Code execution in Icecast 2.0.1(exploit with shellcode)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109640005127644&amp;w=2">20040928 Code execution in Icecast 2.0.1</ref><ref source="OSVDB" url="http://www.osvdb.org/10446">
10446</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011439">
1011439</ref></refs><vuln_soft><prod name="Icecast" vendor="Icecast"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1562" published="2004-12-31" seq="2004-1562" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2">20040930 Multiple vulnerabilities in w-agora forum</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html">20040930 Multiple vulnerabilities in w-agora forum</ref><ref source="BID" url="http://www.securityfocus.com/bid/11283">11283</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12695">12695</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17557">wagora-redirurl-sql-injection(17557)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011463">1011463</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.1.6a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1563" published="2004-12-31" seq="2004-1563" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2">20040930 Multiple vulnerabilities in w-agora forum</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html">20040930 Multiple vulnerabilities in w-agora forum</ref><ref source="BID" url="http://www.securityfocus.com/bid/11283">11283</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12695">12695</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17553">wagora-get-post-xss(17553)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011463">1011463</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.1.6a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1564" published="2004-12-31" seq="2004-1564" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2">20040930 Multiple vulnerabilities in w-agora forum</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html">20040930 Multiple vulnerabilities in w-agora forum</ref><ref source="BID" url="http://www.securityfocus.com/bid/11283">11283</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12695">12695</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17558">wagora-response-splitting(17558)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011463">1011463</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.1.6a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1565" published="2004-12-31" seq="2004-1565" severity="Medium" type="CVE"><desc><descript source="cve">list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2">20040930 Multiple vulnerabilities in w-agora forum</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html">20040930 Multiple vulnerabilities in w-agora forum</ref><ref source="BID" url="http://www.securityfocus.com/bid/11283">11283</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12695">12695</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011463">1011463</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.1.6a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1566" published="2004-12-31" seq="2004-1566" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655763808924&amp;w=2">20040930 Multiple Vulnerabilities in Silent Storm Portal</ref><ref source="BID" url="http://www.securityfocus.com/bid/11284">11284</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12704">12704</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17554">silent-storm-xss(17554)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011470">1011470</ref></refs><vuln_soft><prod name="Silent-Storm Portal" vendor="Silent-Storm"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1567" published="2004-12-31" seq="2004-1567" severity="High" type="CVE"><desc><descript source="cve">profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655763808924&amp;w=2">20040930 Multiple Vulnerabilities in Silent Storm Portal</ref><ref source="BID" url="http://www.securityfocus.com/bid/11284">11284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12704">12704</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17555">silent-storm-gain-admin(17555)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011470">1011470</ref></refs><vuln_soft><prod name="Silent-Storm Portal" vendor="Silent-Storm"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1568" published="2004-12-31" seq="2004-1568" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109647769526696&amp;w=2">20040929 directory traversal in ParaChat Server 5.5</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109656982803391&amp;w=2">20040930 Re: directory traversal in ParaChat Server 5.5</ref><ref source="BID" url="http://www.securityfocus.com/bid/11272">11272</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12678/">12678</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17541">parachat-directory-traversal(17541)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/1047.html">20040928 directory traversal in ParaChat Server 5.5</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/1063.html">20040929 Re: directory traversal in ParaChat Server 5.5</ref><ref source="OSVDB" url="http://www.osvdb.org/10436">10436</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011438">1011438</ref></refs><vuln_soft><prod name="ParaChat Server" vendor="ParaChat"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1569" published="2004-12-31" seq="2004-1569" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109668542406346&amp;w=2">20040930 dbPowerAmp Buffer Overflow And Dos Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00052-09272004">http://www.gulftech.org/?node=research&amp;article_id=00052-09272004</ref><ref source="BID" url="http://www.securityfocus.com/bid/11266">11266</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12684/">12684</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17535">dbpoweramp-player-filename-bo(17535)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17539">dbpoweramp-converter-filename-bo(17539)</ref></refs><vuln_soft><prod name="dBpowerAMP Music Converter" vendor="Illustrate"><vers num="10.0"/></prod><prod name="dBpowerAMP Audio Player" vendor="Illustrate"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1570" published="2004-12-31" seq="2004-1570" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109665351632048&amp;w=2">20041001 SQL Injection vulnerability in bBlog 0.7.3</ref><ref source="MISC" url="http://www.servers.co.nz/security/SCN200409-1.php">http://www.servers.co.nz/security/SCN200409-1.php</ref><ref source="BID" url="http://www.securityfocus.com/bid/11303">11303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12691">12691</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17552">bblog-array-sql-injection(17552)</ref></refs><vuln_soft><prod name="bBlog" vendor="Eaden McKee"><vers num="0.7.3"/><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-1571" published="2004-12-31" seq="2004-1571" severity="Medium" type="CVE"><desc><descript source="cve">AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2">20041001 Multiple Vulnerabilities in AJ-Fork</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv07-y3dips-2004.txt">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17568">aj-fork-path-disclosure(17568)</ref></refs><vuln_soft><prod name="AJ-Fork" vendor="AJ-Fork"><vers num="167"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-1572" published="2004-12-31" seq="2004-1572" severity="Medium" type="CVE"><desc><descript source="cve">AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2">20041001 Multiple Vulnerabilities in AJ-Fork</ref><ref source="MISC" url="http://echo.or.id/adv/adv07-y3dips-2004.txt">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11301">11301</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17569">af-fork-directory-disclosure(17569)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011484">1011484</ref></refs><vuln_soft><prod name="AJ-Fork" vendor="AJ-Fork"><vers num="167"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1573" published="2004-12-31" seq="2004-1573" severity="High" type="CVE"><desc><descript source="cve">The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2">20041001 Multiple Vulnerabilities in AJ-Fork</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv07-y3dips-2004.txt">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11301">11301</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17571">aj-fork-usersdbphp-write-access(17571)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011484">1011484</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="0.88"/></prod><prod name="AJ-Fork" vendor="AJ-Fork"><vers num="167"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1574" published="2004-12-31" seq="2004-1574" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/vymesbof-adv.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11310">11310</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12605">12605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17572">vypress-visual-bo(17572)</ref><ref source="OSVDB" url="http://www.osvdb.org/10451">10451</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011489">1011489</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109665993315769&amp;w=2">20041001 Broadcast buffer-overflow in Vypress Messenger 3.5.1</ref></refs><vuln_soft><prod name="Vypres Messenger" vendor="Vypress"><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1575" published="2004-12-31" seq="2004-1575" severity="Medium" type="CVE"><desc><descript source="cve">The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674050017645&amp;w=2">20041002 Security advisory - Xerces-C++ 2.5.0: Attribute blowup</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11312">11312</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12715">12715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17575">xercescplusplus-xml-parser-dos(17575)</ref></refs><vuln_soft><prod name="Xerces-C++" vendor="Apache Software Foundation"><vers num="2.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1576" published="2004-12-31" seq="2004-1576" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674541519610&amp;w=2">20041002 In-game format string in Judge Dredd vs. Death 1.01</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12710">12710</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17579">judge-dredd-death-format-string(17579)</ref></refs><vuln_soft><prod name="Judge Dredd: Dredd vs. Death" vendor="Megalo"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1577" published="2004-12-31" seq="2004-1577" severity="Medium" type="CVE"><desc><descript source="cve">index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109693280416747&amp;w=2">20041003 Full path disclosure in PHP Links</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17588">phplinks-path-disclosure(17588)</ref></refs><vuln_soft><prod name="PHPLinks" vendor="Greg Donald"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1578" published="2004-12-31" seq="2004-1578" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109701091207517&amp;w=2">20041005 [MAXPATROL Security Advisories] Cross site scripting in Invision Power Board</ref><ref source="BID" url="http://www.securityfocus.com/bid/11332">11332</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12740">12740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17604">invision-referer-header-xss(17604)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1579" published="2004-12-31" seq="2004-1579" severity="Medium" type="CVE"><desc><descript source="cve">index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109713382400457&amp;w=2">20041006 Full path disclosure and sql injection on CubeCart 2.0.1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17630">cubecart-catid-path-disclosure(17630)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1580" published="2004-12-31" seq="2004-1580" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109713382400457&amp;w=2">20041006 Full path disclosure and sql injection on CubeCart 2.0.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/11337">11337</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12764">12764</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17632">cubecart-catid-sql-injection(17632)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1581" published="2004-12-31" seq="2004-1581" severity="Medium" type="CVE"><desc><descript source="cve">BlackBoard 1.5.1 allows remote attackers to gains sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707701719659&amp;w=2">20041006 Multiple vulnerabilities in BlackBoard</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17636">blackboard-directory-traversal(17636)</ref></refs><vuln_soft><prod name="BlackBoard" vendor="Blackboard"><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1582" published="2004-12-31" seq="2004-1582" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called &quot;libpach&quot;) to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707701719659&amp;w=2">20041006 Multiple vulnerabilities in BlackBoard</ref><ref patch="1" source="CONFIRM" url="http://blackboard.unclassified.de/70,1#1031">http://blackboard.unclassified.de/70,1#1031</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11336">11336</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12757">12757</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17637">blackboard-lang-file-include(17637)</ref></refs><vuln_soft><prod name="BlackBoard Internet Newsboard System" vendor="BlackBoard Internet Newsboard System"><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1583" published="2004-12-31" seq="2004-1583" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109709637732276&amp;w=2">20041006 Directory traversal in Tridcomm 1.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/11343">11343</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12755">12755</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17631">tridcomm-dotdot-directory-traversal(17631)</ref></refs><vuln_soft><prod name="TriDComm" vendor="TriDComm"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1584" published="2004-12-31" seq="2004-1584" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716327724041&amp;w=2">20041006 HTTP Response Splitting Vulnerability in Wordpress 1.2</ref><ref patch="1" source="CONFIRM" url="http://wordpress.org/development/2004/10/wp-121/">http://wordpress.org/development/2004/10/wp-121/</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-12.xml">GLSA-200410-12</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11348">11348</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12773">12773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17649">wordpress-response-splitting(17649)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1585" published="2004-12-31" seq="2004-1585" severity="Medium" type="CVE"><desc><descript source="cve">Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716787607302&amp;w=2">20041007 Server crash in Flash Messaging 5.2.0g</ref><ref source="BID" url="http://www.securityfocus.com/bid/11351">11351</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011569">1011569</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12759/">12759</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17647">flash-messaging-dos(17647)</ref></refs><vuln_soft><prod name="Flash Messaging" vendor="Jera Technology"><vers num="5.2g"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1586" published="2004-12-31" seq="2004-1586" severity="Low" type="CVE"><desc><descript source="cve">Flash Messaging clients can ignore disconnecting commands such as &quot;shutdown&quot; from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716787607302&amp;w=2">20041007 Server crash in Flash Messaging 5.2.0g</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011569">1011569</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12759/">12759</ref></refs><vuln_soft><prod name="Flash Messaging Server" vendor="Jera Technology"><vers num="5.2.0g"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1587" published="2004-12-31" seq="2004-1587" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109728194025487&amp;w=2">20041007 Limited \secure\ buffer-overflow in some old Monolith games</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11354">11354</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12776/">12776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17668">blood2-long-query-bo(17668)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17670">shogo-long-query-bo(17670)</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=10635">10635</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Oct/1011603.html">1011603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17665">avp2-long-query-bo(17665)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17669">nolf-long-query-bo(17669)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109727077824860&amp;w=2">20041008 Limited \secure\ buffer-overflow in some old Monolith games</ref></refs><vuln_soft><prod name="No One Lives Forever" vendor="Monolith Productions"><vers num="1.0.004"/></prod><prod name="Alien versus Predator" vendor="Monolith Productions"><vers num="2.1.0.9.6"/></prod><prod name="Shogo" vendor="Monolith Productions"><vers num="2.2"/></prod><prod name="Blood" vendor="Monolith Productions"><vers num="2 2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1588" published="2004-12-31" seq="2004-1588" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109751522823011&amp;w=2">20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board</ref><ref source="BID" url="http://www.securityfocus.com/bid/11361">11361</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12790/">12790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17678">gosmart-forum-loginexec-sql-injection(17678)</ref></refs><vuln_soft><prod name="GoSmart Message Board" vendor="GoSmart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1589" published="2004-12-31" seq="2004-1589" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109751522823011&amp;w=2">20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board</ref><ref source="BID" url="http://www.securityfocus.com/bid/11361">11361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12790/">12790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17679">gosmart-forum-mainmessageid-xss(17679)</ref></refs><vuln_soft><prod name="GoSmart Message Board" vendor="GoSmart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1590" published="2004-12-31" seq="2004-1590" severity="Medium" type="CVE"><desc><descript source="cve">Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109787365801512&amp;w=2">20041012 Clientexec Billing Software</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12862">12862</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17741">clientexec-phpinfo-info-disclosure(17741)</ref></refs><vuln_soft><prod name="Clientexec" vendor="Clientexec"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1591" published="2004-12-31" seq="2004-1591" severity="High" type="CVE"><desc><descript source="cve">The web interface for Micronet Wireless Broadband Router SP916BM running firmware before 1.9 08/04/2004 resets the password to the default password when the router is shut off, which could allow remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109759963126161&amp;w=2">20041012 Micronet wireless broadband router SP916BM admin password reset when power off</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17697">micronet-router-password-reset(17697)</ref></refs><vuln_soft><prod name="Wireless Broadband Router SP916BM" vendor="Microsoft"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1592" published="2004-12-31" seq="2004-1592" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109763314312828&amp;w=2">20041012 [hackgen-2004-#002] - Remote file inclusion bug in ocPortal 1.0.3.</ref><ref adv="1" source="MISC" url="http://www.hackgen.org/advisories/hackgen-2004-002.txt">http://www.hackgen.org/advisories/hackgen-2004-002.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11368">11368</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12811/">12811</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17699">ocportal-reqpath-file-include(17699)</ref></refs><vuln_soft><prod name="ocPortal" vendor="ocPortal"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1593" published="2004-12-31" seq="2004-1593" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109768337007983&amp;w=2">20041013 XXS in SCT email client</ref><ref source="BID" url="http://www.securityfocus.com/bid/11392">11392</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12826">12826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17704">sct-campus-userlayoutrootnode-xss(17704)</ref></refs><vuln_soft><prod name="Campus Pipeline" vendor="SCT Corporation"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1594" published="2004-10-13" seq="2004-1594" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109768460312168&amp;w=2">20041013 XXS in fusetalk forum</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12823">12823</ref><ref adv="1" source="SECUNIA" url="http://www.securityfocus.com/bid/11393">12823</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17701">fusetalk-imgsrc-xss(17701)</ref></refs><vuln_soft><prod name="FuseTalk" vendor="e-Zone Media Inc."><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1595" published="2004-10-13" seq="2004-1595" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778648232233&amp;w=2">20041013 Buffer-overflow in ShixxNOTE 6.net</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11409">11409</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12822/">12822</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17705">shixxnote-font-bo(17705)</ref></refs><vuln_soft><prod name="ShixxNOTE" vendor="ShixxNOTE"><vers num="6.net"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1596" published="2004-10-13" seq="2004-1596" severity="High" type="CVE"><desc><descript source="cve">The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778914829901&amp;w=2">20041013 3COM Wireless router (3CRADSL72) information disclosure</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/378551">20041015 More details on BID 11408 (3com 3cradsl72 wireless router)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810854031673&amp;w=2">20041015 Re: 3COM Wireless router (3CRADSL72) information disclosure</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11408">11408</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17723">3com-officeconnect-obtain-info(17723)</ref></refs><vuln_soft><prod name="Wireless Router" vendor="3Com"><vers num="3CRADSL72"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-1597" published="2004-10-13" seq="2004-1597" severity="Medium" type="CVE"><desc><descript source="cve">RIM Blackberry 7230 running RIM Blackberry OS 3.7 SP1 allows remote attackers to cause a denial of service (device reboot and possibly data corruption) via a calendar message with a long Location field, which triggers a watchdog while the message is being stored.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109769022430842&amp;w=2">20041013 [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778267829493&amp;w=2">20041014 [HV-MED] UPDATE: RIM Blackberry DoS, data loss</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027487.html">20041012 [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss</ref><ref adv="1" source="MISC" url="http://www.hexview.com/docs/20041012-1.txt">http://www.hexview.com/docs/20041012-1.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Known_%20Issues_-_HexView_advisory_on_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&amp;vernum=0">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Known_%20Issues_-_HexView_advisory_on_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&amp;vernum=0</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11389">11389</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12814">12814</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17700">blackberry-calendar-bo(17700)</ref></refs><vuln_soft><prod name="Blackberry" vendor="RIM"><vers num="7230 3.7.1 .41"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1598" published="2004-10-12" seq="2004-1598" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109771686326956&amp;w=2">20041012 Adobe acrobat / Adobe Reader 6 can read local files</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779541602447&amp;w=2">20041014 Re: Adobe acrobat / Adobe Reader 6 can read local files</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109812210520520&amp;w=2">20041015 Re: Adobe acrobat / Adobe Reader 6 can read local files</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11386">11386</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17694">adobe-acrobat-swf-read-files(17694)</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1599" published="2004-10-16" seq="2004-1599" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2">20041016 Multiple Vulnerabilities in CoolPHP</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11437">11437</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1011748">1011748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12850">12850</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17742">coolphp-multiple-xss(17742)</ref></refs><vuln_soft><prod name="CoolPHPWeb Portal" vendor="CoolPHP"><vers num="1.0 stable"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1600" published="2004-10-16" seq="2004-1600" severity="Medium" type="CVE"><desc><descript source="cve">index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2">20041016 Multiple Vulnerabilities in CoolPHP</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1011748">1011748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12850">12850</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17744">coolphp-path-disclosure(17744)</ref></refs><vuln_soft><prod name="CoolPHP" vendor="CoolPHP"><vers num="1.0 stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1601" published="2004-10-16" seq="2004-1601" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2">20041016 Multiple Vulnerabilities in CoolPHP</ref><ref source="BID" url="http://www.securityfocus.com/bid/11437">11437</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1011748">1011748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12850">12850</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17745">coolphp-dotdot-directory-traversal(17745)</ref></refs><vuln_soft><prod name="CoolPHP Web Portal" vendor="CoolPHP"><vers num="1.0 stable"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1602" published="2004-10-15" seq="2004-1602" severity="Medium" type="CVE"><desc><descript source="cve">ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786760926133&amp;w=2">20041015 ProFTPD 1.2.x remote users enumeration bug</ref><ref adv="1" patch="1" source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-10-02">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-10-02</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11430">11430</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011687">1011687</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17724">proftpd-info-disclosure(17724)</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2.9 rc3"/><vers num="1.2.9 rc2"/><vers num="1.2.9 rc1"/><vers num="1.2.9"/><vers num="1.2.8 rc2"/><vers num="1.2.8 rc1"/><vers num="1.2.8"/><vers num="1.2.7 rc3"/><vers num="1.2.7 rc2"/><vers num="1.2.7 rc1"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5 rc1"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2 rc3"/><vers num="1.2.2 rc1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2 pre9"/><vers num="1.2 pre8"/><vers num="1.2 pre7"/><vers num="1.2 pre6"/><vers num="1.2 pre5"/><vers num="1.2 pre4"/><vers num="1.2 pre3"/><vers num="1.2 pre2"/><vers num="1.2 pre11"/><vers num="1.2 pre10"/><vers num="1.2 pre1"/><vers num="1.2.0 rc3"/><vers num="1.2.0 rc2"/><vers num="1.2.0 rc1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1603" published="2004-10-18" seq="2004-1603" severity="Medium" type="CVE"><desc><descript source="cve">cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811572123753&amp;w=2">20041018 cPanel hardlink backup issue</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811654104208&amp;w=2">20041018 cPanel hardlink chown issue</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11449">11449</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11455">11455</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12865">12865</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17779">cpanel-backup-view-file(17779)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17780">cpanel-htaccess-modify-ownership(17780)</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="9.4.1 R64"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1604" published="2004-09-30" seq="2004-1604" severity="Medium" type="CVE"><desc><descript source="cve">cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811762230326&amp;w=2">20041018 cPanel symlink chmod issue</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="9.9.1 R3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1605" published="2004-10-14" seq="2004-1605" severity="High" type="CVE"><desc><descript source="cve">SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17749">saleslogix-cookie-admin-access(17749)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10942">10942</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1606" published="2004-10-18" seq="2004-1606" severity="Medium" type="CVE"><desc><descript source="cve">slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17750">saleslogix-info-disclosure(17750)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10943">10943</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1607" published="2004-10-18" seq="2004-1607" severity="Medium" type="CVE"><desc><descript source="cve">slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17751">saleslogix-filename-path-disclosure(17751)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10944">10944</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1608" published="2004-10-18" seq="2004-1608" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17752">saleslogix-sql-injection(17752)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10945">10945</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1609" published="2004-10-18" seq="2004-1609" severity="Medium" type="CVE"><desc><descript source="cve">SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17753">saleslogix-obtain-passwords(17753)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10946">10946</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1610" published="2004-10-18" seq="2004-1610" severity="High" type="CVE"><desc><descript source="cve">SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1611" published="2004-10-18" seq="2004-1611" severity="Medium" type="CVE"><desc><descript source="cve">SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17754">saleslogix-getconnection-account-disclosure(17754)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10947">10947</ref><ref source="OSVDB" url="http://www.osvdb.org/10948">10948</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="Best Software"><vers num=""/></prod><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1612" published="2004-10-18" seq="2004-1612" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11450">11450</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12883">12883</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17765">saleslogix-processqueuefile-file-upload(17765)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html">20041018 Multiple vulnerabilities in Sage Saleslogix</ref><ref source="OSVDB" url="http://www.osvdb.org/10949">10949</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011769">1011769</ref></refs><vuln_soft><prod name="SalesLogix" vendor="SalesLogix Corporation"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1613" published="2004-10-18" seq="2004-1613" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html">20041018 Web browsers - a mini-farce</ref><ref source="MISC" url="http://lcamtuf.coredump.cx/mangleme/gallery/">http://lcamtuf.coredump.cx/mangleme/gallery/</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11439">11439</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1011810">1011810</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17805">mozilla-html-tags-dos(17805)</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.8 Alpha2"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Linux Advanced Workstation" vendor="Red Hat"><vers edition="Itanium" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 2.0"/><vers num="Core 1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1614" published="2004-10-18" seq="2004-1614" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an &quot;unusual combination of visual elements,&quot; including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="MISC" url="http://lcamtuf.coredump.cx/mangleme/gallery/">http://lcamtuf.coredump.cx/mangleme/gallery/</ref><ref adv="1" source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1011810.html">http://securitytracker.com/alerts/2004/Oct/1011810.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11440">11440</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011810">1011810</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.8 Alpha2"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1615" published="2004-10-18" seq="2004-1615" severity="Low" type="CVE"><desc><descript source="cve">Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.</descript></desc><sols><sol source="nvd">This was fixed in version 7.60.</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="MISC" url="http://lcamtuf.coredump.cx/mangleme/gallery/">http://lcamtuf.coredump.cx/mangleme/gallery/</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11441">11441</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17806">opera-colspan-tbody-dos(17806)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/><vers num="7.53"/><vers num="7.52"/><vers num="7.51"/><vers num="7.50"/><vers num="7.23"/><vers num="7.22"/><vers num="7.21"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.10"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers edition="Linux" num="6.10"/><vers edition="win32" num="6.0.5"/><vers edition="win32" num="6.0.4"/><vers edition="win32" num="6.0.3"/><vers edition="Linux" num="6.0.3"/><vers edition="win32" num="6.0.2"/><vers edition="Linux" num="6.0.2"/><vers edition="win32" num="6.0.1"/><vers edition="Linux" num="6.0.1"/><vers num="6.0.1"/><vers edition="win32" num="6.0"/><vers num="6.0.6"/><vers edition="win32" num="6.0.6"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1616" published="2004-10-18" seq="2004-1616" severity="Medium" type="CVE"><desc><descript source="cve">Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="MISC" url="http://lcamtuf.coredump.cx/mangleme/gallery/">http://lcamtuf.coredump.cx/mangleme/gallery/</ref><ref adv="1" source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1011808.html">http://securitytracker.com/alerts/2004/Oct/1011808.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11442">11442</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17803">links-large-table-dos(17803)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011808">1011808</ref></refs><vuln_soft><prod name="Links" vendor="Links"><vers num="0.99"/><vers num="0.98"/><vers num="0.97"/><vers num="0.96"/><vers num="0.95"/><vers num="0.94"/><vers num="0.93"/><vers num="0.92"/><vers num="0.91"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1617" published="2004-10-18" seq="2004-1617" severity="Medium" type="CVE"><desc><descript source="cve">Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not terminated, as demonstrated by mangleme.  NOTE: a followup suggests that the relevant trigger for this issue is the large COLS value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html">20041018 Web browsers - a mini-farce</ref><ref adv="1" source="MISC" url="http://lcamtuf.coredump.cx/mangleme/gallery/">http://lcamtuf.coredump.cx/mangleme/gallery/</ref><ref adv="1" source="MISC" url="http://securitytracker.com/alerts/2004/Oct/1011809.html">http://securitytracker.com/alerts/2004/Oct/1011809.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11443">11443</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17804">lynx-dos(17804)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011809">1011809</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1077">DSA-1077</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1076">DSA-1076</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1085">DSA-1085</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20383">20383</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435689/30/4740/threaded">20060602 Re: [SECURITY] [DSA 1085-1] New lynx-cur packages fix several vulnerabilities</ref></refs><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num="2.8.5 dev8"/><vers num="2.8.5 dev5"/><vers num="2.8.5 dev4"/><vers num="2.8.5 dev3"/><vers num="2.8.5 dev2"/><vers num="2.8.5"/><vers num="2.8.4 rel1"/><vers num="2.8.4"/><vers num="2.8.3 rel1"/><vers num="2.8.3 pre5"/><vers num="2.8.3 dev22"/><vers num="2.8.3"/><vers num="2.8.2 rel1"/><vers num="2.8.1"/><vers num="2.8"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1618" published="2004-10-19" seq="2004-1618" severity="Medium" type="CVE"><desc><descript source="cve">Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/toneboom-adv.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11462">11462</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12890">12890</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17775">vypress-tonecast-dos(17775)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109820344806472&amp;w=2">20041019 Broadcast crash in Vypress Tonecast 1.3</ref></refs><vuln_soft><prod name="Tonecast" vendor="Vypress"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1619" published="2004-10-20" seq="2004-1619" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Privateer&apos;s Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829017407842&amp;w=2">20041020 Buffer-overflow in Age of Sail II 1.04.151</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11479">11479</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12905">12905</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17791">age-of-sail-bo(17791)</ref></refs><vuln_soft><prod name="Privateer&apos;s Bounty Age of Sail II" vendor="Akella"><vers num="1.56"/><vers num="1.55"/><vers num="1.4.51"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1620" published="2004-10-21" seq="2004-1620" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109841283115808&amp;w=2">20041021 HTTP Response Splitting in Serendipity 0.7-beta4</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.s9y.org/5.html">http://www.s9y.org/5.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11497">11497</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12909/">12909</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17798">serendipity-response-splitting(17798)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=276694"></ref><ref source="OSVDB" url="http://www.osvdb.org/11013">11013</ref><ref source="OSVDB" url="http://www.osvdb.org/11038">11038</ref><ref source="OSVDB" url="http://www.osvdb.org/11039">11039</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011864">1011864</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/comment.php?rev=1.49&amp;view=markup"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/exit.php?rev=1.10&amp;view=markup"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/index.php?rev=1.52&amp;view=markup"></ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7 Beta4"/><vers num="0.7 Beta2"/><vers num="0.7 beta3"/><vers num="0.7 beta1"/><vers num="0.6 rc2"/><vers num="0.6 rc1"/><vers num="0.6 pl3"/><vers num="0.6 pl2"/><vers num="0.6 pl1"/><vers num="0.6"/><vers num="0.5 pl1"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1621" published="2004-10-18" seq="2004-1621" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields.  NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109812960023736&amp;w=2">20041018 IBM Lotus Notes/Domino fails to encode Square Brackets ( [  ] )</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109841682529328&amp;w=2">20041021 Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [  ] )</ref><ref adv="1" source="MISC" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21187833">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21187833</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1011779">http://securitytracker.com/id?1011779</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11458">11458</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12891">12891</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17758">lotus-notes-xss(17758)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/><vers num="6.0.3"/><vers num="6.0.2 CF2"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1622" published="2004-10-21" seq="2004-1622" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109839925207038&amp;w=2">20041021 SQL Injection in UBB.threads 3.4.x</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11502">11502</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17821">ubbthreads-sql-injection(17821)</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="3.5"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1623" published="2004-10-22" seq="2004-1623" severity="Medium" type="CVE"><desc><descript source="cve">The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109846319313443&amp;w=2">20041021 [HV-LOW] Unsafe WAV header handling can cause DoS on Windows</ref><ref adv="1" source="MISC" url="http://www.hexview.com/docs/20041021-1.txt">http://www.hexview.com/docs/20041021-1.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11503">11503</ref><ref source="OSVDB" url="http://www.osvdb.org/11053">11053</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011880">1011880</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17864">windowsxp-explorer-wav-dos(17864)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1624" published="2004-10-21" seq="2004-1624" severity="High" type="CVE"><desc><descript source="cve">Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109846296406459&amp;w=2">20041022 [Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11500">11500</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12962">12962</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17838">carboncopy-help-gain-privileges(17838)</ref></refs><vuln_soft><prod name="Carbon Copy Consumer Client" vendor="Altiris"><vers num="6.0"/><vers num="5.0"/></prod><prod name="Carbon Copy Consumer Console" vendor="Altiris"><vers num="6.0"/><vers num="5.0"/></prod><prod name="Carbon Copy Solution Agent" vendor="Altiris"><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1625" published="2004-10-22" seq="2004-1625" severity="Medium" type="CVE"><desc><descript source="cve">pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109849689808245&amp;w=2">20041022 Windows DoS in certain pGina configurations</ref><ref source="MISC" url="http://www.lovebug.org/pgina_dos.txt">http://www.lovebug.org/pgina_dos.txt</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17836">pgina-dos(17836)</ref></refs><vuln_soft><prod name="pGina" vendor="pGina"><vers num="1.7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1626" published="2004-10-22" seq="2004-1626" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109850947508816&amp;w=2">20041022 Ability FTP Server 2.34 Buffer Overflow Exploit</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/857846">VU#857846</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11508">11508</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/11030">11030</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12941">12941</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17823">abilityftpserver-stor-dos(17823)</ref></refs><vuln_soft><prod name="Ability Server" vendor="Code-Crafters"><vers num="2.3.4"/><vers num="2.3.2"/><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1627" published="2004-10-22" seq="2004-1627" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://lists.virus.org/dw-0day-0412/msg00004.html">[0day] 20041208 Ability Server 2.25 - 2.34 FTP =&gt; &apos;APPE&apos; Buffer Overflow - PnK:: DCN3T</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11508">11508</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1012464">http://securitytracker.com/id?1012464</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12941">12941</ref><ref source="OSVDB" url="http://www.osvdb.org/12347">12347</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18405">ability-appe-bo(18405)</ref></refs><vuln_soft><prod name="Ability Server" vendor="Code-Crafters"><vers num="2.3.4"/><vers num="2.3.2"/><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1628" published="2004-10-23" seq="2004-1628" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109855982425122&amp;w=2">20041023 rssh: pizzacode security alert</ref><ref patch="1" source="CONFIRM" url="http://www.pizzashack.org/rssh/">http://www.pizzashack.org/rssh/</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-28.xml">GLSA-200410-28</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12954">12954</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17831">rssh-format-string(17831)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1629" published="2004-10-23" seq="2004-1629" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109855895702903&amp;w=2">20041023 dwc_articles possible sql injection</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11509">11509</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17830">dwc-articles-sql-injection(17830)</ref></refs><vuln_soft><prod name="DWC_Articles" vendor="Distinct Web Creations"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1630" published="2004-10-25" seq="2004-1630" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109876304705234&amp;w=2">20041024 Two Vulnerabilities in OpenWFE Web Client</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11514">11514</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12970">12970</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17853">openwfe-login-form-xss(17853)</ref></refs><vuln_soft><prod name="Work Flow Engine" vendor="OpenWFE"><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1631" published="2004-10-25" seq="2004-1631" severity="Medium" type="CVE"><desc><descript source="cve">Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109876304705234&amp;w=2">20041024 Two Vulnerabilities in OpenWFE Web Client</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11514">11514</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12970">12970</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17852">openwfe-rmi-obtain-information(17852)</ref></refs><vuln_soft><prod name="Work Flow Engine" vendor="OpenWFE"><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1632" published="2004-10-25" seq="2004-1632" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109873622006103&amp;w=2">20041025 STG Security Advisory: [SSA-20041022-08] MoniWiki XSS vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11516">11516</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12975">12975</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17835">moniwiki-wiki-xss(17835)</ref></refs><vuln_soft><prod name="MoniWiki" vendor="MoniWiki"><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1633" published="2004-10-25" seq="2004-1633" severity="Medium" type="CVE"><desc><descript source="cve">process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=252638">https://bugzilla.mozilla.org/show_bug.cgi?id=252638</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17840">bugzilla-bug-change(17840)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1634" published="2004-10-25" seq="2004-1634" severity="Medium" type="CVE"><desc><descript source="cve">show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=263780">https://bugzilla.mozilla.org/show_bug.cgi?id=263780</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11511">11511</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17841">bugzilla-xml-information-disclosure(17841)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/><vers num="2.8"/><vers num="2.6"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1635" published="2004-10-24" seq="2004-1635" severity="Medium" type="CVE"><desc><descript source="cve">Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=250605">https://bugzilla.mozilla.org/show_bug.cgi?id=250605</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=253544">https://bugzilla.mozilla.org/show_bug.cgi?id=253544</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11511">11511</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17842">bugzila-metadata-information-disclosure(17842)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/><vers num="2.8"/><vers num="2.6"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1636" published="2004-10-26" seq="2004-1636" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109885074513940&amp;w=2">20041026 wvtfpd remote root heap overflow</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11525">11525</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12986">12986</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17869">wvtfpd-wvtftpservercc-bo(17869)</ref></refs><vuln_soft><prod name="WvTftp" vendor="Net Integration Technologies Inc."><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-15" name="CVE-2004-1637" published="2004-10-26" seq="2004-1637" severity="High" type="CVE"><desc><descript source="cve">The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882884617886&amp;w=2">20041026 Hawking Technologies HAR11A router considered insecure</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11543">11543</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17877">har11a-gain-unauth-access(17877)</ref></refs><vuln_soft><prod name="HAR11A DSL Router" vendor="Hawking Technology"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1638" published="2004-10-16" seq="2004-1638" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880961630050&amp;w=2">20041026 MailCarrier 2.51 SMTP server Buffer Overflow [PoC included]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11535">11535</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12999">12999</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17861">mailcarrier-ehlo-helo-bo(17861)</ref></refs><vuln_soft><prod name="MailCarrier" vendor="Tabs Laboratories"><vers num="2.51"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1639" published="2004-10-26" seq="2004-1639" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109886388528179&amp;w=2">20041026 Rendering large binary file as HTML makes Mozilla Firefox stop responding</ref><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q4/0017.html">20041026 Rendering large binary file as HTML makes Mozilla Firefox stop responding or crash</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17839">mozilla-html-dos(17839)</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="5.0"/></prod><prod name="Gecko" vendor="Mozilla"><vers num="2004-09-13"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1640" published="2004-08-28" seq="2004-1640" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394077209963&amp;w=2">20040828 Cross Site Scripting in XOOPS Version 2.x Dictionary module</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11064">11064</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12424">12424</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17154">xoops-dictionsary-letter-xss(17154)</ref><ref source="" url="http://cyruxnet.org/modulo_dic_xoops.htm"></ref><ref source="OSVDB" url="http://www.osvdb.org/9393">9393</ref><ref source="OSVDB" url="http://www.osvdb.org/9394">9394</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17152">xoops-dictionary-search-xss(17152)</ref></refs><vuln_soft><prod name="XOOPS Dictionary" vendor="XOOPS"><vers num="0.94"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1641" published="2004-08-29" seq="2004-1641" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396159332523&amp;w=2">20040829 [vulnwatch] Titan FTP Server Long Command Heap Overflow Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11069">11069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12419">12419</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17172">titan-long-command-bo(17172)</ref></refs><vuln_soft><prod name="Titan FTP Server" vendor="South River Technologies"><vers num="2.2"/><vers num="2.10"/><vers num="3.01"/><vers num="3.10"/><vers num="3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1642" published="2004-08-29" seq="2004-1642" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396193723317&amp;w=2">20040829 [vulnwatch] WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11067">11067</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12420">12420</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17169">wftpd-mlst-command-dos(17169)</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="3.21 R2"/><vers num="3.21 R3"/><vers num="3.21 R1"/><vers num="3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1643" published="2004-08-29" seq="2004-1643" severity="Medium" type="CVE"><desc><descript source="cve">WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a &quot;../&quot; sequence.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109389890712888&amp;w=2">20040829 [vulnwatch] WS_FTP Server Denial of Service Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11065">11065</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12406">12406</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17155">wsftp-file-parsing-dos(17155)</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1644" published="2004-08-30" seq="2004-1644" severity="Medium" type="CVE"><desc><descript source="cve">Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2">20040830 Multiple Vulnerabilities In Xedus Webserver</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11071">11071</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12418">12418</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17165">xedus-mult-connection-dos(17165)</ref></refs><vuln_soft><prod name="Xedus" vendor="Jerod Moemeka"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1645" published="2004-08-30" seq="2004-1645" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2">20040830 Multiple Vulnerabilities In Xedus Webserver</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11071">11071</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12418">12418</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17166">xedus-test-xss(17166)</ref></refs><vuln_soft><prod name="Xedus" vendor="Jerod Moemeka"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1646" published="2004-08-30" seq="2004-1646" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2">20040830 Multiple Vulnerabilities In Xedus Webserver</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11071">11071</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12418">12418</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17167">xedus-dotdot-directory-traversal(17167)</ref></refs><vuln_soft><prod name="Xedus" vendor="Jerod Moemeka"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1647" published="2004-08-30" seq="2004-1647" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109414967003192&amp;w=2">20040830 Password Protect XSS and SQL-Injection vulnerabilities.</ref><ref source="MISC" url="http://www.criolabs.net/advisories/passprotect.txt">http://www.criolabs.net/advisories/passprotect.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11073">11073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12407">12407</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17188">password-protect-sql-injection(17188)</ref></refs><vuln_soft><prod name="Password Protect" vendor="Web Animations"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1648" published="2004-08-31" seq="2004-1648" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109414967003192&amp;w=2">20040830 Password Protect XSS and SQL-Injection vulnerabilities.</ref><ref adv="1" source="MISC" url="http://www.criolabs.net/advisories/passprotect.txt">http://www.criolabs.net/advisories/passprotect.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11073">11073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12407">12407</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17187">password-protect-showmsg-xss(17187)</ref></refs><vuln_soft><prod name="Password Protect" vendor="Web Animations"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1649" published="2004-08-31" seq="2004-1649" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter.  NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413415205017&amp;w=2">20040831 MSInfo  Buffer Overflow</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025902.html">20040830 MSInfo  Buffer Overflow</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109391133831787&amp;w=2">20040830 MSInfo  Buffer Overflow</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17153">msinfo-msinfofile-bo(17153)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1650" published="2004-08-31" seq="2004-1650" severity="High" type="CVE"><desc><descript source="cve">D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396893820049&amp;w=2">20040831 D-Link DCS-900 IP camera remote exploit that change the IP</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1011100.html">http://www.securitytracker.com/alerts/2004/Aug/1011100.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11072">11072</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12425">12425</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17171">dlink-dcs900-ip-modification(17171)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011100">1011100</ref></refs><vuln_soft><prod name="DCS-900 Internet Camera" vendor="D-Link"><vers num="2.10"/><vers num="2.20"/><vers num="2.28"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1651" published="2004-08-31" seq="2004-1651" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109399590602709&amp;w=2">20040831 Multiple Vulnerabilities in phpScheduleIt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11080">11080</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17193">phpscheduleit-xss(17193)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0216.html">20040917 Re: Multiple Vulnerabilities in phpScheduleIt</ref><ref source="OSVDB" url="http://www.osvdb.org/9451">9451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17194">phpscheduleit-script-injection(17194)</ref></refs><vuln_soft><prod name="phpScheduleIt" vendor="BrickHost"><vers num="1.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1652" published="2004-08-31" seq="2004-1652" severity="High" type="CVE"><desc><descript source="cve">phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109399590602709&amp;w=2">20040831 Multiple Vulnerabilities in phpScheduleIt</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17195">phpscheduleit-gain-privileges(17195)</ref></refs><vuln_soft><prod name="phpScheduleIt" vendor="BrickHost"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-1653" published="2004-08-31" seq="2004-1653" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413637313484&amp;w=2">20040831 SSHD / AnonCVS Nastyness</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011143.html">http://www.securitytracker.com/alerts/2004/Sep/1011143.html</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17213">openssh-port-bounce(17213)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413637313484&amp;w=2">20040831 SSHD / AnonCVS Nastyness</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011143">1011143</ref><ref source="OSVDB" url="http://www.osvdb.org/9562">
9562</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1654" published="2004-09-01" seq="2004-1654" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413493005513&amp;w=2">20040901 Multiple Vulnerabilities In phpWebsite</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00048-08312004">http://www.gulftech.org/?node=research&amp;article_id=00048-08312004</ref><ref patch="1" source="CONFIRM" url="http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822">http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11088">11088</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12438">12438</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17199">phpwebsite-calendar-module-sql-injection(17199)</ref></refs><vuln_soft><prod name="phpWebsite" vendor="phpWebsite"><vers num="0.7.3"/><vers num="0.8.2"/><vers num="0.8.3"/><vers num="0.9.3.4"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1655" published="2004-09-01" seq="2004-1655" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413493005513&amp;w=2">20040901 Multiple Vulnerabilities In phpWebsite</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00048-08312004">http://www.gulftech.org/?node=research&amp;article_id=00048-08312004</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1011120.html">http://www.securitytracker.com/alerts/2004/Aug/1011120.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822">http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11088">11088</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12438">12438</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17202">phpwebsite-comments-module-xss(17202)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011120">1011120</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17203">phpwebsite-notes-script-injection(17203)</ref></refs><vuln_soft><prod name="phpWebsite" vendor="phpWebsite"><vers num="0.7.3"/><vers num="0.8.2"/><vers num="0.8.3"/><vers num="0.9.3.4"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1656" published="2004-09-01" seq="2004-1656" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109405777905519&amp;w=2">20040901 ADVISORY: http response splitting hole in Comersus shopping cart</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11083">11083</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17201">comersus-cart-response-splitting(17201)</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num="5.0.991"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1657" published="2004-09-01" seq="2004-1657" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109443321830050&amp;w=2">20040901 Cross-Site Scripting Vulnerability in Newtelligence DasBlog</ref><ref adv="1" source="CONFIRM" url="http://staff.newtelligence.net/clemensv/PermaLink.aspx?guid=69bce168-cb09-4f09-8d53-f0b97f11b198">http://staff.newtelligence.net/clemensv/PermaLink.aspx?guid=69bce168-cb09-4f09-8d53-f0b97f11b198</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11086">11086</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12416">12416</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17174">dasblog-useragent-referer-xss(17174)</ref></refs><vuln_soft><prod name="DasBlog" vendor="newtelligence"><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1658" published="2004-09-02" seq="2004-1658" severity="Medium" type="CVE"><desc><descript source="cve">Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel&apos;s SDT ServiceTable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109420310631039&amp;w=2">20040902 Kerio Personal Firewall&apos;s Application Launch Protection Can Be Disabled by Direct Service Table Restoration</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/kerio4016.html">http://www.security.org.sg/vuln/kerio4016.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12468/">12468</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11096">11096</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17270">kerio-pf-protection-dos(17270)</ref></refs><vuln_soft><prod name="Personal Firewall" vendor="Kerio"><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1659" published="2004-09-02" seq="2004-1659" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109415338521881&amp;w=2">20040902 [hackgen-2004-#001] - Non-critacal Cross-Site Scripting bug in CuteNews</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11097">11097</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12432">12432</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17214">cutenews-mod-xss(17214)</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="0.88"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1660" published="2004-08-30" seq="2004-1660" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2004/Sep/0014.html">20040830 RE: CuteNews News.txt writable to world</ref><ref adv="1" source="MISC" url="http://www.7a69ezine.org/node/view/130">http://www.7a69ezine.org/node/view/130</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12432">12432</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17288">cutenews-file-include(17288)</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1661" published="2004-09-02" seq="2004-1661" severity="High" type="CVE"><desc><descript source="cve">MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains &quot;auth=1&quot; and &quot;uId=1.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109416709710447&amp;w=2">20040902 MailWorks Professional - Authentication bypass</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11095">11095</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12458">12458</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17217">mailworks-cookie-admin-access(17217)</ref></refs><vuln_soft><prod name="MailWorks Professional" vendor="SiteCubed"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1662" published="2004-08-25" seq="2004-1662" severity="Medium" type="CVE"><desc><descript source="cve">YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109441750900432&amp;w=2">20040904 FUll Path Disclosure in YABBSE</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv05-y3dips-2004.txt">http://echo.or.id/adv/adv05-y3dips-2004.txt</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17267">yabb-admin-path-disclosure(17267)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1663" published="2004-09-04" seq="2004-1663" severity="Medium" type="CVE"><desc><descript source="cve">Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109435831811484&amp;w=2">20040904 Engenio/LSI Logic controllers denial of service/data corruption</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11108">11108</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12464">12464</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17290">engenio-controller-tcp-dos(17290)</ref></refs><vuln_soft><prod name="Fabric OS" vendor="Brocade"><vers num="2.1.2"/><vers num="2.2"/><vers num="3.1"/></prod><prod name="Storage Controller" vendor="Engenio"><vers num="2822"/><vers num="2882"/><vers num="4884"/><vers num="5884"/></prod><prod name="D280" vendor="Storagetek"><vers num=""/></prod><prod name="SilkWorm" vendor="Brocade"><vers num="3200"/><vers num="3250"/><vers num="3800"/><vers num="3850"/><vers num="3900"/></prod><prod name="DS4100" vendor="IBM"><vers num=""/></prod><prod name="SilkWorm Fiber Channel Switch" vendor="Brocade"><vers num="2010"/><vers num="2040"/><vers num="2050"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1664" published="2004-09-05" seq="2004-1664" severity="Medium" type="CVE"><desc><descript source="cve">Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109449953200587&amp;w=2">20040905 Broadcast shutdown in Call of Duty 1.4</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11119">11119</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17286">callofduty-dos(17286)</ref></refs><vuln_soft><prod name="Call of Duty" vendor="Activision"><vers num="1.4"/></prod><prod name="Call of Duty United Offensive" vendor="Activision"><vers num="1.41"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1665" published="2004-09-05" seq="2004-1665" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109458516524494&amp;w=2">20040905 Bug XSS in PsNews 1.1</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011191.html">http://www.securitytracker.com/alerts/2004/Sep/1011191.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11124">11124</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17302">psnews-xss(17302)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011191">1011191</ref></refs><vuln_soft><prod name="PSnews" vendor="PSnews"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1666" published="2004-12-31" seq="2004-1666" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109466618609375&amp;w=2">20040908 Cerulean Studios Trillian 0.74i Buffer Overflow in MSN module exploit</ref><ref adv="1" source="MISC" url="http://unsecure.altervista.org/security/trillian.htm">http://unsecure.altervista.org/security/trillian.htm</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11142">11142</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12487">12487</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17292">trillian-msn-bo(17292)</ref></refs><vuln_soft><prod name="Trillian" vendor="Cerulean Studios"><vers num="0.74i"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1667" published="2004-09-09" seq="2004-1667" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/haloboom-adv.txt"></ref><ref adv="1" patch="1" source="Bungie" url="http://www.bungie.net/News/Story.aspx?link=hpc105"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11147">11147</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12504">12504</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17310">halo-response-offbyone-bo(17310)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109479695022024&amp;w=2">20040909 Off-by-one bug in Halo 1.04</ref></refs><vuln_soft><prod name="Halo Combat Evolved" vendor="Gearbox Software"><vers num="1.2"/><vers num="1.4"/><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1668" published="2004-09-10" seq="2004-1668" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483089621955&amp;w=2">20040910 SQL-Injection in Subjects 2.0 for Postnuke</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11148">11148</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12497">12497</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17311">subjects-indexphp-sql-injection(17311)</ref></refs><vuln_soft><prod name="Factory Subjects Module" vendor="EasyWeb"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1669" published="2004-09-10" seq="2004-1669" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17313">merak-icewarp-xss(17313)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod><prod name="Mail Server" vendor="Merak"><vers num="7.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1670" published="2004-09-10" seq="2004-1670" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17314">merak-icewarp-create-directory(17314)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod><prod name="Mail Server" vendor="Merak"><vers num="7.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1671" published="2004-10-12" seq="2004-1671" severity="Medium" type="CVE"><desc><descript source="cve">Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17315">merak-icewarp-path-disclosure(17315)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1672" published="2004-10-12" seq="2004-1672" severity="High" type="CVE"><desc><descript source="cve">attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users&apos; attachments by specifying the username and message ID in an HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17316">merak-icewarp-view-attachment(17316)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1673" published="2004-10-12" seq="2004-1673" severity="High" type="CVE"><desc><descript source="cve">accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17317">merak-icewarp-create-file(17317)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1674" published="2004-10-12" seq="2004-1674" severity="High" type="CVE"><desc><descript source="cve">viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11371">11371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12789">12789</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17976">merak-icewarp-file-deletion(17976)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="3.3.2"/><vers num="5.2.7"/><vers num="5.2.8"/></prod><prod name="Mail Server" vendor="Merak"><vers num="7.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1675" published="2004-09-11" seq="2004-1675" severity="Medium" type="CVE"><desc><descript source="cve">Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109495074211638&amp;w=2">20040911 Serv-U up to 5.2 Denial of Service</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11155">11155</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12507/">12507</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17329">servu-stou-dos(17329)</ref></refs><vuln_soft><prod name="Serv-U" vendor="RhinoSoft"><vers num="3.0"/><vers num="3.1"/><vers num="4.0.0.4"/><vers num="4.1.0.11"/><vers num="4.1"/><vers num="4.2"/><vers num="5.0.0.9"/><vers num="5.0.0.6"/><vers num="5.0.0.4"/><vers num="5.1.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1676" published="2004-09-12" seq="2004-1676" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508834910733&amp;w=2">20040912 Gadu-Gadu (all versions with image-send feature) Heap Overflow</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11158">11158</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12510">12510</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17324">gadu-gadu-image-bo(17324)</ref></refs><vuln_soft><prod name="Gadu-Gadu Instant Messenger" vendor="Gadu-Gadu"><vers num="6.0 build149"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1677" published="2004-09-12" seq="2004-1677" severity="Medium" type="CVE"><desc><descript source="cve">pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509026406554&amp;w=2">20040912 Posible Inclusion File in Perl Desk</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12512">12512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17343">perldesk-lang-file-include(17343)</ref></refs><vuln_soft><prod name="PerlDesk" vendor="logicNow"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1678" published="2004-09-13" seq="2004-1678" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via &quot;..&quot; sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509026406554&amp;w=2">20040912 Posible Inclusion File in Perl Desk</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11160">11160</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12512">12512</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19712">perldesk-directory-traversal(19712)</ref></refs><vuln_soft><prod name="PerlDesk" vendor="logicNow"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1679" published="2004-08-04" seq="2004-1679" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers create arbitrary files via a .../ (triple dot) in the (1) CWD, (2) STOR, or (3) RETR commands.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509243831121&amp;w=2">20040913 Directory Traversal Vulnerability in TwinFTP Server allows overwriting of files outside FTP directory</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/twinftp103r2.html">http://www.security.org.sg/vuln/twinftp103r2.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11159">11159</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12511/">12511</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17323">twinftp-argument-directory-traversal(17323)</ref></refs><vuln_soft><prod name="TwinFTP Enterprise" vendor="Jigunet"><vers num="1.0.3 R2"/></prod><prod name="TwinFTP Standard" vendor="Jigunet"><vers num="1.0.3 R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1680" published="2004-09-13" seq="2004-1680" severity="Medium" type="CVE"><desc><descript source="cve">application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a091304-2.txt">A091304-2</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11161">11161</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12523">12523</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17346">xpressa-applicationcgi-dos(17346)</ref></refs><vuln_soft><prod name="Xpressa" vendor="Pingtel"><vers num="1.2.5"/><vers num="1.2.7.4"/><vers num="1.2.8"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1.11.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1681" published="2004-08-26" seq="2004-1681" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109510393407597&amp;w=2">20040913 [RLSA_02-2004] QNX Photon multiple buffer overflows</ref><ref source="MISC" url="http://www.rfdslabs.com.br/qnx-advs-03-2004.txt">http://www.rfdslabs.com.br/qnx-advs-03-2004.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11164">11164</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17339">qnx-rtp-photon-bo(17339)</ref></refs><vuln_soft><prod name="RTP" vendor="QNX"><vers num="6.1"/></prod><prod name="Photon MicroGUI" vendor="QNX"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1682" published="2004-08-15" seq="2004-1682" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109511327005476&amp;w=2">20040913 [RLSA_03-2004] QNX ftp client format string bug</ref><ref source="MISC" url="http://www.rfdslabs.com.br/qnx-advs-04-2004.txt">http://www.rfdslabs.com.br/qnx-advs-04-2004.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12533">12533</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17347">qnx-ftp-quote-format-string(17347)</ref></refs><vuln_soft><prod name="RTP" vendor="QNX"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1683" published="2004-09-13" seq="2004-1683" severity="Low" type="CVE"><desc><descript source="cve">A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109511737504357&amp;w=2">20040913 [RLSA_04-2004] QNX crrtrap possible race condition vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11165">11165</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17345">qnx-rtp-crttrap-race-condition(17345)</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.2.0A"/><vers num="6.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1684" published="2004-09-13" seq="2004-1684" severity="Medium" type="CVE"><desc><descript source="cve">Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109510732611448&amp;w=2">20040913 Zyxel Prestige 681 SDSL router information leak</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11167">11167</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17372">prestige-information-disclosure(17372)</ref><ref source="OSVDB" url="http://www.osvdb.org/9962">9962</ref></refs><vuln_soft><prod name="Prestige" vendor="ZyXEL"><vers num="681"/></prod><prod name="ZyNOS" vendor="ZyXEL"><vers num="Vt020225a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1685" published="2004-09-15" seq="2004-1685" severity="High" type="CVE"><desc><descript source="cve">SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526094614160&amp;w=2">20040915 SMC7004VWBR / SMC7008ABR </ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11197">11197</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12601">12601</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17443">smc-router-security-bypass(17443)</ref><ref source="OSVDB" url="http://www.osvdb.org/10088">10088</ref></refs><vuln_soft><prod name="SMC7004VWBR" vendor="SMC Networks"><vers num="1.21a"/><vers num="1.22"/><vers num="1.23"/></prod><prod name="SMC7008ABR" vendor="SMC Networks"><vers num="1.32"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1686" published="2004-09-15" seq="2004-1686" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109539520310153&amp;w=2">20040915 IE6 + XP SP2 Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11200">11200</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20617">ie-information-bar-bypass(20617)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-1687" published="2004-09-16" seq="2004-1687" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109537195413691&amp;w=2">20040916 ADVISORY: security hole (http response splitting) in snitz forums</ref><ref adv="1" source="CONFIRM" url="http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&amp;TOPIC_ID=54791">http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&amp;TOPIC_ID=54791</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11201">11201</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12590">12590</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17421">snitz-response-splitting(17421)</ref></refs><vuln_soft><prod name="Snitz Forums 2000" vendor="Snitz Communications"><vers num="3.0"/><vers num="3.1"/><vers num="3.3.03"/><vers num="3.3.02"/><vers num="3.3.01"/><vers num="3.3"/><vers num="3.4.04"/><vers num="3.4.03"/><vers num="3.4.02"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1688" published="2004-09-16" seq="2004-1688" severity="Medium" type="CVE"><desc><descript source="cve">Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109543366631724&amp;w=2">20040916 Freeze in Pigeon Server 3.02.0143</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026515.html">20040916 Freeze in Pigeon Server 3.02.0143</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11203">11203</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12585">12585</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17427">pigeon-server-dos(17427)</ref></refs><vuln_soft><prod name="Pigeon Server" vendor="Tech-Noel"><vers num="3.02.0143"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1689" published="2004-09-16" seq="2004-1689" severity="Low" type="CVE"><desc><descript source="cve">sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109537972929201&amp;w=2">20040916 [sudo-announce] Sudo version 1.6.8p1 now available (fwd)</ref><ref adv="1" patch="1" source="MISC" url="http://packetstormsecurity.nl/0409-exploits/sudoedit.txt">http://packetstormsecurity.nl/0409-exploits/sudoedit.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.sudo.ws/sudo/alerts/sudoedit.html">http://www.sudo.ws/sudo/alerts/sudoedit.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/424358">VU#424358</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-219.shtml">O-219</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11204">11204</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/10023">10023 </ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12596">12596</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17424">sudo-sudoedit-view-files(17424)</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1690" published="2004-09-18" seq="2004-1690" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109552436811493&amp;w=2">20040918 RhinoSoft DNS4ME HTTP Server Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00049-09162004">http://www.gulftech.org/?node=research&amp;article_id=00049-09162004</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1011334">http://securitytracker.com/id?1011334</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11213">11213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12595">12595</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17425">dns4me-xss(17425)</ref></refs><vuln_soft><prod name="DNS4Me" vendor="RhinoSoft"><vers num="3.0.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1691" published="2004-09-18" seq="2004-1691" severity="Medium" type="CVE"><desc><descript source="cve">The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109552436811493&amp;w=2">20040918 RhinoSoft DNS4ME HTTP Server Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00049-09162004">http://www.gulftech.org/?node=research&amp;article_id=00049-09162004</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1011334">http://securitytracker.com/id?1011334</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11213">11213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12595">12595</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17426">dns4me-dos(17426)</ref></refs><vuln_soft><prod name="DNS4Me" vendor="RhinoSoft"><vers num="3.0.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1692" published="2004-09-18" seq="2004-1692" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571849713158&amp;w=2">20040918 Vulnerabilities in TUTOS</ref><ref patch="1" source="CONFIRM" url="http://mamboforge.net/frs/shownotes.php?release_id=1672">http://mamboforge.net/frs/shownotes.php?release_id=1672</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11220">11220</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/10179">10179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20616">mambo-multiple-xss(20616)</ref></refs><vuln_soft><prod name="Mambo Open Source" vendor="Mambo"><vers num="4.5_1.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1693" published="2004-09-18" seq="2004-1693" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571849713158&amp;w=2">20040918 Vulnerabilities in TUTOS</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Sep/1011365.html">http://www.securitytracker.com/alerts/2004/Sep/1011365.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11220">11220</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/10180">10180</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17449">mambo-cachelibrary-execute-code(17449)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011365">1011365</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.5_1.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1694" published="2004-09-21" seq="2004-1694" severity="High" type="CVE"><desc><descript source="cve">Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571689621784&amp;w=2">20040920 Default username/password pairs in ON Command CCM 5.x database</ref><ref adv="1" source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2004.09.29.html">http://www.sarc.com/avcenter/security/Content/2004.09.29.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11225">11225</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12604">12604</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17447">oncommand-multiple-default-accounts(17447)</ref></refs><vuln_soft><prod name="ON Command CCM" vendor="Symantec"><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/></prod><prod name="ON iCommand" vendor="Symantec"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-2004-1695" published="2004-09-20" seq="2004-1695" severity="High" type="CVE"><desc><descript source="cve">EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109577497718374&amp;w=2">20040921 Multiple Vulnerabilities In EmuLive Server4</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00051-09202004">http://www.gulftech.org/?node=research&amp;article_id=00051-09202004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11226">11226</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12616">12616</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17450">emuliveserver4-url-gain-access(17450)</ref></refs><vuln_soft><prod name="Server4" vendor="EmuLive"><vers num="Commerce Build 7560"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-1696" published="2004-09-21" seq="2004-1696" severity="Medium" type="CVE"><desc><descript source="cve">EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109577497718374&amp;w=2">20040921 Multiple Vulnerabilities In EmuLive Server4</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00051-09202004">http://www.gulftech.org/?node=research&amp;article_id=00051-09202004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11226">11226</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12616">12616</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17451">emulive-tcp-port-dos(17451)</ref></refs><vuln_soft><prod name="Server4" vendor="EmuLive"><vers num="Commerce Build 7560"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1697" published="2004-09-21" seq="2004-1697" severity="High" type="CVE"><desc><descript source="cve">The &quot;Forgot your Password&quot; link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109579952809320&amp;w=2">20040921 CA UniCenter Management Portal Username Enumeration Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11229">11229</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12620">12620</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17464">unicenter-management-username-bruteforce(17464)</ref></refs><vuln_soft><prod name="Unicenter Management" vendor="Computer Associates"><vers num="Portal 2.0"/><vers num="Portal 3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1698" published="2004-09-24" seq="2004-1698" severity="Medium" type="CVE"><desc><descript source="cve">The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109581586128899&amp;w=2">20040921 Broadcast crash in Popmessenger 1.60 (before 20 Sep 2004)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11230">11230</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12612/">12612</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17465">popmessenger-base64-dos(17465)</ref></refs><vuln_soft><prod name="PopMessenger" vendor="LeadMind"><vers num="1.60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1699" published="2004-09-21" seq="2004-1699" severity="Medium" type="CVE"><desc><descript source="cve">SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109589167110196&amp;w=2">20040922 Pinnacle ShowCenter 1.51 possible DoS</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026733.html">20040921 Pinnacle ShowCenter Skin Denial of Service</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11232">11232</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17463">pinnacle-showcenter-dos(17463)</ref></refs><vuln_soft><prod name="ShowCenter" vendor="Pinnacle Systems"><vers num="1.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-1700" published="2004-10-14" seq="2004-1700" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12613">12613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17708">pinnacle-showcenter-xss(17708)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11415">11415</ref></refs><vuln_soft><prod name="ShowCenter" vendor="Pinnacle Systems"><vers num="1.51 build 121"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1701" published="2004-08-09" seq="2004-1701" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109208394910086&amp;w=2">20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption</ref><ref adv="1" patch="1" source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886670528775&amp;w=2">20050219 cfengine rsa heap remote exploit:   part of PTjob project</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-08.xml">GLSA-200408-08</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10899">10899</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12251">12251</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16935">cfengine-cfservd-command-execution(16935)</ref></refs><vuln_soft><prod name="Cfengine" vendor="GNU"><vers num="2.0.8p1"/><vers num="2.0.8"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5 pre2"/><vers num="2.0.5 pre"/><vers num="2.0.5b1"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7 p3"/><vers num="2.0.7 p2"/><vers num="2.0.7 p1"/><vers num="2.0.7"/><vers num="2.1.0a9"/><vers num="2.1.0a8"/><vers num="2.1.0a6"/><vers num="2.1.7 p1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1702" published="2004-08-09" seq="2004-1702" severity="Medium" type="CVE"><desc><descript source="cve">The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109208394910086&amp;w=2">20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption</ref><ref adv="1" patch="1" source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200408-08.xml">GLSA-200408-08</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10900">10900</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12251">12251</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16937">cfengine-cfservd-dos(16937)</ref></refs><vuln_soft><prod name="Cfengine" vendor="GNU"><vers num="2.0.8p1"/><vers num="2.0.8"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5 pre2"/><vers num="2.0.5 pre"/><vers num="2.0.5b1"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7 p3"/><vers num="2.0.7 p2"/><vers num="2.0.7 p1"/><vers num="2.0.7"/><vers num="2.1.0a9"/><vers num="2.1.0a8"/><vers num="2.1.0a6"/><vers num="2.1.7 p1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1703" published="2004-07-30" seq="2004-1703" severity="High" type="CVE"><desc><descript source="cve">Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator&apos;s browser loads the page with the img tag.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109122824523226&amp;w=2">20040729 Fusion News Yet Another Unauthorized Account Addition Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10836">10836</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1010829">1010829</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16853">fusion-news-add-account(16853)</ref></refs><vuln_soft><prod name="Fusion News" vendor="Fusionphp"><vers num="3.3"/><vers num="3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1704" published="2004-07-30" seq="2004-1704" severity="High" type="CVE"><desc><descript source="cve">WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109122270013514&amp;w=2">20040730 WpQuiz Gain Admin Rightd Exploit found</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16848">wpquiz-extra-gain-access(16848)</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/8321">8321</ref></refs><vuln_soft><prod name="WpQuiz" vendor="Wire Plastic Design"><vers num="2.60b1"/><vers num="2.60b2"/><vers num="2.60b3"/><vers num="2.60b4"/><vers num="2.60b5"/><vers num="2.60b6"/><vers num="2.60b7"/><vers num="2.60b8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-1705" published="2004-07-30" seq="2004-1705" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109121546120575&amp;w=2">20040731 Citadel/UX Remote DoS Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109146099404071&amp;w=2">20040731 Re: Citadel/UX Remote DoS Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-04.txt">http://www.nosystem.com.ar/advisories/advisory-04.txt</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1010809">http://securitytracker.com/id?1010809</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10833">10833</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12197">12197</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16840">citadel-user-dos(16840)</ref></refs><vuln_soft><prod name="Citadel_UX" vendor="Citadel"><vers num="5.90"/><vers num="5.91"/><vers num="6.08"/><vers num="6.07"/><vers num="6.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1706" published="2004-08-02" seq="2004-1706" severity="High" type="CVE"><desc><descript source="cve">The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109146350605751&amp;w=2">20040802 7a69Adv#13 - USRobotics AP Wireless Denial of Service</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10840">10840</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12207">12207</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16860">usrobotics-wireless-get-bo(16860)</ref></refs><vuln_soft><prod name="USR808054" vendor="U.S.Robotics"><vers num="1.21 h"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-1707" published="2004-07-30" seq="2004-1707" severity="High" type="CVE"><desc><descript source="cve">The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109147677214087&amp;w=2">20040802 OPEN3S - Local Privilege Elevation through Oracle products (Unix Platform)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10829">10829</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12205">12205</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16839">oracle-libraries-gain-privileges(16839)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Enterprise 8.0.5 .0.0"/><vers num="Enterprise 8.0.6 .0.1"/><vers num="Enterprise 8.0.6 .0.0"/><vers num="Enterprise 8.1.5 .1.0"/><vers num="Enterprise 8.1.5 .0.2"/><vers num="Enterprise 8.1.5 .0.0"/><vers num="Enterprise 8.1.6 .1.0"/><vers num="Enterprise 8.1.6 .0.0"/><vers num="Enterprise 8.1.7 .1.0"/><vers num="Enterprise 8.1.7 .0.0"/><vers num="Standard 8.0.6 .3"/><vers num="Standard 8.0.6"/><vers num="Standard 8.1.5"/><vers num="Standard 8.1.6"/><vers num="Standard 8.1.7 .4"/><vers num="Standard 8.1.7 .1"/><vers num="Standard 8.1.7 .0.0"/><vers num="Standard 8.1.7"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Client 9.2.0.2"/><vers num="Client 9.2.0.1"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/><vers num="Enterprise 9.0.1"/><vers num="Enterprise 9.2.0.4"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/><vers num="Personal 8.1.7"/><vers num="Personal 9.0.1.5"/><vers num="Personal 9.0.1.4"/><vers num="Personal 9.0.1"/><vers num="Personal 9.2.0.4"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Standard 9.0"/><vers num="Standard 9.0.1.5"/><vers num="Standard 9.0.1.4"/><vers num="Standard 9.0.1.3"/><vers num="Standard 9.0.1.2"/><vers num="Standard 9.0.1"/><vers num="Standard 9.0.2"/><vers num="Standard 9.2.3"/><vers num="Standard 9.2.0.4"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num=""/><vers num="1.0.2.2.2"/><vers num="1.0.2.2"/><vers num="1.0.2.1s"/><vers num="1.0.2"/><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="Portal 3.0.9.8.5"/><vers num="Portal 9.0.2.3B"/><vers num="Portal 9.0.2.3A"/><vers num="Portal 9.0.2.3"/></prod><prod name="Oracle9i Lite" vendor="Oracle"><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1708" published="2004-08-02" seq="2004-1708" severity="Medium" type="CVE"><desc><descript source="cve">Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109156450320855&amp;w=2">20040803 DoS in Webbsyte Chat 0.9.0</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10842">10842</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16852">webbsyte-chat-dos(16852)</ref></refs><vuln_soft><prod name="Webbsyte Chat" vendor="Shawn Webb"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1709" published="2004-08-04" seq="2004-1709" severity="Low" type="CVE"><desc><descript source="cve">Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109164096013467&amp;w=2">20040804 Clear text password exposure in Datakey&apos;s tokens and smartcards</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16887">datakey-plaintext-pin(16887)</ref></refs><vuln_soft><prod name="Rainbow iKey2032 USB token" vendor="Datakey"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1710" published="2004-08-06" seq="2004-1710" severity="High" type="CVE"><desc><descript source="cve">page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="OSVDB" url="http://www.osvdb.org/8936">8936</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19713">pagecgi-url-command-execution(19713)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181771832634&amp;w=2">20040806 Remote Command Execution</ref></refs><vuln_soft><prod name="page_cgi" vendor="Andrew Kilpatrick"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1711" published="2004-08-06" seq="2004-1711" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109182851216921&amp;w=2">20040806 xss in moodle (post.php)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10884">10884</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12262">12262</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16924">moodle-post-xss(16924)</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1712" published="2004-08-06" seq="2004-1712" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in TypePad allows remote attackers inject arbitrary Javascript via the name parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109189453302959&amp;w=2">20040806 Type xxs</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19664">typepad-name-xss(19664)</ref></refs><vuln_soft><prod name="TypePad" vendor="TypePad"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1713" published="2004-08-10" seq="2004-1713" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215093809027&amp;w=2">SSRT4785</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10907">10907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12245">12245</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16928">hp-prm-wlm-file-corruption(16928)</ref></refs><vuln_soft><prod name="Process Resource Manager" vendor="HP"><vers num="C.02.01.01"/><vers num="C.01.08.02"/><vers num="C.01.07"/></prod><prod name="Workload Manager" vendor="HP"><vers num="A.02.01"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1714" published="2004-08-11" seq="2004-1714" severity="Low" type="CVE"><desc><descript source="cve">BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109223751031166&amp;w=2">20040811 BlackICE unprivileged local user attack</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html">20040811 ISS BlackIce Server Protect Unprivileged User Attack</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10915">10915</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16959">blackice-firewall-dos(16959)</ref></refs><vuln_soft><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6ccg"/><vers num="3.6ccf"/><vers num="3.6cce"/><vers num="3.6ccd"/><vers num="3.6ccc"/><vers num="3.6ccb"/><vers num="3.6cca"/><vers num="3.6cbz"/><vers num="3.6cbr"/><vers num="3.6cbd"/></prod><prod name="BlackICE Server Protection" vendor="Internet Security Systems"><vers num="3.5cdf"/><vers num="3.6cch"/><vers edition="6ccg" num="3"/><vers num="3.6ccf"/><vers num="3.6cce"/><vers num="3.6ccd"/><vers num="3.6ccc"/><vers num="3.6ccb"/><vers num="3.6cca"/><vers num="3.6cbz"/><vers num="3.6cno"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1715" published="2004-08-11" seq="2004-1715" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via &quot;..\\&quot;, &quot;..\&quot;, and similar dot dot sequences in the URL.</descript></desc><sols><sol source="nvd">This was fixed in MIMEsweeper for Web v5.0.4.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109224211512029&amp;w=2">20040811 Clearswift Mimesweeper Path Traversal Vulnerability</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225567212978&amp;w=2">20040811 Re: Clearswift Mimesweeper Path Traversal Vulnerability</ref><ref adv="1" source="MISC" url="http://packetstormsecurity.nl/0408-exploits/clearswift.txt">http://packetstormsecurity.nl/0408-exploits/clearswift.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10918">10918</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12273">12273</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16960">mimesweeper-directory-traversal(16960)</ref></refs><vuln_soft><prod name="MIMEsweeper For Web" vendor="Clearswift"><vers num="4.0"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1716" published="2004-08-16" seq="2004-1716" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109267937212298&amp;w=2">20040814 pscript.de PFORUM XSS Vulnerability</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/674542">VU#674542</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10954">10954</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/8985">8985</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12317/">12317</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17003">pforum-irc-aim-xss(17003)</ref></refs><vuln_soft><prod name="PForum" vendor="Powie"><vers num="1.24"/><vers num="1.25"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1717" published="2004-08-16" seq="2004-1717" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109267677114331&amp;w=2">20040816 gv buffer overflows: here, there, and everywhere</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10944">10944</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17019">gv-psscan-header-bo(17019)</ref></refs><vuln_soft><prod name="gv" vendor="gv"><vers num="2.7b5"/><vers num="2.7b4"/><vers num="2.7b3"/><vers num="2.7b2"/><vers num="2.7b1"/><vers num="2.7.6"/><vers num="2.9.4"/><vers num="3.0.0"/><vers num="3.0.4"/><vers num="3.1.4"/><vers num="3.1.6"/><vers num="3.2.4"/><vers num="3.4.2"/><vers num="3.4.3"/><vers num="3.4.12"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1718" published="2004-08-17" seq="2004-1718" severity="Low" type="CVE"><desc><descript source="cve">The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the &quot;oa&quot; argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109276749821133&amp;w=2">20040817 [NGSEC-2004-6] IPD, local system denial of service.</ref><ref adv="1" source="MISC" url="http://www.ngsec.com/docs/advisories/NGSEC-2004-6.txt">http://www.ngsec.com/docs/advisories/NGSEC-2004-6.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10965">10965</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12169">12169</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17010">ipd-oa-pointer-dos(17010)</ref></refs><vuln_soft><prod name="Integrity Protection Driver" vendor="Pedestal Software"><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1719" published="2004-08-17" seq="2004-1719" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an &lt;img&gt; tag, or (15) the subject of an e-mail message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2">20040817 Vulnerabilities in Merak Webmail Server</ref><ref adv="1" patch="1" source="MISC" url="http://packetstormsecurity.nl/0408-exploits/merak527.txt">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1010969.html">http://www.securitytracker.com/alerts/2004/Aug/1010969.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10966">10966</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9037">9037</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9038">9038</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9039">9039</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9040">9040</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9041">9041</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9042">9042</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12269">12269</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17024">merak-xss(17024)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010969">1010969</ref></refs><vuln_soft><prod name="Mail Server" vendor="Merak"><vers num="7.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1720" published="2004-08-17" seq="2004-1720" severity="Medium" type="CVE"><desc><descript source="cve">The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2">20040817 Vulnerabilities in Merak Webmail Server</ref><ref adv="1" patch="1" source="MISC" url="http://packetstormsecurity.nl/0408-exploits/merak527.txt">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1010969.html">http://www.securitytracker.com/alerts/2004/Aug/1010969.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10966">10966</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9043">9043</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12269">12269</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17027">merak-address-calendar-path-disclosure(17027)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010969">1010969</ref></refs><vuln_soft><prod name="Mail Server" vendor="Merak"><vers num="7.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1721" published="2004-08-17" seq="2004-1721" severity="Medium" type="CVE"><desc><descript source="cve">The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2">20040817 Vulnerabilities in Merak Webmail Server</ref><ref adv="1" patch="1" source="MISC" url="http://packetstormsecurity.nl/0408-exploits/merak527.txt">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1010969.html">http://www.securitytracker.com/alerts/2004/Aug/1010969.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10966">10966</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9045">9045</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12269">12269</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17029">merak-view-php-files(17029)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010969">1010969</ref></refs><vuln_soft><prod name="Mail Server" vendor="Merak"><vers num="5.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1722" published="2004-08-17" seq="2004-1722" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2">20040817 Vulnerabilities in Merak Webmail Server</ref><ref adv="1" patch="1" source="MISC" url="http://packetstormsecurity.nl/0408-exploits/merak527.txt">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1010969.html">http://www.securitytracker.com/alerts/2004/Aug/1010969.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10966">10966</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/9044">9044</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12269">12269</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17022">merak-calendarhtml-sql-injection(17022)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010969">1010969</ref></refs><vuln_soft><prod name="Mail Server" vendor="Merak"><vers num="7.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1723" published="2004-12-31" seq="2004-1723" severity="Medium" type="CVE"><desc><descript source="cve">The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109285292901685&amp;w=2">20040818 Multiple vulnerabilities in PHP-FUSION</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17036">phpfusion-path-disclosure(17036)</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="4.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1724" published="2004-08-18" seq="2004-1724" severity="High" type="CVE"><desc><descript source="cve">The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109285292901685&amp;w=2">20040818 Multiple vulnerabilities in PHP-FUSION</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10974">10974</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12336">12336</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17037">phpfusion-database-file-access(17037)</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1725" published="2004-12-31" seq="2004-1725" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109302498125092&amp;w=2">20040820 XV multiple buffer overflows, exploit included</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10985">10985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17053">xv-image-bo(17053)</ref></refs><vuln_soft><prod name="XV" vendor="John Bradley"><vers num="3.10a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1726" published="2004-08-20" seq="2004-1726" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109302498125092&amp;w=2">20040820 XV multiple buffer overflows, exploit included</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10985">10985</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17053">xv-image-bo(17053)</ref></refs><vuln_soft><prod name="XV" vendor="John Bradley"><vers num="3.10a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-1727" published="2004-08-20" seq="2004-1727" severity="Medium" type="CVE"><desc><descript source="cve">BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109309119502208&amp;w=2">20040820 BadBlue Webserver v2.5 Denial Of Service Vulnerability</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00043-08202004">http://www.gulftech.org/?node=research&amp;article_id=00043-08202004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10983">10983</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12346">12346</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17064">badblue-mult-connection-dos(17064)</ref></refs><vuln_soft><prod name="BadBlue" vendor="Working Resources Inc."><vers num="2.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1728" published="2004-08-20" seq="2004-1728" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109308454122827&amp;w=2">20040820 Buffer overflow in sarad</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10984">10984</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12348">12348</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17060">sara-server-bo(17060)</ref></refs><vuln_soft><prod name="SARA" vendor="British National Corpus"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1729" published="2004-08-20" seq="2004-1729" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109305923208449&amp;w=2">20040820 Cross-Site Scripting (XSS) in Nihuo Web Log Analyzer</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10988">10988</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12347">12347</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17055">nihuo-http-get-xss(17055)</ref></refs><vuln_soft><prod name="Web Log Analyzer" vendor="Nihuo Software"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1730" published="2004-12-31" seq="2004-1730" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312225727345&amp;w=2">20040820 Multiple Vulnerabilities in Mantis Bugtracker</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17066">mantis-loginpage-xss(17066)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17070">mantis-loginselectprojpage-xss(17070)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17069">mantis-signup-xss(17069)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17072">mantis-viewallset-xss(17072)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10994">10994</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12338">12338</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="0.9"/><vers num="0.9.1"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.11"/><vers num="0.11.1"/><vers num="0.12"/><vers num="0.13"/><vers num="0.13.1"/><vers num="0.14"/><vers num="0.14.1"/><vers num="0.14.2"/><vers num="0.14.3"/><vers num="0.14.4"/><vers num="0.14.5"/><vers num="0.14.6"/><vers num="0.14.7"/><vers num="0.14.8"/><vers num="0.15"/><vers num="0.15.1"/><vers num="0.15.2"/><vers num="0.15.3"/><vers num="0.15.4"/><vers num="0.15.5"/><vers num="0.15.6"/><vers num="0.15.7"/><vers num="0.15.8"/><vers num="0.15.9"/><vers num="0.15.10"/><vers num="0.15.11"/><vers num="0.15.12"/><vers num="0.16.0"/><vers num="0.16"/><vers num="0.16.1"/><vers num="0.17.0"/><vers num="0.17"/><vers num="0.17.1"/><vers num="0.17.2"/><vers num="0.17.3"/><vers num="0.17.4a"/><vers num="0.17.4"/><vers num="0.17.5"/><vers num="0.18a1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18"/><vers num="0.19.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1731" published="2004-08-20" seq="2004-1731" severity="Medium" type="CVE"><desc><descript source="cve">signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312225727345&amp;w=2">20040820 Multiple Vulnerabilities in Mantis Bugtracker</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10995">10995</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17093">mantis-improper-account-validation(17093)</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="0.9"/><vers num="0.9.1"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.11"/><vers num="0.11.1"/><vers num="0.12"/><vers num="0.13"/><vers num="0.13.1"/><vers num="0.14"/><vers num="0.14.1"/><vers num="0.14.2"/><vers num="0.14.3"/><vers num="0.14.4"/><vers num="0.14.5"/><vers num="0.14.6"/><vers num="0.14.7"/><vers num="0.14.8"/><vers num="0.15"/><vers num="0.15.1"/><vers num="0.15.2"/><vers num="0.15.3"/><vers num="0.15.4"/><vers num="0.15.5"/><vers num="0.15.6"/><vers num="0.15.7"/><vers num="0.15.8"/><vers num="0.15.9"/><vers num="0.15.10"/><vers num="0.15.11"/><vers num="0.15.12"/><vers num="0.16.0"/><vers num="0.16"/><vers num="0.16.1"/><vers num="0.17.0"/><vers num="0.17"/><vers num="0.17.1"/><vers num="0.17.2"/><vers num="0.17.3"/><vers num="0.17.4a"/><vers num="0.17.4"/><vers num="0.17.5"/><vers num="0.18a1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18"/><vers num="0.19.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1732" published="2004-08-20" seq="2004-1732" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.</descript></desc><sols><sol source="nvd">This was fixed in version 1.4.2.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109314495007280&amp;w=2">20040820 Multiple vulnerabilities in  MyDMS</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10996">10996</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12340">12340</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17054">mydms-folderld-sql-injection(17054)</ref></refs><vuln_soft><prod name="MyDMS" vendor="MyDMS"><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1733" published="2004-08-20" seq="2004-1733" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109314495007280&amp;w=2">20040820 Multiple vulnerabilities in  MyDMS</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10996">10996</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12340">12340</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17058">mydms-dotdot-file-download(17058)</ref></refs><vuln_soft><prod name="MyDMS" vendor="MyDMS"><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1734" published="2004-12-31" seq="2004-1734" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109313416727851&amp;w=2">20040820 Mantis Bugtracker Remote PHP Code Execution Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10993">10993</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17065">mantis-php-file-include(17065)</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="0.19.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1735" published="2004-08-21" seq="2004-1735" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312475207604&amp;w=2">20040820 Cross Site Scripting Vulnerability in Sympa</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10992">10992</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12339">12339</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17057">sympa-description-xss(17057)</ref></refs><vuln_soft><prod name="Sympa" vendor="Sympa"><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-1736" published="2004-12-31" seq="2004-1736" severity="Medium" type="CVE"><desc><descript source="cve">Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109272483621038&amp;w=2">20040816 SQL Injection in CACTI</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025376.html">20040816 SQL Injection in CACTI</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12308">12308</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17014">cacti-error-path-disclosure(17014)</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.5a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-1737" published="2004-08-16" seq="2004-1737" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109272483621038&amp;w=2">20040816 SQL Injection in CACTI</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025376.html">20040816 SQL Injection in CACTI</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200408-21.xml">GLSA-200408-21</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10960">10960</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12308">12308</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17011">cacti-authlogin-sql-injection(17011)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.5a"/><vers num="0.8.5"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.6.8a"/><vers num="0.6.8"/><vers num="0.6.7"/><vers num="0.6.6"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1738" published="2004-12-31" seq="2004-1738" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327547026265&amp;w=2">20040823 JShop Input Validation Hole in page.php Permits Cross-Site</ref><ref source="MISC" url="http://indohack.sourceforge.net/drponidi/jshop-vuln.txt">http://indohack.sourceforge.net/drponidi/jshop-vuln.txt</ref><ref source="MISC" url="http://securitytracker.com/id?1011020">http://securitytracker.com/id?1011020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12345">12345</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17075">jshop-page-xpage-xss(17075)</ref></refs><vuln_soft><prod name="JShop Server" vendor="JShop E-Commerce"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1739" published="2004-08-23" seq="2004-1739" severity="Medium" type="CVE"><desc><descript source="cve">Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.</descript></desc><sols><sol source="nvd">This has been fixed in version 1.61 Security Release.</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327938924287&amp;w=2">20040823 DoS in Bird Chat 1.61</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/BirdChat1.61-adv.txt">http://www.autistici.org/fdonato/advisory/BirdChat1.61-adv.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11010">11010</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12365">12365</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17080">bird-chat-dos(17080)</ref></refs><vuln_soft><prod name="Internet Chat Server" vendor="Bird Chat"><vers num="1.61"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1740" published="2004-08-23" seq="2004-1740" severity="Medium" type="CVE"><desc><descript source="cve">Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109329098806595&amp;w=2">20040823 MusicDaemon &lt;= 0.0.3 /etc/shadow Stealer / DoS Exploit</ref><ref patch="1" source="CONFIRM" url="http://musicdaemon.sourceforge.net/">http://musicdaemon.sourceforge.net/</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11006">11006</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17067">musicd-commands-view-files(17067)</ref></refs><vuln_soft><prod name="Music daemon" vendor="Music daemon"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1741" published="2004-08-23" seq="2004-1741" severity="Medium" type="CVE"><desc><descript source="cve">Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109329098806595&amp;w=2">20040823 MusicDaemon &lt;= 0.0.3 /etc/shadow Stealer / DoS Exploit</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Aug/1011025.html">http://www.securitytracker.com/alerts/2004/Aug/1011025.html</ref><ref patch="1" source="CONFIRM" url="http://musicdaemon.sourceforge.net/">http://musicdaemon.sourceforge.net/</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11006">11006</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17068">musicd-load-showlist-dos(17068)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011025">1011025</ref></refs><vuln_soft><prod name="Music daemon" vendor="Music daemon"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1742" published="2004-08-24" seq="2004-1742" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109336268002879&amp;w=2">20040824 WebAPP directory traversal and ability to retrieve the DES encrypted password hash</ref><ref source="CONFIRM" url="http://cornerstone.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=updates&amp;id=1">http://cornerstone.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=updates&amp;id=1</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11028">11028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12373">12373</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17100">webapp-dotdot-directory-traversal(17100)</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-07" name="CVE-2004-1743" published="2004-08-24" seq="2004-1743" severity="Medium" type="CVE"><desc><descript source="cve">Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109341398102863&amp;w=2">20040824 Easy File Sharing Webserver v1.25 Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00045-08242004">http://www.gulftech.org/?node=research&amp;article_id=00045-08242004</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1011045">http://securitytracker.com/id?1011045</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11034">11034</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12372">12372</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17109">easyfilesharing-obtain-info(17109)</ref></refs><vuln_soft><prod name="EFS Web Server" vendor="EFS Software"><vers num="1.2"/><vers num="1.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-07" name="CVE-2004-1744" published="2004-08-24" seq="2004-1744" severity="Medium" type="CVE"><desc><descript source="cve">Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109341398102863&amp;w=2">20040824 Easy File Sharing Webserver v1.25 Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00045-08242004">http://www.gulftech.org/?node=research&amp;article_id=00045-08242004</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11036">11036</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12372">12372</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17110">easyfilesharing-http-request-dos(17110)</ref><ref source="OSVDB" url="http://www.osvdb.org/9175">9175</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011045">1011045</ref></refs><vuln_soft><prod name="EFS Web Server" vendor="EFS Software"><vers num="1.2"/><vers num="1.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1745" published="2004-08-24" seq="2004-1745" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109339761608821&amp;w=2">20040824 Limited buffer overflow in Painkiller 1.31</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11029">11029</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12367">12367</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17101">painkiller-long-password-bo(17101)</ref></refs><vuln_soft><prod name="Painkiller" vendor="People can Fly"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1746" published="2004-12-31" seq="2004-1746" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109340580218818&amp;w=2">20040824 PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11038">11038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12370">12370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17108">snippet-index-xss(17108)</ref></refs><vuln_soft><prod name="PHP Code Snippet Library" vendor="PHP Code Snippet Library"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1747" published="2004-12-31" seq="2004-1747" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041 running firmware 1.2 Release 03 allows remote attackers to inject arbitrary web script or HTML via the DHCP HOSTNAME option.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109344996523392&amp;w=2">20040825 bug found</ref><ref source="BID" url="http://www.securityfocus.com/bid/11046">11046</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17120">network-everywhere-dhcp-gain-access(17120)</ref></refs><vuln_soft><prod name="NR041" vendor="Network Everywhere"><vers num="1.2 Release 03"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1748" published="2004-12-31" seq="2004-1748" severity="Low" type="CVE"><desc><descript source="cve">NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345177124374&amp;w=2">20040825 [NGSEC-2004-7] NtRegmon, local system denial of service.</ref><ref source="MISC" url="http://www.ngsec.com/docs/advisories/NGSEC-2004-7.txt">http://www.ngsec.com/docs/advisories/NGSEC-2004-7.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11042">11042</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17106">ntregmon-registry-dos(17106)</ref></refs><vuln_soft><prod name="Regmon" vendor="Sysinternals"><vers num="6.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1749" published="2004-07-22" seq="2004-1749" severity="Medium" type="CVE"><desc><descript source="cve">Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345253016318&amp;w=2">20040825 IRM 010: Top Layer Attack Mitigator IPS 5500 Denial of Service</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11049">11049</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12390">12390</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17125">am-ips5500-http-dos(17125)</ref></refs><vuln_soft><prod name="Attack Mitigator" vendor="TopLayer"><vers num="5500 3.11.008"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1750" published="2004-12-31" seq="2004-1750" severity="Medium" type="CVE"><desc><descript source="cve">RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109346198700529&amp;w=2">20040825 RealVNC 4.0 DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/11048">11048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13143">13143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17123">realvnc-multiple-connections-dos(17123)</ref></refs><vuln_soft><prod name="RealVNC" vendor="RealVNC"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1751" published="2004-08-26" seq="2004-1751" severity="Medium" type="CVE"><desc><descript source="cve">Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a &quot;Message too long&quot; socket error that is treated as a critical error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/gc2boom-adv.txt"></ref><ref adv="1" patch="1" source="SecurityTracker" url="http://securitytracker.com/id?1011075">http://securitytracker.com/id?1011075</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11058">11058</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17130">ground-control-dos(17130)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109357154602892&amp;w=2">20040826 Broadcast forced exit in Ground Control II 1.0.0.7</ref></refs><vuln_soft><prod name="Ground Control II: Operation Exodus" vendor="Massive Entertainment"><vers num="1.0.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1752" published="2004-08-24" seq="2004-1752" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109364123707953&amp;w=2">20040826 Gaucho v1.4 Build 145 Buffer Overflow</ref><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/gaucho140.html">http://www.security.org.sg/vuln/gaucho140.html</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1011032">http://securitytracker.com/id?1011032</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11023">11023</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12387">12387</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17090">gaucho-pop3-bo(17090)</ref></refs><vuln_soft><prod name="Gaucho" vendor="NakedSoft"><vers num="1.4 build 145"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1753" published="2004-12-31" seq="2004-1753" severity="Low" type="CVE"><desc><descript source="cve">The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/373080">20040826 Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/373309">20040827 Re: Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/373232">20040827 Re: Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref><ref source="MISC" url="http://bugzilla.mozilla.org/show_bug.cgi?id=162134">http://bugzilla.mozilla.org/show_bug.cgi?id=162134</ref><ref source="BID" url="http://www.securityfocus.com/bid/11059">11059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12392">12392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17137">netscape-java-tab-spoofing(17137)</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num="7.1"/><vers num="7.2"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1754" published="2004-06-15" seq="2004-1754" severity="Medium" type="CVE"><desc><descript source="cve">The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://lists.virus.org/bugtraq-0406/msg00234.html">20040615 Symantec Enterprise Firewall DNSD cache poisoning Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2004.06.21.html">http://securityresponse.symantec.com/avcenter/security/Content/2004.06.21.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10557">10557</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11888">11888</ref></refs><vuln_soft><prod name="Enterprise Firewall" vendor="Symantec"><vers edition="Solaris" num="7.0.4"/><vers edition="Windows 2000_NT" num="7.0.4"/><vers edition="Solaris" num="8.0"/><vers edition="Windows 2000_NT" num="8.0"/><vers num="8.0"/></prod><prod name="Gateway Security" vendor="Symantec"><vers num="5110 1.0"/><vers num="5200 1.0"/><vers num="5300 1.0"/><vers num="5310 1.0"/><vers num="5400 2.0"/><vers num="5400 2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1755" published="2004-12-31" seq="2004-1755" severity="High" type="CVE"><desc><descript source="cve">The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jsp</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/858990">VU#858990</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9502">9502</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10725">10725</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15826">weblogic-multiple-connection-gain-access(15826)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1756" published="2004-04-13" seq="2004-1756" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/566390">VU#566390</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1009765">http://securitytracker.com/id?1009765</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10132">10132</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11358">11358</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15862">weblogic-trust-certificate-spoofing(15862)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1757" published="2004-12-31" seq="2004-1757" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_50.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_50.00.jsp</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350350">VU#350350</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9501">9501</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10728">10728</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14957">weblogic-boot-password-disclosure(14957)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP5"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP5"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1758" published="2004-04-13" seq="2004-1758" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/920238">VU#920238</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10131">10131</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15860">bea-configxml-plaintext-password(15860)</ref><ref source="OSVDB" url="http://www.osvdb.org/5297">5297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009764">1009764</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11357">11357</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="7.0"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers num="6.1 SP3"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1759" published="2004-01-21" seq="2004-1759" severity="Medium" type="CVE"><desc><descript source="cve">Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml">20040121 Voice Product Vulnerabilities on IBM Servers</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/721092">VU#721092</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9469">9469</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10696">10696</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14901">ciscovoice-ibmservers-dos(14901)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</ref><ref source="OSVDB" url="http://www.osvdb.org/3691">3691</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008814">1008814</ref></refs><vuln_soft><prod name="MCS-7815I-2.0" vendor="IBM"><vers num=""/></prod><prod name="Director Agent" vendor="IBM"><vers num="2.2"/><vers num="3.11"/></prod><prod name="X340" vendor="IBM"><vers num=""/></prod><prod name="X330" vendor="IBM"><vers num="8674"/><vers num="8654"/></prod><prod name="Internet Service Node" vendor="Cisco"><vers num=""/></prod><prod name="Call Manager" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="3.1.3a"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3.3"/><vers num="3.3"/><vers num="4.0"/></prod><prod name="MCS-7815-1000" vendor="IBM"><vers num=""/></prod><prod name="Emergency Responder" vendor="Cisco"><vers num="1.1"/></prod><prod name="Personal Assistant" vendor="Cisco"><vers num="1.3 (4)"/><vers num="1.3 (3)"/><vers num="1.3 (2)"/><vers num="1.3 (1)"/><vers num="1.4 (2)"/><vers num="1.4 (1)"/></prod><prod name="Conference Connection" vendor="Cisco"><vers num="1.1 (1)"/><vers num="1.2"/></prod><prod name="IP Interactive Voice Response" vendor="Cisco"><vers num="3.0"/></prod><prod name="MCS-7835I-3.0" vendor="IBM"><vers num=""/></prod><prod name="X342" vendor="IBM"><vers num=""/></prod><prod name="IP Call Center Express Enhanced" vendor="Cisco"><vers num="3.0"/></prod><prod name="X345" vendor="IBM"><vers num=""/></prod><prod name="IP Call Center Express Standard" vendor="Cisco"><vers num="3.0"/></prod><prod name="MCS-7835I-2.4" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1760" published="2004-01-21" seq="2004-1760" severity="High" type="CVE"><desc><descript source="cve">The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml">20040121 Voice Product Vulnerabilities on IBM Servers</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/602734">VU#602734</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9468">9468</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10696">10696</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14900">ciscovoice-ibmservers-admin-access(14900)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</ref><ref source="OSVDB" url="http://www.osvdb.org/3692">3692</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008814">1008814</ref></refs><vuln_soft><prod name="MCS-7815I-2.0" vendor="IBM"><vers num=""/></prod><prod name="Director Agent" vendor="IBM"><vers num="2.2"/><vers num="3.11"/></prod><prod name="X340" vendor="IBM"><vers num=""/></prod><prod name="X330" vendor="IBM"><vers num="8674"/><vers num="8654"/></prod><prod name="Internet Service Node" vendor="Cisco"><vers num=""/></prod><prod name="Call Manager" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="3.1.3a"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3.3"/><vers num="3.3"/><vers num="4.0"/></prod><prod name="MCS-7815-1000" vendor="IBM"><vers num=""/></prod><prod name="Emergency Responder" vendor="Cisco"><vers num="1.1"/></prod><prod name="Personal Assistant" vendor="Cisco"><vers num="1.3 (4)"/><vers num="1.3 (3)"/><vers num="1.3 (2)"/><vers num="1.3 (1)"/><vers num="1.4 (2)"/><vers num="1.4 (1)"/></prod><prod name="Conference Connection" vendor="Cisco"><vers num="1.1 (1)"/><vers num="1.2"/></prod><prod name="IP Interactive Voice Response" vendor="Cisco"><vers num="3.0"/></prod><prod name="MCS-7835I-3.0" vendor="IBM"><vers num=""/></prod><prod name="X342" vendor="IBM"><vers num=""/></prod><prod name="IP Call Center Express Enhanced" vendor="Cisco"><vers num="3.0"/></prod><prod name="X345" vendor="IBM"><vers num=""/></prod><prod name="IP Call Center Express Standard" vendor="Cisco"><vers num="3.0"/></prod><prod name="MCS-7835I-2.4" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1761" published="2004-12-31" seq="2004-1761" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00013.html">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/695486">VU#695486</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11185">11185</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15572">ethereal-colour-filter-dos(15572)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-136.html">RHSA-2004:136</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.16"/><vers num="0.8.17a"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.8.20"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.0a"/><vers num="0.10.1"/><vers num="0.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1762" published="2004-12-31" seq="2004-1762" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-linux-hotfixes.shtml">http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-linux-hotfixes.shtml</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/415734">VU#415734</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11089">11089</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15432">fsecure-antivirus-protection-bypass(15432)</ref></refs><vuln_soft><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers edition="Linux" num="4.51 Hotfix 2"/><vers edition="Linux" num="4.50 Hotfix 1"/><vers edition="Linux" num="4.50 Hotfix 2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1763" published="2004-12-31" seq="2004-1763" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108091662105032&amp;w=2">20040402 Buffer Overflow in HAHTsite Scenario Server 5.1</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/705958">VU#705958</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10033">10033</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11288">11288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15717">hahtsite-long-request-bo(15717)</ref></refs><vuln_soft><prod name="HAHTsite Scenario Server" vendor="HAHT Commerce"><vers num="5.1 Patch 6"/><vers num="5.1 Patch 5"/><vers num="5.1 Patch 4"/><vers num="5.1 Patch 3"/><vers num="5.1 Patch 2"/><vers num="5.1 Patch 1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1764" published="2004-01-14" seq="2004-1764" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="HP" url="http://www.securityfocus.com/advisories/6237">HPSBUX0401-308</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/406406">VU#406406</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-057.shtml">O-057</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14828">hp-libdtsvc-bo(14828)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.04"/><vers num="B.11.11"/><vers num="B.11.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1765" published="2004-12-31" seq="2004-1765" severity="High" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945597331370&amp;w=2">20040316 ModSecurity 1.7.4 for Apache 2.x remote off-by-one overflow</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040315.txt">http://www.s-quadra.com/advisories/Adv-20040315.txt</ref><ref source="CONFIRM" url="http://www.modsecurity.org/">http://www.modsecurity.org/</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/779438">VU#779438</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9885">9885</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11138">11138</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15489">mod-security-offbyone-bo(15489)</ref></refs><vuln_soft><prod name="mod_security" vendor="mod_security"><vers num="1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-1766" published="2004-01-20" seq="2004-1766" severity="Medium" type="CVE"><desc><descript source="cve">The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-5VEU8N">http://www.kb.cert.org/vuls/id/CRDY-5VEU8N</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927630">VU#927630</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9455">9455</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10675">10675</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14886">netscreen-information-disclosure(14886)</ref><ref source="" url="http://www.juniper.net/support/security/alerts/58290.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3613">3613</ref></refs><vuln_soft><prod name="NetScreen-Security Manager" vendor="Juniper"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1767" published="2004-12-31" seq="2004-1767" severity="High" type="CVE"><desc><descript source="cve">The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57479-1">57479</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/702526">VU#702526</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9477">9477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14917">solaris-kernel-module-gain-privilege(14917)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4532">oval:org.mitre.oval:def:4532</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1768" published="2004-12-17" seq="2004-1768" severity="Medium" type="CVE"><desc><descript source="cve">The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="ftp://ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/p132_notes.htm">ftp://ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/p132_notes.htm</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/697598">VU#697598</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/12459">12459</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13489">13489</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18530">symantec-brightmail-spamhunter-dos(18530)</ref></refs><vuln_soft><prod name="Brightmail AntiSpam" vendor="Symantec"><vers num="6.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1769" published="2004-03-11" seq="2004-1769" severity="High" type="CVE"><desc><descript source="cve">The &quot;Allow cPanel users to reset their password via email&quot; feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357064/2004-03-08/2004-03-14/0">20040311 Cpanel 8.*.* have a problem ?</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107904890724201&amp;w=2">20040311 cPanel Secuirty Advisory CPANEL-2004:01-01</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/831534">VU#831534</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9848">9848</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11111">11111</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15443">cpanel-resetpass-execute-commands(15443)</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="5.0"/><vers num="5.3"/><vers num="6.0"/><vers num="6.2"/><vers num="6.4"/><vers num="6.4.1"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="7.0"/><vers num="8.0"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1770" published="2004-03-11" seq="2004-1770" severity="High" type="CVE"><desc><descript source="cve">The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911581732035&amp;w=2">20040312 Cpanel 9.1.0 have a problem ?</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/831534">VU#831534</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9855">9855</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11124">11124</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15486">cpanel-login-execute-commands(15486)</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="5.0"/><vers num="5.3"/><vers num="6.0"/><vers num="6.2"/><vers num="6.4"/><vers num="6.4.1"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="7.0"/><vers num="8.0"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1771" published="2004-11-30" seq="2004-1771" severity="Medium" type="CVE"><desc><descript source="cve">Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013553">http://securitytracker.com/id?1013553</ref><ref adv="1" source="MISC" url="http://bugzilla.opengroupware.org/bugzilla/show_bug.cgi?id=1060">http://bugzilla.opengroupware.org/bugzilla/show_bug.cgi?id=1060</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/14675">14675</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19820">ogo-permission-information-disclosure(19820)</ref></refs><vuln_soft><prod name="Scalable OGo" vendor="Open Group"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1772" published="2004-12-31" seq="2004-1772" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/359639">20040406 GNU Sharutils buffer overflow vulnerability.</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2155">FLSA:2155</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137386310299&amp;w=2">20040407 [OpenPKG-SA-2004.011] OpenPKG Security Advisory (sharutils)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10066">10066</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15759">sharutils-shar-bo(15759)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-377.html">RHSA-2005:377</ref></refs><vuln_soft><prod name="sharutils" vendor="GNU"><vers num="4.2"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1773" published="2004-12-31" seq="2004-1773" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200410-01.xml">GLSA-200410-01</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2155">FLSA:2155</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11298">11298</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-377.html">RHSA-2005:377</ref></refs><vuln_soft><prod name="sharutils" vendor="GNU"><vers num="4.2"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-1774" published="2004-08-31" seq="2004-1774" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SDO_CODE_SIZE peocedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/025984.html">20040902 [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server</ref><ref source="MISC" url="http://www.appsecinc.com/resources/alerts/oracle/2004-0001/">http://www.appsecinc.com/resources/alerts/oracle/2004-0001/</ref><ref adv="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref><ref adv="1" patch="1" source="MISC" url="http://www.securiteam.com/securitynews/5CP010KE0W.html">http://www.securiteam.com/securitynews/5CP010KE0W.html</ref><ref source="MISC" url="http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php">http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13145">13145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20078">oracle-mdsysmd2sdocodesize-bo(20078)</ref></refs><vuln_soft><prod name="Oracle10g" vendor="Oracle"><vers num="Enterprise 10.1.0.2"/><vers num="Personal 10.1.0.2"/><vers num="Standard 10.1.0.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1775" published="2004-12-31" seq="2004-1775" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/645400">VU#645400</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/5030">5030</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6179">cisco-snmp-vacm(6179)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0 XW"/><vers num="12.0 XV"/><vers num="12.0 XU"/><vers num="12.0 XS"/><vers num="12.0 XR"/><vers num="12.0 XQ"/><vers num="12.0 XP"/><vers num="12.0 XN"/><vers num="12.0 XM"/><vers num="12.0 XL"/><vers num="12.0 XK"/><vers num="12.0 XJ"/><vers num="12.0 XI"/><vers num="12.0 XH"/><vers num="12.0 XG"/><vers num="12.0 XF"/><vers num="12.0 XE"/><vers num="12.0 XD"/><vers num="12.0 XC"/><vers num="12.0 XB"/><vers num="12.0 XA"/><vers num="12.0 T"/><vers num="12.0 ST"/><vers num="12.0 SL"/><vers num="12.0 SC"/><vers num="12.0 S"/><vers num="12.0 DC"/><vers num="12.0 DB"/><vers num="12.0 DA"/><vers num="12.1 YD"/><vers num="12.1 YC"/><vers num="12.1 YB"/><vers num="12.1 YA"/><vers num="12.1 XZ"/><vers num="12.1 XY"/><vers num="12.1 XX"/><vers num="12.1 XW"/><vers num="12.1 XV"/><vers num="12.1 XU"/><vers num="12.1 XT"/><vers num="12.1 XS"/><vers num="12.1 XR"/><vers num="12.1 XQ"/><vers num="12.1 XP"/><vers num="12.1 XM"/><vers num="12.1 XL"/><vers num="12.1 XK"/><vers num="12.1 XI"/><vers num="12.1 XH"/><vers num="12.1 XG"/><vers num="12.1 XF"/><vers num="12.1 XE"/><vers num="12.1 XD"/><vers num="12.1 XC"/><vers num="12.1 XB"/><vers num="12.1 XA"/><vers num="12.1 T"/><vers num="12.1 EX"/><vers num="12.1 EC"/><vers num="12.1 EA"/><vers num="12.1 E"/><vers num="12.1 DC"/><vers num="12.1 DB"/><vers num="12.1 DA"/><vers num="12.1 CX"/><vers num="12.1 AA"/><vers num="12.1"/></prod><prod name="CatOS" vendor="Cisco"><vers num="5.5"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1776" published="2001-02-28" seq="2004-1776" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/840665">VU#840665</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/6180">cisco-ios-cable-docsis(6180)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1(3)"/><vers num="12.1(3)T"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-08-14" name="CVE-2004-1777" published="2004-12-31" seq="2004-1777" severity="Medium" type="CVE"><desc><descript source="cve">A &quot;range check error&quot; in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.skype.com/security/ssa-2004-01.html">http://www.skype.com/security/ssa-2004-01.html</ref><ref source="BUGTRAQ" url="http://lists.virus.org/bugtraq-0406/msg00221.html">20040615 Skype URI callto username overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/11860">11860</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010490">1010490</ref></refs><vuln_soft><prod name="Skype" vendor="Skype Technologies"><vers num="0.98.0.04"/><vers num="0.98.0.27" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1778" published="2004-12-22" seq="2004-1778" severity="Medium" type="CVE"><desc><descript source="cve">Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110374568916303&amp;w=2">20041222 Permission problem in Skype BETA for linux</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868557905786&amp;w=2">20050216 Re: Permission problem in Skype BETA for linux</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12081">12081</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18644">skype-lang-insecure-permissions(18644)</ref></refs><vuln_soft><prod name="Skype" vendor="Skype Technologies"><vers num="1.0.0.1"/><vers num="0.92.0.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1779" published="2004-12-31" seq="2004-1779" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=207893">http://sourceforge.net/project/shownotes.php?release_id=207893</ref><ref patch="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/thwb/thwb/board.php?r1=1.11&amp;r2=1.12">http://cvs.sourceforge.net/viewcvs.py/thwb/thwb/board.php?r1=1.11&amp;r2=1.12</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9367">9367</ref><ref source="OSVDB" url="http://www.osvdb.org/3330">3330</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1008617">1008617</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10546">10546</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14143">thwboard-board-xss(14143)</ref></refs><vuln_soft><prod name="Thwboard Beta" vendor="Thwboard"><vers num="2.83"/><vers num="2.82"/><vers num="2.81"/><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1780" published="2004-12-31" seq="2004-1780" severity="Medium" type="CVE"><desc><descript source="cve">Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9347">9347</ref></refs><vuln_soft><prod name="Surfnet" vendor="Info Touch"><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1781" published="2004-12-31" seq="2004-1781" severity="Medium" type="CVE"><desc><descript source="cve">Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9348">9348</ref></refs><vuln_soft><prod name="Surfnet" vendor="Info Touch"><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1782" published="2004-12-31" seq="2004-1782" severity="High" type="CVE"><desc><descript source="cve">athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9349">9349</ref><ref source="" url="http://www.threatfinder.com/?page=test_details&amp;back=fresh_tests&amp;id=18376"></ref><ref source="OSVDB" url="http://www.osvdb.org/16861">16861</ref></refs><vuln_soft><prod name="Athena Web Registration" vendor="David Maciejak"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1783" published="2004-12-31" seq="2004-1783" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5FP051FBPQ.html">http://www.securiteam.com/windowsntfocus/5FP051FBPQ.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/9350">9350</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008588">1008588</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10522">10522</ref></refs><vuln_soft><prod name="Flash FTP Server" vendor="Net2Soft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1784" published="2004-01-03" seq="2004-1784" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348818">20040103 Webcam Watchdog Stack Overflow Vulnerability</ref><ref source="MISC" url="http://www.elitehaven.net/webcamwatchdog.txt">http://www.elitehaven.net/webcamwatchdog.txt</ref><ref source="MISC" url="http://www.webcamsoft.com/en/watchdog_h.html">http://www.webcamsoft.com/en/watchdog_h.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9351">9351</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/3312">3312</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10527">10527</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14131">webcam-watchdog-get-bo(14131)</ref></refs><vuln_soft><prod name="Webcam Watchdog" vendor="Webcam Corp"><vers num="1.0"/><vers num="1.1"/><vers num="3.63"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1785" published="2004-01-03" seq="2004-1785" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this-&gt;chosen_month variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348821">20040103 [SCSA-025] Invision Power Board SQL Injection Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9353">9353</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/3319">3319</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10530">10530</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008589">1008589</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2004-1786" published="2004-01-04" seq="2004-1786" severity="Medium" type="CVE"><desc><descript source="cve">PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9354">9354</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1008627">1008627</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14169">portalapp-url-access-database(14169)</ref></refs><vuln_soft><prod name="PortalApp" vendor="Iatek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-1787" published="2004-12-31" seq="2004-1787" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2537">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2537</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9372">9372</ref><ref source="OSVDB" url="http://www.osvdb.org/3336">3336</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1008621">1008621</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10554">10554</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14111">postcalendar-search-sql-injection(14111)</ref></refs><vuln_soft><prod name="PostCalendar" vendor="PostNuke Software Foundation"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1788" published="2004-12-31" seq="2004-1788" severity="Medium" type="CVE"><desc><descript source="cve">ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9355">9355</ref></refs><vuln_soft><prod name="ASP-Nuke" vendor="ASP-Nuke"><vers num="1.0"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1789" published="2004-12-31" seq="2004-1789" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/349085">20040106 ZyXEL10 OF ZyWALL Series Router Cross Site Scripting Vulnerabillity</ref><ref source="BID" url="http://www.securityfocus.com/bid/9373">9373</ref><ref source="OSVDB" url="http://www.osvdb.org/3443">3443</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008644">1008644</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14163">zywall-xss(14163)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10574">10574</ref><ref source="OSVDB" url="http://www.osvdb.org/12793">12793</ref></refs><vuln_soft><prod name="Zywall10" vendor="ZyXEL"><vers num="3.20 WA1"/><vers num="3.20 WA0"/><vers num="3.24 WA2"/><vers num="3.24 WA1"/><vers num="3.24 WA0"/><vers num="3.50 WA2"/><vers num="3.50 WA1"/><vers num="4.07"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1790" published="2004-12-31" seq="2004-1790" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/349089">20040106 EDIMAX AR-6004 Full Rate ADSL Router Cross Site Scripting Vulnerabillity</ref><ref source="BID" url="http://www.securityfocus.com/bid/9374">9374</ref><ref source="OSVDB" url="http://www.osvdb.org/3435">3435</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008643">1008643</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10576">10576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14165">edimax-ar6004-xss(14165)</ref></refs><vuln_soft><prod name="Full Rate ADSL Router" vendor="Edimax"><vers num="AR_6004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1791" published="2004-12-31" seq="2004-1791" severity="High" type="CVE"><desc><descript source="cve">The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/349089">20040106 EDIMAX AR-6004 Full Rate ADSL Router Cross Site Scripting Vulnerabillity</ref><ref source="OSVDB" url="http://www.osvdb.org/3511">3511</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008643">1008643</ref></refs><vuln_soft><prod name="Full Rate ADSL Router" vendor="Edimax"><vers num="AR_6004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1792" published="2004-12-31" seq="2004-1792" severity="Medium" type="CVE"><desc><descript source="cve">swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348693">20040102 Switch Off Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.elitehaven.net/switchoff.txt">http://www.elitehaven.net/switchoff.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9339">9339</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008581">1008581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10521">10521</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14123">switch-off-swnet-dos(14123)</ref></refs><vuln_soft><prod name="Switch Off" vendor="YatSoft"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1793" published="2004-12-31" seq="2004-1793" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348693">20040102 Switch Off Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.elitehaven.net/switchoff.txt">http://www.elitehaven.net/switchoff.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9340">9340</ref><ref source="OSVDB" url="http://www.osvdb.org/3309">3309</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008581">1008581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10521">10521</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14124">switch-off-swnet-bo(14124)</ref></refs><vuln_soft><prod name="Switch Off" vendor="YatSoft"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1794" published="2004-12-31" seq="2004-1794" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0006.html">20040101 Possible XSS vuln in VCard4J</ref><ref source="BID" url="http://www.securityfocus.com/bid/9343">9343</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1008582">1008582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14120">vcard4j-nickname-xss(14120)</ref></refs><vuln_soft><prod name="VCard4J" vendor="VCard4J"><vers num="0.1"/><vers num="0.2"/><vers num="1.0"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1795" published="2004-12-31" seq="2004-1795" severity="Low" type="CVE"><desc><descript source="cve">Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a &apos;file://&apos; URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9346">9346</ref></refs><vuln_soft><prod name="Surfnet" vendor="Info Touch"><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1796" published="2004-12-31" seq="2004-1796" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348840">20040104 HotNews arbitary file inclusion</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=342594">http://sourceforge.net/forum/forum.php?forum_id=342594</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9357">9357</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1008608">1008608</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10551">10551</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14140">hotnews-php-file-include(14140)</ref><ref source="OSVDB" url="http://www.osvdb.org/3332">3332</ref><ref source="OSVDB" url="http://www.osvdb.org/3405">3405</ref></refs><vuln_soft><prod name="HotNews" vendor="HotNews"><vers num="0.5.3"/><vers num="0.6.0 pre"/><vers num="0.6.0"/><vers num="0.6.1"/><vers num="0.7.0"/><vers num="0.7.1"/><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1797" published="2004-12-31" seq="2004-1797" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9359">9359</ref><ref source="OSVDB" url="http://www.osvdb.org/3335">3335</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1008606">1008606</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10547">10547</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14147">freznoshop-searchphp-xss(14147)</ref></refs><vuln_soft><prod name="FreznoShop" vendor="FreznoShop"><vers num="1.0"/><vers num="1.1.0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.3.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-1798" published="2004-12-31" seq="2004-1798" severity="Medium" type="CVE"><desc><descript source="cve">RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the &quot;My Computer&quot; zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a &quot;file:javascript:&quot; URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/349086">20040107 RealNetworks fails to address Cross-Site Scripting in RealOne Player</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9378">9378</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/3826">3826</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008647">1008647</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/9584">9584</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14168">realoneplayer-smil-xss(14168)</ref></refs><vuln_soft><prod name="RealOne Desktop Manager" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/><vers num="6.0.11.868"/><vers num="6.0.11.853"/><vers num="6.0.11.841"/><vers num="6.0.11.830"/><vers num="6.0.11.818"/><vers edition="Gold" num="6.0.10.505"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers num="8.0"/></prod><prod name="RealOne Enterprise Desktop" vendor="RealNetworks"><vers num="6.0.11.774"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1799" published="2004-12-31" seq="2004-1799" severity="High" type="CVE"><desc><descript source="cve">PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107331321302113&amp;w=2">20040105 firewall security bug?</ref><ref source="BID" url="http://www.securityfocus.com/bid/9362">9362</ref><ref source="OSVDB" url="http://www.osvdb.org/19105">19105</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1800" published="2004-12-31" seq="2004-1800" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9380">9380</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008695">1008695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10595">10595</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14206">simpledata-gain-unauth-access(14206)</ref></refs><vuln_soft><prod name="SimpleData" vendor="Sysbotz"><vers num="4.0"/><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1801" published="2004-12-31" seq="2004-1801" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107876388211413&amp;w=2">20040308 directory traversal in PWebServer 0.3.3</ref><ref patch="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/PWebServer0.3.3-adv.txt">http://www.autistici.org/fdonato/advisory/PWebServer0.3.3-adv.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9817">9817</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11057">11057</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15404">pwebserver-dotdot-directory-traversal(15404)</ref></refs><vuln_soft><prod name="PWebServer Web Server" vendor="PWebServer"><vers num="0.3.0"/><vers num="0.3.2"/><vers num="0.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1802" published="2004-12-31" seq="2004-1802" severity="Medium" type="CVE"><desc><descript source="cve">Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/chatany-ghost-adv.txt"></ref><ref patch="1" source="CONFIRM" url="http://www.lionmax.com/chatanywhere.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/9823">9823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15416">chat-anywhere-admin-bypass(15416)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107885946220895&amp;w=2">20040309 Ghost users in Chat Anywhere 2.72</ref></refs><vuln_soft><prod name="Chat Anywhere" vendor="LionMax Software"><vers num="2.72" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1804" published="2004-12-31" seq="2004-1804" severity="Medium" type="CVE"><desc><descript source="cve">wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107894337524376&amp;w=2">20040310 DoS in wMCam server 2.1.348</ref><ref source="BID" url="http://www.securityfocus.com/bid/9839">9839</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15431">wmcam-multiple-connections-dos(15431)</ref></refs><vuln_soft><prod name="wMCam Server" vendor="iNvicta"><vers num="2.1.348"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1805" published="2004-12-31" seq="2004-1805" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/unrfs-adv.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9840">9840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11108">11108</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15430">ut-class-format-string(15430)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893764406905&amp;w=2">20040310 Format string bug in EpicGames Unreal engine</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107902755204583&amp;w=2">20040311 Re: Format string bug in EpicGames Unreal engine</ref></refs><vuln_soft><prod name="Unreal Engine" vendor="Epic Games"><vers num="436"/><vers num="433"/><vers num="226f"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1806" published="2004-12-31" seq="2004-1806" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911090901744&amp;w=2">20040312 Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040312.txt">http://www.s-quadra.com/advisories/Adv-20040312.txt</ref><ref source="MISC" url="http://securitytracker.com/id?1009403">http://securitytracker.com/id?1009403</ref><ref source="BID" url="http://www.securityfocus.com/bid/9854">9854</ref><ref source="OSVDB" url="http://www.osvdb.org/4229">4229</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11112">11112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15447">cfwebstore-index-sql-injection(15447)</ref></refs><vuln_soft><prod name="CFWebstore" vendor="Dogpatch Software"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1807" published="2004-12-31" seq="2004-1807" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911090901744&amp;w=2">20040312 Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040312.txt">http://www.s-quadra.com/advisories/Adv-20040312.txt</ref><ref source="MISC" url="http://securitytracker.com/id?1009403">http://securitytracker.com/id?1009403</ref><ref source="BID" url="http://www.securityfocus.com/bid/9856">9856</ref><ref source="OSVDB" url="http://www.osvdb.org/4230">4230</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11112">11112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15454">cfwebstore-url-xss(15454)</ref></refs><vuln_soft><prod name="CFWebstore" vendor="Dogpatch Software"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1808" published="2004-12-31" seq="2004-1808" severity="Low" type="CVE"><desc><descript source="cve">Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107910934926062&amp;w=2">20040312 Metamail extcompose script Symlink Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9850">9850</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15460">metamail-extcompose-symlink(15460)</ref></refs><vuln_soft><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1809" published="2004-12-31" seq="2004-1809" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107920498205324&amp;w=2">20040313 phpBB 2.0.6d &amp;&amp; Earlier Security Issues</ref><ref source="CONFIRM" url="http://www.phpbb.com/support/documents.php?mode=changelog#206">http://www.phpbb.com/support/documents.php?mode=changelog#206</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9865">9865</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9866">9866</ref><ref source="OSVDB" url="http://www.osvdb.org/4257">4257</ref><ref source="OSVDB" url="http://www.osvdb.org/4259">4259</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11121">11121</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15464">phpbb-viewforum-viewtopic-xss(15464)</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1810" published="2004-12-31" seq="2004-1810" severity="Medium" type="CVE"><desc><descript source="cve">The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936810909082&amp;w=2">20040314 Opera Array Allocation Managment Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/9869">9869</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15413">safari-array-dos(15413)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.22"/><vers num="7.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1811" published="2004-12-31" seq="2004-1811" severity="High" type="CVE"><desc><descript source="cve">The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936784030214&amp;w=2">20040314 Multiple Immunity Advisories</ref><ref adv="1" source="MISC" url="http://www.immunitysec.com/downloads/hp_http.sxw.pdf">http://www.immunitysec.com/downloads/hp_http.sxw.pdf</ref><ref patch="1" source="HP" url="http://www.tru64.org/stories.php?story=04/03/12/0204078">HPSBMA01003</ref><ref patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-100.shtml">O-100</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9859">9859</ref><ref source="COMPAQ" url="http://www.securityfocus.com/advisories/6448">SSRT4679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15466">hp-http-certificate-upload(15466)</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0057.html">20040315 Immunity Advisory: Compaq Web Management vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11126">11126</ref></refs><vuln_soft><prod name="HP SSL HTTP Server" vendor="HP"><vers num="5.0"/><vers num="5.92"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1812" published="2004-12-31" seq="2004-1812" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936784030214&amp;w=2">20040314 Multiple Immunity Advisories</ref><ref source="VULNWATCH" url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2004-03/0008.html">20040315 Immunity Advisory: Computer Associates Unicenter TNG</ref><ref adv="1" source="MISC" url="http://www.immunitysec.com/downloads/awservices.sxw.pdf">http://www.immunitysec.com/downloads/awservices.sxw.pdf</ref><ref adv="1" source="CONFIRM" url="ftp://ftp.ca.com/CAproducts/unicenter/CCS31/nt/qi52764/QI52764.DB0">ftp://ftp.ca.com/CAproducts/unicenter/CCS31/nt/qi52764/QI52764.DB0</ref><ref source="BID" url="http://www.securityfocus.com/bid/9863">9863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11131">11131</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15472">unicentertng-awservices-cam-bo(15472)</ref></refs><vuln_soft><prod name="Unicenter TNG" vendor="Computer Associates"><vers num="2.4"/><vers num="2.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1813" published="2004-12-31" seq="2004-1813" severity="High" type="CVE"><desc><descript source="cve">VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936739131657&amp;w=2">20040315 VocalTec Gateway 8 Reverse Directory Transversal + Authorization Bypass</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15476">vgw48-gateway-directory-traversal(15476)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9876">9876</ref></refs><vuln_soft><prod name="VGW4_8 Telephony Gateway" vendor="VocalTec"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1814" published="2004-12-31" seq="2004-1814" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936739131657&amp;w=2">20040315 VocalTec Gateway 8 Reverse Directory Transversal + Authorization Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/9876">9876</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15476">vgw48-gateway-directory-traversal(15476)</ref></refs><vuln_soft><prod name="VGW4_8 Telephony Gateway" vendor="VocalTec"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1815" published="2004-03-15" seq="2004-1815" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2">20040315 Multiple Vendor SOAP server array DoS</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9877">9877</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11132">11132</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15473">soap-array-dos(15473)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="6.0"/><vers num="6.1"/><vers num="6.0 J2EE"/><vers num="6.1 J2EE"/></prod><prod name="JRun" vendor="Macromedia"><vers num="4.0 SP1a"/><vers num="4.0 SP1"/><vers num="4.0 build 61650"/><vers num="4.0"/></prod><prod name="ONE Application Server" vendor="Sun"><vers edition="Standard" num="7.0 UR2 Upgrade"/><vers edition="Platform" num="7.0 UR2 Upgrade"/><vers edition="Standard" num="7.0 UR2"/><vers edition="Platform" num="7.0 UR2"/><vers edition="Standard" num="7.0 UR1"/><vers edition="Platform" num="7.0 UR1"/><vers edition="Standard" num="7.0"/><vers edition="Platform" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1816" published="2004-03-15" seq="2004-1816" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2">20040315 Multiple Vendor SOAP server array DoS</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57517-1">57517</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9877">9877</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11130">11130</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15473">soap-array-dos(15473)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="6.0"/><vers num="6.1"/><vers num="J2EE 6.0"/><vers num="J2EE 6.1"/></prod><prod name="JRun" vendor="Macromedia"><vers num="4.0 SP1a"/><vers num="4.0 SP1"/><vers num="4.0 build 61650"/><vers num="4.0"/></prod><prod name="ONE Application Server" vendor="Sun"><vers edition="Standard" num="7.0 UR2 Upgrade"/><vers edition="Platform" num="7.0 UR2 Upgrade"/><vers edition="Standard" num="7.0 UR2"/><vers edition="Platform" num="7.0 UR2"/><vers edition="Standard" num="7.0 UR1"/><vers edition="Platform" num="7.0 UR1"/><vers edition="Standard" num="7.0"/><vers edition="Platform" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1817" published="2004-03-15" seq="2004-1817" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937752811633&amp;w=2">20040315 [waraxe-2004-SA#005 - XSS in Php-Nuke 7.1.0 - part 2]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9879">9879</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11135">11135</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15491">phpnuke-multiple-parameters-xss(15491)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1818" published="2004-03-15" seq="2004-1818" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9881">9881</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4293">4293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11134">11134</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15497">4nalbum-nmimagephp-xss(15497)</ref></refs><vuln_soft><prod name="4nAlbum Module" vendor="WarpSpeed"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1819" published="2004-03-15" seq="2004-1819" severity="Medium" type="CVE"><desc><descript source="cve">4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9881">9881</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4291">4291</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11134">11134</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15493">4nalbum-error path-disclosure(15493)</ref></refs><vuln_soft><prod name="4nAlbum Module" vendor="WarpSpeed"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1820" published="2004-03-15" seq="2004-1820" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9881">9881</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4292">4292</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11134">11134</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15496">4nalbum-displaycategory-file-include(15496)</ref></refs><vuln_soft><prod name="4nAlbum Module" vendor="WarpSpeed"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1821" published="2004-03-15" seq="2004-1821" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9881">9881</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4294">4294</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11134">11134</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15498">4nalbum-modulesphp-SQL-injection(15498)</ref></refs><vuln_soft><prod name="4nAlbum Module" vendor="WarpSpeed"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1822" published="2004-03-15" seq="2004-1822" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107939479713136&amp;w=2">20040315 Phorum 5.0.3 Beta &amp;&amp; Earlier XSS Issues</ref><ref adv="1" source="CONFIRM" url="http://phorum.org/changelog.txt">http://phorum.org/changelog.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9882">9882</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11157">11157</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15494">phorum-register-xss(15494)</ref><ref source="OSVDB" url="http://www.osvdb.org/4333">4333</ref><ref source="OSVDB" url="http://www.osvdb.org/4334">4334</ref><ref source="OSVDB" url="http://www.osvdb.org/4335">4335</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009433">1009433</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.1"/><vers num="3.1.1 rc2"/><vers num="3.1.1 pre"/><vers num="3.1.1a"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.2"/><vers num="3.2.2"/><vers num="3.2.3b"/><vers num="3.2.3a"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.2.5"/><vers num="3.2.6"/><vers num="3.2.7"/><vers num="3.2.8"/><vers num="3.3.1a"/><vers num="3.3.1"/><vers num="3.3.2b3"/><vers num="3.3.2a"/><vers num="3.3.2"/><vers num="3.4"/><vers num="3.4.1"/><vers num="3.4.2"/><vers num="3.4.3"/><vers num="3.4.4"/><vers num="3.4.5"/><vers num="3.4.6"/><vers num="5.0.3 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1823" published="2004-12-31" seq="2004-1823" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945556112453&amp;w=2">20040316 JelSoft vBulletin Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9888">9888</ref><ref source="BID" url="http://www.securityfocus.com/bid/9889">9889</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11142">11142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15495">vbulletin-showthread-xss(15495)</ref><ref source="OSVDB" url="http://www.osvdb.org/4310">4310</ref><ref source="OSVDB" url="http://www.osvdb.org/4311">4311</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009440">1009440</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0.0 can4"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1824" published="2004-12-31" seq="2004-1824" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945556112453&amp;w=2">20040316 JelSoft vBulletin Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9887">9887</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11142">11142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15495">vbulletin-showthread-xss(15495)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2002-11/0276.html">20021121 XSS bug in vBulletin</ref><ref source="BID" url="http://www.securityfocus.com/bid/6226">6226</ref><ref source="OSVDB" url="http://www.osvdb.org/4312">4312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009440">1009440</ref><ref source="XF" url="http://www.iss.net/security_center/static/10679.php">vbulletin-memberlist-xss(10679)</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="2.0 beta 3"/><vers num="2.0 beta 2"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9 can"/><vers num="2.3.0"/><vers num="2.3.3"/><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1825" published="2004-03-16" seq="2004-1825" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2">20040316 Mambo Open Source Multiple Vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9890">9890</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/4665">4665</ref><ref source="OSVDB" url="http://www.osvdb.org/4308">4308</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11140">11140</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15499">mambo-return-moschangetemplate-xss(15499)</ref></refs><vuln_soft><prod name="Mambo Open Source" vendor="Mambo"><vers num="4.5_1.0.1"/><vers num="4.5_1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1826" published="2004-03-16" seq="2004-1826" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2">20040316 Mambo Open Source Multiple Vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9891">9891</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/4307">4307</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11140">11140</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15500">mambo-id-sql-injection(15500)</ref></refs><vuln_soft><prod name="Mambo Open Source 4.5" vendor="Mambo"><vers num="1.0.3beta"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-1827" published="2004-03-15" seq="2004-1827" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9873">9873</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11128">11128</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15488">yabb-glow-shadow-xss(15488)</ref><ref source="" url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009427">1009427</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936800226430&amp;w=2">20040314 YaBB/YaBBse Cross Site Scripting Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107948064923981&amp;w=2">20040316 RE: YaBB/YaBBse Cross Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="Simple Machines SMF" vendor="Simple Machines"><vers num="1.0 b"/></prod><prod name="YaBB" vendor="YaBB"><vers num="1 Gold - SP 1.3"/><vers edition="Second Edition" num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1828" published="2004-12-31" seq="2004-1828" severity="Medium" type="CVE"><desc><descript source="cve">Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107957312531199&amp;w=2">20040317 Vcard 2.8 uninstall script problem</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9910">9910</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15522">vcard-uninstall-delete-table(15522)</ref></refs><vuln_soft><prod name="vCard" vendor="Belchior Foundry"><vers num="2.8"/><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1829" published="2004-03-18" seq="2004-1829" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9911">9911</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15529">errormanager-error-xss(15529)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15530">errormanager-error-command-execution(15530)</ref><ref source="OSVDB" url="http://www.osvdb.org/4384">4384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11164">11164</ref></refs><vuln_soft><prod name="PHP-Nuke Module" vendor="Error Manager"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1830" published="2004-03-18" seq="2004-1830" severity="Medium" type="CVE"><desc><descript source="cve">error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref><ref source="BID" url="http://www.securityfocus.com/bid/9911">9911</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15524">errormanager-error-path-disclosure(15524)</ref><ref source="OSVDB" url="http://www.osvdb.org/4386">4386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11164">11164</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1831" published="2004-12-31" seq="2004-1831" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/chrome-boom-adv.txt">http://aluigi.altervista.org/adv/chrome-boom-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9898">9898</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15535">chrome-malloc-memcpy-dos(15535)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107964719614657&amp;w=2">20040318 Chrome 1.2.0.0 server crash</ref></refs><vuln_soft><prod name="Chrome" vendor="Techland"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1832" published="2004-12-31" seq="2004-1832" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107965605008575&amp;w=2">20040318 mac osx- admin service buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107971225327629&amp;w=2">20040319 Re: mac osx- admin service buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15533">macos-admin-servicebo(15533)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9914">9914</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-1833" published="2004-03-20" seq="2004-1833" severity="High" type="CVE"><desc><descript source="cve">The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=80&amp;type=vulnerabilities&amp;flashstatus=true">20040319 Borland Interbase admin.ib Administrative Access Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9929">9929</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4381">4381</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009500">1009500</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11172">11172</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15546">interbase-admin-gain-privileges(15546)</ref></refs><vuln_soft><prod name="Interbase" vendor="Borland Software"><vers num="4.0"/><vers num="5.0"/><vers num="6.0"/><vers num="6.4"/><vers num="6.5"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1834" published="2004-03-20" seq="2004-1834" severity="Low" type="CVE"><desc><descript source="cve">mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107981737322495&amp;w=2">20040319 Apache mod_disk_cache stores client authentication credentials on disk</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9933">9933</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4446">4446</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009509">1009509</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11176">11176</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15547">apache-moddiskcache-obtain-info(15547)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-562.html">RHSA-2004:562</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28 Beta"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/><vers num="2.0.49"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1835" published="2004-12-31" seq="2004-1835" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997906500032&amp;w=2">20040322 Invision Gallery SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9944">9944</ref><ref source="OSVDB" url="http://www.osvdb.org/4472">4472</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009512">1009512</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11194">11194</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15566">invision-gallery-sql-injection(15566)</ref></refs><vuln_soft><prod name="Invision Gallery" vendor="Invision Power Services"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1836" published="2004-12-31" seq="2004-1836" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997924117652&amp;w=2">20040322 Invision Power Top Site List SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9945">9945</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009511">1009511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11187">11187</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15568">invision-id-sql-injection(15568)</ref></refs><vuln_soft><prod name="Invision Power Top Site List" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.1 RC2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1837" published="2004-12-31" seq="2004-1837" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997967421972&amp;w=2">20040322 Mod_Survey security advisory: Script injection bug</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9941">9941</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009516">1009516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15582">modsurvey-xss(15582)</ref></refs><vuln_soft><prod name="Mod_Survey" vendor="Joel Palmius"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0.0"/><vers num="3.0.9"/><vers num="3.0.11"/><vers num="3.0.12"/><vers num="3.0.13"/><vers num="3.0.14e"/><vers num="3.0.14d"/><vers num="3.0.14"/><vers num="3.0.15 pre6"/><vers num="3.0.15 pre5"/><vers num="3.0.15 pre4"/><vers num="3.0.15 pre3"/><vers num="3.0.15 pre2"/><vers num="3.0.15 pre1"/><vers num="3.0.15"/><vers num="3.0.16 pre1"/><vers num="3.2.0 pre3"/><vers num="3.2.0 pre2"/><vers num="3.2.0 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1838" published="2004-03-22" seq="2004-1838" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997946623770&amp;w=2">20040322 directory traversal in xweb 1.0</ref><ref adv="1" patch="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt">http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9937">9937</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4460">4460</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009514">1009514</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11186">11186</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15567">xweb-dotdot-directory-traversal(15567)</ref></refs><vuln_soft><prod name="XWeb" vendor="XWeb"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1839" published="2004-03-22" seq="2004-1839" severity="Medium" type="CVE"><desc><descript source="cve">MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9946">9946</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.5"/><vers num="6.5 Beta1"/><vers num="6.5 FINAL"/><vers num="6.5 RC1"/><vers num="6.5 RC2"/><vers num="6.5 RC3"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0"/><vers num="7.0 FINAL"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1840" published="2004-03-22" seq="2004-1840" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9947">9947</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15575">msanalysis-modules-title-xss(15575)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.5"/><vers num="6.5 Beta1"/><vers num="6.5 FINAL"/><vers num="6.5 RC1"/><vers num="6.5 RC2"/><vers num="6.5 RC3"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0"/><vers num="7.0 FINAL"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1841" published="2004-12-31" seq="2004-1841" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref><ref source="BID" url="http://www.securityfocus.com/bid/9948">9948</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15576">msanalysis-referer-sql-injection(15576)</ref></refs><vuln_soft><prod name="Website Traffic Analyzer" vendor="MS_Analysis"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1842" published="2004-12-31" seq="2004-1842" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006309112075&amp;w=2">20040322 [waraxe-2004-SA#008 - easy way to get superadmin rights in PhpNuke 6.x-7.1.0]</ref><ref source="BID" url="http://www.securityfocus.com/bid/9895">9895</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11195">11195</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15596">phpnuke-img-gain-privileges(15596)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1843" published="2004-03-20" seq="2004-1843" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999697625786&amp;w=2">20040322 Vulnerabilities in Member Management System 2.1</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9931">9931</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009508">1009508</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11179">11179</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15551">mms-id-sql-injection(15551)</ref></refs><vuln_soft><prod name="Member Management System" vendor="Expinion.net"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1844" published="2004-12-31" seq="2004-1844" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999697625786&amp;w=2">20040322 Vulnerabilities in Member Management System 2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/9932">9932</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009508">1009508</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11179">11179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15552">mms-xss(15552)</ref></refs><vuln_soft><prod name="Member Management System" vendor="Expinion.net"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1845" published="2004-12-31" seq="2004-1845" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref><ref source="BID" url="http://www.securityfocus.com/bid/9935">9935</ref><ref source="OSVDB" url="http://www.osvdb.org/4492">4492</ref><ref source="OSVDB" url="http://www.osvdb.org/4493">4493</ref><ref source="OSVDB" url="http://www.osvdb.org/4494">4494</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009507">1009507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11180">11180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15548">news-manager-xss(15548)</ref></refs><vuln_soft><prod name="News Manager Lite" vendor="Expinion.net"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1846" published="2004-03-20" seq="2004-1846" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9935">9935</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4495">4495</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4496">4496</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4497">4497</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009507">1009507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11180">11180</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15549">news-manager-sql-injection(15549)</ref></refs><vuln_soft><prod name="News Manager Lite" vendor="Expinion.net"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1847" published="2004-03-20" seq="2004-1847" severity="High" type="CVE"><desc><descript source="cve">News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9935">9935</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009507">1009507</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11180">11180</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15550">news-manager-admin-access(15550)</ref></refs><vuln_soft><prod name="News Manager Lite" vendor="Expinion.net"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-05-21" name="CVE-2004-1848" published="2004-12-31" seq="2004-1848" severity="Medium" type="CVE"><desc><descript source="cve">Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006717731989&amp;w=2">20040323 How to crash a harddisk - the Ipswitch WS_FTP Server way</ref><ref source="BID" url="http://www.securityfocus.com/bid/9953">9953</ref><ref source="OSVDB" url="http://www.osvdb.org/4542">4542</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11206">11206</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009529">1009529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15560">wsftp-rest-dos(15560)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41831">wsftp-rest-stor-dos(41831)</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="3.0 1"/><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.4"/><vers num="4.0.2"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1849" published="2004-03-24" seq="2004-1849" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006627005371&amp;w=2">20040323 More Cpanel Vuls (cross site scripting)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9965">9965</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4529">4529</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4530">4530</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009541">1009541</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15517">cpanel-dodelautores-addhandle-xss(15517)</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1850" published="2004-03-23" seq="2004-1850" severity="Medium" type="CVE"><desc><descript source="cve">The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/ragefreeze-adv.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9961">9961</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009540">1009540</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15584">therage-packet-dos(15584)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006680013576&amp;w=2">20040323 Server freeze in The Rage 1.01</ref></refs><vuln_soft><prod name="The Rage" vendor="FluidGames"><vers num="1.0 1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1851" published="2004-03-24" seq="2004-1851" severity="High" type="CVE"><desc><descript source="cve">Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2">20030323 Dameware Passes Weak File Encryption Key in the Clear</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9957">9957</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4547">4547</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009557">1009557</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11205">11205</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15587">dameware-random-generator-weak(15587)</ref></refs><vuln_soft><prod name="Mini Remote Control Server" vendor="DameWare Development"><vers num="4.1 .0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1852" published="2004-03-23" seq="2004-1852" severity="Medium" type="CVE"><desc><descript source="cve">DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2">20040323 Dameware Passes Weak File Encryption Key in the Clear</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.dameware.com/support/security/bulletin.asp?ID=SB3">http://www.dameware.com/support/security/bulletin.asp?ID=SB3</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9959">9959</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4547">4547</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009557">1009557</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11205">11205</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15586">dameware-encryption-key-plaintext(15586)</ref></refs><vuln_soft><prod name="Mini Remote Control Server" vendor="DameWare Development"><vers num="3.70 .0.0"/><vers num="3.71 .0.0"/><vers num="3.72 .0.0"/><vers num="3.73 .0.0"/><vers num="4.0"/><vers num="4.1 .0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1853" published="2004-03-19" seq="2004-1853" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/t3cbof-adv.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9918">9918</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4447">4447</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009498">1009498</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11182">11182</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15542">terminator3-bo(15542)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016076221855&amp;w=2">20040323 Broadcast client buffer-overflow in Terminator 3 1.0</ref></refs><vuln_soft><prod name="Terminator 3 War of the Machines" vendor="Atari"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1854" published="2004-03-24" seq="2004-1854" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/picobof-adv.txt"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9969">9969</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4550">4550</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009551">1009551</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11209">11209</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15595">picophone-logging-function-bo(15595)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016032220647&amp;w=2">20040324 Buffer overflow in PicoPhone 1.63</ref></refs><vuln_soft><prod name="Internet Telephone" vendor="Picophone"><vers num="1.63"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1855" published="2004-03-23" seq="2004-1855" severity="Medium" type="CVE"><desc><descript source="cve">Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016932816707&amp;w=2">20040324 Dark Age of Camelot login client vulnerability to man in the middle</ref><ref source="FULLDISC" url="http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html">20040323 Dark Age of Camelot login client vulnerability to man in the middle attack</ref><ref adv="1" source="MISC" url="http://capnbry.net/daoc/advisory20040323/">http://capnbry.net/daoc/advisory20040323/</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9960">9960</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15597">daoc-login-mitm(15597)</ref></refs><vuln_soft><prod name="Dark Age of Camelot" vendor="Mythic Entertainment"><vers num="1.60"/><vers num="1.61"/><vers num="1.62"/><vers num="1.63"/><vers num="1.65"/><vers num="1.66"/><vers num="1.67"/><vers num="1.68"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1856" published="2004-03-24" seq="2004-1856" severity="Medium" type="CVE"><desc><descript source="cve">devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2">20040324 HP Web JetAdmin vulnerabilities.</ref><ref adv="1" source="MISC" url="http://sh0dan.org/files/hpjadmadv.txt">http://sh0dan.org/files/hpjadmadv.txt</ref><ref source="HP" url="http://www.securityfocus.com/advisories/6492">SSRT4700</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9971">9971</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15605">hp-jetadmin-file-upload(15605)</ref></refs><vuln_soft><prod name="Web Jetadmin" vendor="HP"><vers num="7.5.2546"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1857" published="2004-03-24" seq="2004-1857" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2">20040324 HP Web JetAdmin vulnerabilities.</ref><ref adv="1" source="HP" url="http://www.securityfocus.com/advisories/6492">SSRT4700</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9972">9972</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15606">hp-jetadmin-setinfo-directory-traversal(15606)</ref></refs><vuln_soft><prod name="Web Jetadmin" vendor="HP"><vers num="7.5.2546"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1858" published="2004-12-31" seq="2004-1858" severity="Medium" type="CVE"><desc><descript source="cve">HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the &quot;$&quot; character.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2">20040324 HP Web JetAdmin vulnerabilities.</ref><ref source="HP" url="http://www.securityfocus.com/advisories/6492">SSRT4700</ref></refs><vuln_soft><prod name="Web Jetadmin" vendor="HP"><vers num="7.5.2546"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1859" published="2004-03-24" seq="2004-1859" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108014604529316&amp;w=2">20040324 TrendMacro Interscan Viruswall Directory Traversal</ref><ref adv="1" patch="1" source="CONFIRM" url="http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257">http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9966">9966</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4549">4549</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009550">1009550</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11215">11215</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15590">interscan-dotdot-directory-traversal(15590)</ref></refs><vuln_soft><prod name="InterScan VirusWall for Windows NT" vendor="Trend Micro"><vers num="3.4"/><vers num="3.5"/><vers num="3.6"/><vers num="3.51"/><vers num="3.52 build1466"/><vers num="3.52"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1860" published="2004-12-31" seq="2004-1860" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code via a large filter on a column when using SmartView Tracker.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023281112510&amp;w=2">20040325 Check Point SmartDashboard Buffer Overflow</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Mar/1009490.html">http://www.securitytracker.com/alerts/2004/Mar/1009490.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15539">fw1-smartdashboard-bo(15539)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009490">1009490</ref><ref source="BID" url="http://www.securityfocus.com/bid/9870">9870</ref><ref source="OSVDB" url="http://www.osvdb.org/4412">4412</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP3"/><vers num="1.9 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1861" published="2004-03-25" seq="2004-1861" severity="Medium" type="CVE"><desc><descript source="cve">Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032304932321&amp;w=2">20040326 NetSupport School Pro: Password Encryption Weaknesses</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9981">9981</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15621">netsupportschoolpro-weak-encryption(15621)</ref></refs><vuln_soft><prod name="NetSupport School" vendor="NetSupport"><vers num="7.0 1"/><vers num="7.0"/><vers num="7.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1862" published="2004-03-26" seq="2004-1862" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9983">9983</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15654">xmb-forum-multiple-xss(15654)</ref><ref source="OSVDB" url="http://osvdb.org/14983">14983</ref><ref source="OSVDB" url="http://osvdb.org/14985">14985</ref><ref source="OSVDB" url="http://osvdb.org/14986">14986</ref><ref source="OSVDB" url="http://osvdb.org/14987">14987</ref><ref source="OSVDB" url="http://osvdb.org/14988">14988</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11230">11230</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP3"/><vers num="1.9 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-1863" published="2004-12-31" seq="2004-1863" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]</ref><ref source="BID" url="http://www.securityfocus.com/bid/9983">9983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15654">xmb-forum-multiple-xss(15654)</ref><ref source="OSVDB" url="http://www.osvdb.org/14982">14982</ref><ref source="OSVDB" url="http://www.osvdb.org/14989">14989</ref><ref source="OSVDB" url="http://www.osvdb.org/14991">14991</ref><ref source="OSVDB" url="http://www.osvdb.org/16884">16884</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP3"/><vers num="1.9 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1864" published="2004-03-26" seq="2004-1864" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2004/Mar/1009561.html">http://www.securitytracker.com/alerts/2004/Mar/1009561.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9983">9983</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15655">xmb-forum-sql-injection(15655)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009561">1009561</ref><ref source="OSVDB" url="http://www.osvdb.org/16886">16886</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.8 SP3"/><vers num="1.9 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1865" published="2004-03-26" seq="2004-1865" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname).  NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034226717745&amp;w=2">20040326 bblog 0.7.2 cross site scripting</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1009564">1009564</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15635">bblog-name-xss(15635)</ref><ref source="BID" url="http://www.securityfocus.com/bid/13397">13397</ref><ref source="OSVDB" url="http://www.osvdb.org/10510">10510</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1866" published="2004-03-26" seq="2004-1866" severity="Medium" type="CVE"><desc><descript source="cve">nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034249916453&amp;w=2">20040326 Nstxd vulnerability</ref><ref patch="1" source="CONFIRM" url="http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz">http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9989">9989</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009567">1009567</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15638">nstx-null-dos(15638)</ref></refs><vuln_soft><prod name="IP Over DNS Utility" vendor="Nstx"><vers num="1.0"/><vers num="1.1 beta3"/><vers num="1.1 beta2"/><vers num="1.1 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1867" published="2004-12-31" seq="2004-1867" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057935827431&amp;w=2">20040328 vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/9995">9995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15649">freshguestbook-guest-xss(15649)</ref></refs><vuln_soft><prod name="Fresh Guest Book" vendor="Web Fresh"><vers num="2.0"/><vers num="2.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1868" published="2004-03-25" seq="2004-1868" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108025234317408&amp;w=2">20040325 eSignal v7 remote buffer overflow (exploit)</ref><ref adv="1" source="MISC" url="http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt">http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt</ref><ref patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0056.html">20040406 Re: eSignal v7 remote buffer overflow</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9978">9978</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11222">11222</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15624">esignal-specs-bo(15624)</ref></refs><vuln_soft><prod name="eSignal" vendor="eSignal"><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1869" published="2004-12-31" seq="2004-1869" severity="Medium" type="CVE"><desc><descript source="cve">Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/ethboom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/9979">9979</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15618">etherlords1-packet-dos(15618)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15619">etherlords2-packet-dos(15619)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024309814423&amp;w=2">20040325 Remote crash in Etherlords I 1.07 and II 1.03</ref></refs><vuln_soft><prod name="Etherlords" vendor="Nival Interactive"><vers num="1.0 7"/><vers num="1.0 6"/><vers num="1.0 5"/><vers num="1.0 4"/><vers num="1.0 3"/><vers num="1.0 2"/><vers num="1.0 1"/><vers num="1.0"/></prod><prod name="Etherlords II" vendor="Nival Interactive"><vers num="1.0 3"/><vers num="1.0 2"/><vers num="1.0 1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-1870" published="2004-03-29" seq="2004-1870" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users&apos; passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009571">http://securitytracker.com/id?1009571</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9994">9994</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11241">11241</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15642">photopost-php-sql-injection(15642)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/><vers num="4.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-1871" published="2004-03-29" seq="2004-1871" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009571">http://securitytracker.com/id?1009571</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9994">9994</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11241">11241</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15643">photopost-php-xss(15643)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/><vers num="4.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-2004-1872" published="2004-03-29" seq="2004-1872" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057915916365&amp;w=2">20040329 WebCT Campus Edition 4.1 - Cross site scripting using CSS @import</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9999">9999</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11242">11242</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15652">webct-import-xss(15652)</ref></refs><vuln_soft><prod name="WebCT" vendor="WebCT"><vers num="Campus 3.8"/><vers num="Campus 3.8.4"/><vers num="Campus 4.0"/><vers num="Campus 4.1"/><vers num="Campus 4.1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1873" published="2004-12-31" seq="2004-1873" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057887008983&amp;w=2">20040329 A-CART Pro &amp; A-CART 2.0 Input Validation Holes</ref><ref source="BID" url="http://www.securityfocus.com/bid/9997">9997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11236">11236</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15661">acart-categoryasp-sql-injection(15661)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452005/100/0/threaded">20061118 A-Cart 2.0 SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451594/100/100/threaded">20061114 A-Cart pro[ injection sql (post&amp;get)]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452006/100/0/threaded">20061118 A-Cart PRO SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452023/100/0/threaded">20061118 Re: A-Cart PRO SQL Injection</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=31"></ref><ref source="" url="http://s-a-p.ca/index.php?page=OurAdvisories&amp;id=27"></ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=32"></ref></refs><vuln_soft><prod name="A-Cart" vendor="Alan Ward"><vers num="2.0"/><vers edition="Pro" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1874" published="2004-03-29" seq="2004-1874" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057887008983&amp;w=2">20040329 A-CART Pro &amp; A-CART 2.0 Input Validation Holes</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9997">9997</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11236">11236</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15660">acart-deliverasp-billingasp-xss(15660)</ref></refs><vuln_soft><prod name="A-Cart" vendor="Alan Ward"><vers num="2.0"/><vers edition="Pro" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-1875" published="2004-03-30" seq="2004-1875" severity="High" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html.  NOTE: the dnslook.html vector was later reported to exist in cPanel 10.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066561608676&amp;w=2">20040330 Exensive cPanel Cross Site Scripting</ref><ref adv="1" patch="1" source="MISC" url="http://www.cirt.net/advisories/cpanel_xss.shtml">http://www.cirt.net/advisories/cpanel_xss.shtml</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10002">10002</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4208">4208</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4209">4209</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4210">4210</ref><ref source="OSVDB" url="http://www.osvdb.org/4211">4211</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4212">4212</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4213">4213</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4214">4214</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4215">4215</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/4243">4243</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11244">11244</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15671">cpanel-multiple-scripts-xss(15671)</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=30"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21142">21142</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4658">ADV-2006-4658</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22984">22984</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="9.1.0 R85"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1876" published="2004-03-30" seq="2004-1876" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;%f&quot; feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066864608615&amp;w=2">20040330 clamd - NEVER use </ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-03.xml">GLSA-200405-03</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10007">10007</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11253">11253</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15692">clamantivirus-virusevent-gain-privileges(15692)</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.60"/><vers num="0.65"/><vers num="0.67"/><vers num="0.68.1"/><vers num="0.68"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1877" published="2004-03-30" seq="2004-1877" severity="Low" type="CVE"><desc><descript source="cve">The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067040722235&amp;w=2">20040330 Problem with customized login pages for Oracle SSO</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10009">10009</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15676">oracle-sso-login-spoofing(15676)</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="8.1.7"/><vers num="9.0.1"/><vers num="9.2 .0"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2"/><vers num="1.0.2.1s"/><vers num="1.0.2.2"/><vers num="1.0.2.2.2"/><vers num="9.0.2"/><vers num="9.0.2.0.0"/><vers num="9.0.2.0.1"/><vers num="9.0.2.1"/><vers num="9.0.2.2"/><vers num="9.0.2 .3"/><vers num="9.0.3"/><vers num="9.0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1878" published="2004-03-30" seq="2004-1878" severity="Medium" type="CVE"><desc><descript source="cve">LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067245401673&amp;w=2">20040330 Linbit linbox Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.websec.org/adv/linbit.txt.html">http://www.websec.org/adv/linbit.txt.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10010">10010</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11264">11264</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15677">linbox-slashslash-security-bypass(15677)</ref></refs><vuln_soft><prod name="LINBOX Officeserver" vendor="LinBit Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1879" published="2004-12-31" seq="2004-1879" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067894822358&amp;w=2">20040330 phpkit suffers (reale stupid) XSS vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/10013">10013</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15681">phpkit-forum-message-xss(15681)</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers num="1.6.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1880" published="2004-12-31" seq="2004-1880" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685">CLSA-2003:685</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/9203">9203</ref><ref patch="1" source="" url="http://www.securityfocus.com/archive/1/359106"></ref><ref source="OSVDB" url="http://www.osvdb.org/17000">17000</ref></refs><vuln_soft><prod name="OpenLDAP" vendor="OpenLDAP"><vers num="2.1.12"/><vers num="2.1.11"/><vers num="2.1.10"/><vers num="2.1.9"/><vers num="2.1.8"/><vers num="2.1.7"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/><vers num="2.0.15"/><vers num="2.0.16"/><vers num="2.0.17"/><vers num="2.0.18"/><vers num="2.0.19"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.24"/><vers num="2.0.25"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1881" published="2004-12-31" seq="2004-1881" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075059013762&amp;w=2">20040331 CactuSoft CactuShop v5.x shopping cart software multiple security</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040331.txt">http://www.s-quadra.com/advisories/Adv-20040331.txt</ref><ref source="MISC" url="http://securitytracker.com/id?1009601">http://securitytracker.com/id?1009601</ref><ref source="BID" url="http://www.securityfocus.com/bid/10019">10019</ref><ref source="OSVDB" url="http://www.osvdb.org/4785">4785</ref><ref source="OSVDB" url="http://www.osvdb.org/4786">4786</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11272">11272</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15686">cactushop-multiple-sql-injection(15686)</ref></refs><vuln_soft><prod name="CactuShop" vendor="CactuSoft"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1882" published="2004-12-31" seq="2004-1882" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075059013762&amp;w=2">20040331 CactuSoft CactuShop v5.x shopping cart software multiple security</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/019566.html">2004031 CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10020">10020</ref><ref source="OSVDB" url="http://www.osvdb.org/4787">4787</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11272">11272</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15687">cactushop-popularlargeimageasp-xss(15687)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009601">1009601</ref></refs><vuln_soft><prod name="CactuShop" vendor="CactuSoft"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-1883" published="2004-12-31" seq="2004-1883" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006553222397&amp;w=2">20040323 ALLO ALLO WS_FTP Server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/358361">20040323 Think of the buffers! Wont somebody think of the buffers?!</ref><ref source="BID" url="http://www.securityfocus.com/bid/9953">9953</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11206">11206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15561">wsftp-allo-bo(15561)</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1884" published="2004-03-23" seq="2004-1884" severity="High" type="CVE"><desc><descript source="cve">Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006581418116&amp;w=2">20040323 Open the WS_FTP Server backdoor to SYSTEM</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9953">9953</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11206">11206</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15558">wftp-site-gain-priviliege(15558)</ref></refs><vuln_soft><prod name="WS_FTP Pro" vendor="Ipswitch"><vers num="6.0"/><vers num="7.5"/><vers num="8.0 3"/><vers num="8.0 2"/></prod><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="3.0 1"/><vers num="3.0"/><vers num="3.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.4"/><vers num="4.0.2"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1885" published="2004-12-31" seq="2004-1885" severity="High" type="CVE"><desc><descript source="cve">Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006581418116&amp;w=2">20040323 Open the WS_FTP Server backdoor to SYSTEM</ref><ref source="BID" url="http://www.securityfocus.com/bid/9953">9953</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11206">11206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15558">wftp-site-gain-priviliege(15558)</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0 incomplete approximation" modified="2008-05-21" name="CVE-2004-1886" published="2004-03-23" reject="1" seq="2004-1886" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1848.  Reason: This candidate is a duplicate of CVE-2004-1848.  Notes: All CVE users should reference CVE-2004-1848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1887" published="2004-12-31" seq="2004-1887" severity="Medium" type="CVE"><desc><descript source="cve">Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108083813528255&amp;w=2">20040401 Index viewing in imgSvr 0.4</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/imgSvr0.4-adv.txt">http://www.autistici.org/fdonato/advisory/imgSvr0.4-adv.txt</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=230023">http://sourceforge.net/project/shownotes.php?release_id=230023</ref><ref source="BID" url="http://www.securityfocus.com/bid/10026">10026</ref><ref source="BID" url="http://www.securityfocus.com/bid/10027">10027</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11277">11277</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15706">imgsvr-obtain-information(15706)</ref></refs><vuln_soft><prod name="ImgSvr" vendor="ADA"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1888" published="2004-12-31" seq="2004-1888" severity="High" type="CVE"><desc><descript source="cve">display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108100973820868&amp;w=2">20040403 Remote Exploit for Aboriors Encore Web Forum</ref><ref source="BID" url="http://www.securityfocus.com/bid/10040">10040</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15725">encore-display-command-execution(15725)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437813/100/0/threaded">20060620 display.cgi</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437978/100/0/threaded">20060621 Re: display.cgi</ref><ref source="OSVDB" url="http://www.osvdb.org/16831">16831</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1009652">1009652</ref></refs><vuln_soft><prod name="Encore Web Forum" vendor="Aborior"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1889" published="2004-12-31" seq="2004-1889" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc">20040401-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/10037">10037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15722">irix-ftpd-link-dos(15722)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22"/><vers num="6.5.23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1890" published="2004-04-02" seq="2004-1890" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc">20040401-01-P</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10037">10037</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15723">irix-ftpd-port-dos(15723)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22"/><vers num="6.5.23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1891" published="2004-12-31" seq="2004-1891" severity="Medium" type="CVE"><desc><descript source="cve">The ftp_syslog function in ftpd in SGI IRIX 6.5.20 &quot;doesn&apos;t work with anonymous FTP,&quot; which has an unknown impact, possibly preventing the actions of anonymous users from being logged.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc">20040401-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1892" published="2004-12-31" seq="2004-1892" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108100987429960&amp;w=2">20040403 eMule v0.42d Buffer Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.emule-project.net/home/perl/news.cgi?l=1&amp;cat_id=22">http://www.emule-project.net/home/perl/news.cgi?l=1&amp;cat_id=22</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10039">10039</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11289">11289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15730">emule-decodebase16-bo(15730)</ref></refs><vuln_soft><prod name="Emule" vendor="Emule"><vers num="0.42d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1893" published="2004-12-31" seq="2004-1893" severity="Medium" type="CVE"><desc><descript source="cve">Dreamweaver MX, when &quot;Using Driver On Testing Server&quot; or &quot;Using DSN on Testing Server&quot; is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.nextgenss.com/advisories/dreamweaver.txt">http://www.nextgenss.com/advisories/dreamweaver.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108102481929451&amp;w=2">20040403 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]</ref><ref adv="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html">http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/10036">10036</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11284">11284</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15721">dreamweaver-test-script-sql-injection(15721)</ref></refs><vuln_soft><prod name="Dreamweaver MX" vendor="Macromedia"><vers num="2004"/><vers num="6.0"/><vers num="6.1"/></prod><prod name="Dreamweaver Ultradev" vendor="Macromedia"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1894" published="2004-12-31" seq="2004-1894" severity="Low" type="CVE"><desc><descript source="cve">TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118755923319&amp;w=2">20040404 Texutil symlink vulnerability.</ref><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019777.html">20040404 Texutil symlink vulnerability.</ref><ref source="MISC" url="http://securitytracker.com/id?1009661">http://securitytracker.com/id?1009661</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10042">10042</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15728">texutil-symlink-attack(15728)</ref></refs><vuln_soft><prod name="ConTeXt" vendor="PRAGMA ADE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-1895" published="2004-12-31" seq="2004-1895" severity="Low" type="CVE"><desc><descript source="cve">YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118395519164&amp;w=2">20040405 SuSEs YaST Online Update - possible symlink attack</ref><ref source="MISC" url="http://securitytracker.com/id?1009668">http://securitytracker.com/id?1009668</ref><ref source="BID" url="http://www.securityfocus.com/bid/10047">10047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11300">11300</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15731">suse-you-symlink(15731)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0058.html">20040406 Re: SuSEs YaST Online Update - possible symlink attack</ref><ref source="OSVDB" url="http://www.osvdb.org/4985">4985</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1896" published="2004-12-31" seq="2004-1896" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118289208693&amp;w=2">20040405 NGSSoftware Insight Security Research Advisory</ref><ref patch="1" source="MISC" url="http://www.nextgenss.com/advisories/winampheap.txt">http://www.nextgenss.com/advisories/winampheap.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10045">10045</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11285">11285</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15727">winamp-inmod-bo(15727)</ref><ref source="OSVDB" url="http://www.osvdb.org/4944">4944</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009660">1009660</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="2.91"/><vers num="3.0"/><vers num="3.1"/><vers num="5.0.2"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1897" published="2004-12-31" seq="2004-1897" severity="Medium" type="CVE"><desc><descript source="cve">Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2">20040405 Advisory: Multiple Vulnerabilities in Monit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10051">10051</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11304">11304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15734">monit-basic-auth-dos(15734)</ref></refs><vuln_soft><prod name="Monit" vendor="TildeSlash"><vers num="1.4"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.2"/><vers num="4.3 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1898" published="2004-12-31" seq="2004-1898" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2">20040405 Advisory: Multiple Vulnerabilities in Monit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10051">10051</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11304">11304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15735">monit-offbyone-bo(15735)</ref><ref source="OSVDB" url="http://www.osvdb.org/4981">4981</ref></refs><vuln_soft><prod name="Monit" vendor="TildeSlash"><vers num="1.4"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.2"/><vers num="4.3 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1899" published="2004-12-31" seq="2004-1899" severity="Medium" type="CVE"><desc><descript source="cve">The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2">20040405 Advisory: Multiple Vulnerabilities in Monit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10051">10051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11304">11304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15736">monit-post-offbyone-bo(15736)</ref><ref source="OSVDB" url="http://www.osvdb.org/4979">4979</ref></refs><vuln_soft><prod name="Monit" vendor="TildeSlash"><vers num="1.4"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.2"/><vers num="4.3 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1900" published="2004-12-31" seq="2004-1900" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108120385811815&amp;w=2">20040405 Format string bug in IGI 2: Covert Strike 1.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/10053">10053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11299">11299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15742">igi2covertstrike-rcon-format-string(15742)</ref><ref source="" url="http://aluigi.altervista.org/adv/igi2fs-adv.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/4966">4966</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009667">1009667</ref></refs><vuln_soft><prod name="I.G.I-2 Covert Strike" vendor="Pan Vision"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1901" published="2004-12-31" seq="2004-1901" severity="Medium" type="CVE"><desc><descript source="cve">Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/><env/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-01.xml">GLSA-200404-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10060">10060</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11305">11305</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15754">portage-lockfile-hardlink(15754)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1902" published="2004-12-31" seq="2004-1902" severity="Low" type="CVE"><desc><descript source="cve">The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108127948610311&amp;w=2">20040406 Foundstone Labs Advisory: Citrix MetaFrame Password Manager 2.0</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?entryID=4062&amp;categoryID=256">http://support.citrix.com/kb/entry.jspa?entryID=4062&amp;categoryID=256</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10049">10049</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11293">11293</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15737">metaframe-wizard-info-disclosure(15737)</ref><ref source="OSVDB" url="http://www.osvdb.org/4942">4942</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009659">1009659</ref></refs><vuln_soft><prod name="MetaFrame Password Manager" vendor="Citrix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1903" published="2004-12-31" seq="2004-1903" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108127833002955&amp;w=2">20040406 blaxxun3D(blaxxun Platform) 7 - Remote Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/10064">10064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15625">blaxxun-applicationxcc3d-bo(15625)</ref></refs><vuln_soft><prod name="Contact 3D" vendor="Blaxxun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1904" published="2004-12-31" seq="2004-1904" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108130573130482&amp;w=2">20040406 Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S)</ref><ref source="MISC" url="http://theinsider.deep-ice.com/texts/advisory53.txt">http://theinsider.deep-ice.com/texts/advisory53.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/10065">10065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11312">11312</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15764">panda-activescan-ascontrol-bo(15764)</ref></refs><vuln_soft><prod name="ActiveScan" vendor="Panda"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1905" published="2004-12-31" seq="2004-1905" severity="Medium" type="CVE"><desc><descript source="cve">ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108130573130482&amp;w=2">20040406 Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S)</ref><ref source="MISC" url="http://theinsider.deep-ice.com/texts/advisory53.txt">http://theinsider.deep-ice.com/texts/advisory53.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/10067">10067</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15831">panda-activescan-ascontrol-dos(15831)</ref></refs><vuln_soft><prod name="ActiveScan" vendor="Panda"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1906" published="2004-12-31" seq="2004-1906" severity="Medium" type="CVE"><desc><descript source="cve">Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136872711898&amp;w=2">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019877.html">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref><ref source="MISC" url="http://theinsider.deep-ice.com/texts/advisory54.txt">http://theinsider.deep-ice.com/texts/advisory54.txt</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html">20040407 Symantec, McAfee and Panda ActiveX controls</ref><ref source="BID" url="http://www.securityfocus.com/bid/10071">10071</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11313">11313</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15772">freescan-mcfscan-bo(15772)</ref></refs><vuln_soft><prod name="FreeScan" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1907" published="2004-12-31" seq="2004-1907" severity="Low" type="CVE"><desc><descript source="cve">The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing &quot;%13%12%13&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0061.html">20040406 Kerio Personal Firewall 4 and IE 6 </ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137421524251&amp;w=2">20040407 Kerio Personal Firewall 4.0.13 - Remote DoS (Crash)</ref><ref source="MISC" url="http://www.cipher.org.uk/index.php?p=advisories/HEX-Kerio_Personal_Firewall_Remote_DOS_7-04-2004.advisory">http://www.cipher.org.uk/index.php?p=advisories/HEX-Kerio_Personal_Firewall_Remote_DOS_7-04-2004.advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/10075">10075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11331">11331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15821">kerio-pf-webfilter-dos(15821)</ref></refs><vuln_soft><prod name="Personal Firewall" vendor="Kerio"><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/><vers num="4.0.9"/><vers num="4.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1908" published="2004-12-31" seq="2004-1908" severity="Medium" type="CVE"><desc><descript source="cve">McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136872711898&amp;w=2">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019877.html">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html">20040407 Symantec, McAfee and Panda ActiveX controls</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137545531496&amp;w=2">20040407 McAfee Freescan ActiveX Information Disclosure [Additional Details &amp; PoC]</ref><ref source="BID" url="http://www.securityfocus.com/bid/10077">10077</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11313">11313</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15782">freescan-mcfscan-info-disclosure(15782)</ref></refs><vuln_soft><prod name="FreeScan" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1909" published="2004-12-31" seq="2004-1909" severity="Low" type="CVE"><desc><descript source="cve">Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://freshmeat.net/projects/clamav/?branch_id=29355&amp;release_id=154462">http://freshmeat.net/projects/clamav/?branch_id=29355&amp;release_id=154462</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-07.xml">GLSA-200404-07</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9897">9897</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11177">11177</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15553">clam-antivirus-rar-dos(15553)</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.65"/><vers num="0.67"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1910" published="2004-12-31" seq="2004-1910" severity="Medium" type="CVE"><desc><descript source="cve">rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function.  NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136901406896&amp;w=2">20040407 Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108143485021721&amp;w=2">20040408 Re:  Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow, Apr 7</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html">20040407 Symantec, McAfee and Panda ActiveX controls</ref><ref source="BID" url="http://www.securityfocus.com/bid/10069">10069</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15778">symantec-sc-rufsi-bo(15778)</ref></refs><vuln_soft><prod name="Security Check Virus Detection" vendor="Symantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2004-1911" published="2004-12-31" seq="2004-1911" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144342317973&amp;w=2">20040408 [waraxe-2004-SA#014 - Cross-Site Scripting aka XSS in AzDGDatingLite]</ref><ref source="BID" url="http://www.securityfocus.com/bid/10084">10084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11326">11326</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15796">azdgdating-index-view-xss(15796)</ref><ref source="OSVDB" url="http://www.osvdb.org/5018">5018</ref><ref source="OSVDB" url="http://www.osvdb.org/5019">5019</ref></refs><vuln_soft><prod name="AzDGDating" vendor="Azerbaijan Development Group"><vers edition="Lite" num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1912" published="2004-12-31" seq="2004-1912" severity="Medium" type="CVE"><desc><descript source="cve">The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref><ref source="BID" url="http://www.securityfocus.com/bid/10082">10082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15795">nuke-calendar-path-disclosure(15795)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod><prod name="NukeCalendar" vendor="shiba-design"><vers num="1.1.a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1913" published="2004-12-31" seq="2004-1913" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref><ref source="BID" url="http://www.securityfocus.com/bid/10082">10082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15798">nuke-calendar-modulesphp-xss(15798)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod><prod name="NukeCalendar" vendor="shiba-design"><vers num="1.1.a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1914" published="2004-12-31" seq="2004-1914" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref><ref source="BID" url="http://www.securityfocus.com/bid/10082">10082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15799">nukecalendar-modulesphp-sql-injection(15799)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod><prod name="NukeCalendar" vendor="shiba-design"><vers num="1.1.a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1915" published="2004-04-08" seq="2004-1915" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108145722229810&amp;w=2">20040408 PSR - #2004-001 Remote - LCDProc</ref><ref adv="1" source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-19.xml">GLSA-200404-19</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10085">10085</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11333">11333</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15803">lcdproc-parseallclientmessages-bo(15803)</ref></refs><vuln_soft><prod name="LCDProc" vendor="LCDProc"><vers num="0.3"/><vers num="0.4"/><vers num="0.4.1 r1"/><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1916" published="2004-04-08" seq="2004-1916" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2">20040408 PSR - #2004-002 Remote - LCDProc</ref><ref adv="1" source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-19.xml">GLSA-200404-19</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10085">10085</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11333">11333</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15814">lcdproc-testfuncfunc-bo(15814)</ref></refs><vuln_soft><prod name="LCDProc" vendor="LCDProc"><vers num="0.3"/><vers num="0.4"/><vers num="0.4.1 r1"/><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1917" published="2004-04-08" seq="2004-1917" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2">20040408 PSR - #2004-002 Remote - LCDProc</ref><ref adv="1" source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-19.xml">GLSA-200404-19</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10085">10085</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11333">11333</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15817">lcdproc-testfuncfunc-format-string(15817)</ref></refs><vuln_soft><prod name="LCDProc" vendor="LCDProc"><vers num="0.3"/><vers num="0.4"/><vers num="0.4.1 r1"/><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1918" published="2004-04-09" seq="2004-1918" severity="Medium" type="CVE"><desc><descript source="cve">RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/rsniff-adv.txt"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10093">10093</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11339">11339</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15823">rsniff-connection-dos(15823)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152508004665&amp;w=2">20040409 DoS in Rsniff 1.0</ref></refs><vuln_soft><prod name="RSniff" vendor="RSniff"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1919" published="2004-04-09" seq="2004-1919" severity="Medium" type="CVE"><desc><descript source="cve">The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152479316967&amp;w=2">20040409 DoS in Crackalaka 1.0.8</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10092">10092</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11340">11340</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15824">crackalaka-hashstrcmp-dos(15824)</ref></refs><vuln_soft><prod name="Crackalaka" vendor="Crackalaka"><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1920" published="2004-04-10" seq="2004-1920" severity="High" type="CVE"><desc><descript source="cve">X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded &quot;super&quot; username and password, which could allow remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108162529229947&amp;w=2">20040410 Backdoor in X-Micro WLAN 11b Broadband Router</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10095">10095</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11342">11342</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15829">xmicro-router-default-account(15829)</ref></refs><vuln_soft><prod name="WLAN 11b Broadband Router Firmware" vendor="X-Micro"><vers num="1.2.2.4"/><vers num="1.2.2.3"/><vers num="1.2.2"/><vers num="1.6.0.1"/><vers num="1.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1921" published="2004-04-10" seq="2004-1921" severity="High" type="CVE"><desc><descript source="cve">X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded &quot;1502&quot; username and password, which could allow remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108223222519855&amp;w=2">20040416 NEW backdoor in X-Micro WLAN 11b Broadband Router</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213608111111&amp;w=2">20040416 Re: Backdoor in X-Micro WLAN 11b Broadband Router</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10095">10095</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11342">11342</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15890">xmicro-router-default-login(15890)</ref></refs><vuln_soft><prod name="WLAN 11b Broadband Router Firmware" vendor="X-Micro"><vers num="1.2.2.4"/><vers num="1.2.2.3"/><vers num="1.2.2"/><vers num="1.6.0.1"/><vers num="1.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1922" published="2004-04-11" seq="2004-1922" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108183130827872&amp;w=2">20040411 Microsoft Internet Explorer BMP file memory DoS vulnerability</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1923" published="2004-04-11" seq="2004-1923" severity="Medium" type="CVE"><desc><descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15847">tikiwiki-path-disclosure(15847)</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1924" published="2004-04-11" seq="2004-1924" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15846">tikiwiki-xss(15846)</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-1925" published="2004-04-12" seq="2004-1925" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040411 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15845">tikiwiki-sql-injection(15845)</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8.1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1926" published="2004-04-11" seq="2004-1926" severity="Medium" type="CVE"><desc><descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1927" published="2004-04-11" seq="2004-1927" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15848">tikiwiki-tikimap-file-disclosure(15848)</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2004-1928" published="2004-04-12" seq="2004-1928" severity="High" type="CVE"><desc><descript source="cve">The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10100">10100</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11344">11344</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15849">tikiwiki-file-upload(15849)</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1929" published="2004-04-13" seq="2004-1929" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180111826852&amp;w=2">20040412 [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=17">http://www.waraxe.us/index.php?modname=sa&amp;id=17</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10135">10135</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11347">11347</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15839">phpnuke-bypass-authentication(15839)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="5.5"/><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1930" published="2004-04-12" seq="2004-1930" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108182759214035&amp;w=2">20040412 [waraxe-2004-SA#016 - Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=16">http://www.waraxe.us/index.php?modname=sa&amp;id=16</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10128">10128</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11347">11347</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15842">phpnuke-cookiedecode-xss(15842)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1932" published="2004-04-12" seq="2004-1932" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180334918576&amp;w=2">20040412 [waraxe-2004-SA#018 - Admin-level authentication bypass in phpnuke 6.x-7.2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=18">http://www.waraxe.us/index.php?modname=sa&amp;id=18</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15835">phpnuke-admin-bypass-authentication(15835)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2004-1933" published="2004-04-12" seq="2004-1933" severity="Low" type="CVE"><desc><descript source="cve">Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180024428804&amp;w=2">20040412 Citadel/UX 6.20 fixes local permissions vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10102">10102</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15850">citadel-database-insecure-permissions(15850)</ref></refs><vuln_soft><prod name="Citadel_UX" vendor="Citadel"><vers num="5.90"/><vers num="5.91"/><vers num="6.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1934" published="2004-04-15" seq="2004-1934" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206642725505&amp;w=2">20040415 Include vulnerability in GEMITEL v 3.50</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10156">10156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11393">11393</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15887">gemitel-spturnphpfile-include(15887)</ref><ref source="OSVDB" url="http://www.osvdb.org/5396">5396</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009824">1009824</ref></refs><vuln_soft><prod name="Gemitel" vendor="isesam"><vers num="3.50"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1935" published="2004-04-15" seq="2004-1935" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108207280917231&amp;w=2">20040415 SCT javascript execution vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10154">10154</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11396">11396</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15878">sct-campus-attachment-xss(15878)</ref></refs><vuln_soft><prod name="Campus Pipeline" vendor="SCT Corporation"><vers num="1.0"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1936" published="2004-04-14" seq="2004-1936" severity="High" type="CVE"><desc><descript source="cve">ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206751931251&amp;w=2">20040414 ZA Security Hole</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108248415509417&amp;w=2">20040420 Re: ZA Security Hole</ref><ref source="BID" url="http://www.securityfocus.com/bid/10148">10148</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15884">zonealarm-email-bypass-security(15884)</ref></refs><vuln_soft><prod name="ZoneAlarm Plus" vendor="Zone Labs"><vers num="4.0"/><vers num="4.5 .538.001"/></prod><prod name="ZoneAlarm Pro" vendor="Zone Labs"><vers num="2.4"/><vers num="2.6"/><vers num="3.0"/><vers num="3.1"/><vers num="4.0"/><vers num="4.5.538.001"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1937" published="2004-12-31" seq="2004-1937" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108222826225823&amp;w=2">20040417 [SCSA-028] Nuked-Klan Multiple Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txt">http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10104">10104</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11341">11341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15843">nuked-klan-file-include(15843)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15844">nuked-klan-configurtion-corruption(15844)</ref></refs><vuln_soft><prod name="Nuked-Klan" vendor="Nuked-Klan"><vers num="1.2 beta"/><vers num="1.2"/><vers num="1.3 beta"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5 SP2"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1938" published="2004-04-19" seq="2004-1938" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as &quot;%2527&quot;, which is translated to &quot;&apos;&quot;, as demonstrated using the phorum_uriauth parameter to list.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239796512897&amp;w=2">20040419 [waraxe-2004-SA#019 - Critical sql injection bug in Phorum 3.4.7]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=19">http://www.waraxe.us/index.php?modname=sa&amp;id=19</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10173">10173</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11407">11407</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15894">phorum-userlogin-sql-injection(15894)</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.7"/><vers num="3.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1939" published="2004-04-14" seq="2004-1939" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241507812681&amp;w=2">20040419 Zaep AntiSpam Cross Site Scripting</ref><ref adv="1" patch="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html">http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10139">10139</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11388">11388</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15858">zaep-antispam-xss(15858)</ref></refs><vuln_soft><prod name="Zaep AntiSpam" vendor="Rhino Software"><vers num="2.0 .0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1940" published="2004-12-31" seq="2004-1940" severity="Medium" type="CVE"><desc><descript source="cve">sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108244325924859&amp;w=2">20040419 KPhone STUN DoS (Malformed STUN Packets)</ref><ref source="MISC" url="http://www.securiteam.com/unixfocus/5PP0B1FCLY.html">http://www.securiteam.com/unixfocus/5PP0B1FCLY.html</ref><ref patch="1" source="CONFIRM" url="http://www.wirlab.net/kphone/changes-4.0.2.html">http://www.wirlab.net/kphone/changes-4.0.2.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10159">10159</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15874">kphone-stun-dos(15874)</ref></refs><vuln_soft><prod name="KPhone" vendor="KPhone"><vers num="2.0"/><vers num="2.1"/><vers num="2.11"/><vers num="3.0"/><vers num="3.1"/><vers num="3.11"/><vers num="3.12"/><vers num="3.13"/><vers num="3.14"/><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1941" published="2004-04-19" seq="2004-1941" severity="Medium" type="CVE"><desc><descript source="cve">Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239249613861&amp;w=2">20040419 DoS in  NETFile FTP/Web Server</ref><ref adv="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/FastreamNETFileFWServer6.5.1.980-adv.txt">http://www.autistici.org/fdonato/advisory/FastreamNETFileFWServer6.5.1.980-adv.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10169">10169</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11428">11428</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15899">fastream-user-pass-dos(15899)</ref><ref source="OSVDB" url="http://www.osvdb.org/5548">5548</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009868">1009868</ref></refs><vuln_soft><prod name="NetFILE FTP_Web Server" vendor="Fastream"><vers num="6.5.1.980"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1942" published="2004-04-19" seq="2004-1942" severity="High" type="CVE"><desc><descript source="cve">The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241638500417&amp;w=2">20040419 Solaris 9 patch 113579-03 introduces a NIS security bug</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57554-1">57554</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-144.shtml">O-144</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10261">10261</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15908">solaris-nis-unauth-privileges(15908)</ref></refs><vuln_soft><prod name="Sun Patch" vendor="Sun"><vers num="113579-02"/><vers num="113579-03"/><vers num="113579-04"/><vers num="113579-05"/><vers num="114342-02"/><vers num="114342-03"/><vers num="114342-04"/><vers num="114342-05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1943" published="2004-04-19" seq="2004-1943" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108244738102532&amp;w=2">20040419 phpBB modified by Przemo arbitary code execution</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10177">10177</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15916">phpbb-albumportal-file-include(15916)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1944" published="2004-04-14" seq="2004-1944" severity="Medium" type="CVE"><desc><descript source="cve">Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020075.html">20040414 Eudora 6.0.3 nested MIME DoS</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241694627321&amp;w=2">20040419 Eudora 6.1 is evil</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10137">10137</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11360">11360</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15857">eudora-mime-message-dos(15857)</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="6.1"/><vers num="6.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1945" published="2004-04-20" seq="2004-1945" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108247921402458&amp;w=2">20040419 Exchange pop3 remote exploit</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108568462428096&amp;w=2">20040527 Re: Exchange pop3 remote exploit</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009882">http://securitytracker.com/id?1009882</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10180">10180</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11449">11449</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15922">exchange-pop3-smtp-bo(15922)</ref><ref source="OSVDB" url="http://www.osvdb.org/5593">5593</ref></refs><vuln_soft><prod name="eXchange POP3" vendor="Kinesphere Corporation"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1946" published="2004-04-19" seq="2004-1946" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument.  NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108249818308672&amp;w=2">20040420 Format String in Cherokee</ref><ref adv="1" source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-03.txt">http://www.nosystem.com.ar/advisories/advisory-03.txt</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15924">cherokee-printerror-format-string(15924)</ref></refs><vuln_soft><prod name="Cherokee HTTPD" vendor="Cherokee"><vers num="0.4.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-1947" published="2004-04-19" seq="2004-1947" severity="Medium" type="CVE"><desc><descript source="cve">The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108240639427412&amp;w=2">20040419 BitDefender Scan Online(ActiveX) - Remote File Download &amp; Execute &amp; Private Information Disclosure</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108248367901616&amp;w=2">20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download &amp; Execute &amp; Private Information Disclosure</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10175">10175</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11427">11427</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15911">bitdefender-avxscanonline-code-execution(15911)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10174">10174</ref><ref source="OSVDB" url="http://www.osvdb.org/5549">5549</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009862">1009862</ref></refs><vuln_soft><prod name="BitDefender" vendor="Softwin"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1948" published="2004-04-20" seq="2004-1948" severity="Medium" type="CVE"><desc><descript source="cve">NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via &quot;ps aux,&quot; which displays the URL in the process list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108247943201685&amp;w=2">20040419 NcFTP - password leaking</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10182">10182</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11438">11438</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15919">ncftp-info-disclosure(15919)</ref><ref source="OSVDB" url="http://www.osvdb.org/5595">5595</ref></refs><vuln_soft><prod name="NcFTP" vendor="NcFTP Software"><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.1.0"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.1.6"/><vers num="3.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1949" published="2004-12-31" seq="2004-1949" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html">20040414 [SCAN Associates Sdn Bhd Security Advisory] Postnuke v 0.726 and below SQL injection</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108256503718978&amp;w=2">20040420 [PNSA 2004-2] PostNuke Security Advisory PNSA 2004-2</ref><ref adv="1" source="CONFIRM" url="http://news.postnuke.com/Article2580.html">http://news.postnuke.com/Article2580.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10146">10146</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11386">11386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15869">postnuke-indexphp-sql-injection(15869)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15875">postnuke-changeinfo-sql-injection(15875)</ref><ref source="OSVDB" url="http://www.osvdb.org/5368">5368</ref><ref source="OSVDB" url="http://www.osvdb.org/5369">5369</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009801">1009801</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.726"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1950" published="2004-04-19" seq="2004-1950" severity="Medium" type="CVE"><desc><descript source="cve">phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239864203144&amp;w=2">20040419 phpBB 2.0.8a and lower - IP spoofing vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241122908409&amp;w=2">20040419 Re: phpBB 2.0.8a and lower - IP spoofing vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10170">10170</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11434">11434</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15909">phbb-common-ip-spoofing(15909)</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1951" published="2004-12-31" seq="2004-1951" severity="Medium" type="CVE"><desc><descript source="cve">xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.xinehq.de/index.php/security/XSA-2004-1">http://www.xinehq.de/index.php/security/XSA-2004-1</ref><ref adv="1" source="CONFIRM" url="http://www.xinehq.de/index.php/security/XSA-2004-2">http://www.xinehq.de/index.php/security/XSA-2004-2</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-20.xml">GLSA-200404-20</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.372791">SSA:2004-111</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10193">10193</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11433">11433</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15939">xine-mrl-file-overwrite(15939)</ref><ref source="OSVDB" url="http://www.osvdb.org/5594">5594</ref><ref source="OSVDB" url="http://www.osvdb.org/5739">5739</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc2"/></prod><prod name="xine" vendor="xine"><vers num="1 beta1"/><vers num="1 beta10"/><vers num="1 beta11"/><vers num="1 beta12"/><vers num="1 beta2"/><vers num="1 beta3"/><vers num="1 beta4"/><vers num="1 beta5"/><vers num="1 beta6"/><vers num="1 beta7"/><vers num="1 beta8"/><vers num="1 beta9"/><vers num="1 rc0a"/><vers num="1 rc1"/><vers num="1 rc2"/><vers num="1 rc3"/><vers num="1 rc3a"/><vers num="1 rc3b"/><vers num="0.9.8"/><vers num="0.9.13"/></prod><prod name="xine-ui" vendor="xine"><vers num="0.9.21"/><vers num="0.9.22"/><vers num="0.9.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1952" published="2004-04-23" seq="2004-1952" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258046402890&amp;w=2">20040421 Advanced Guestbook 2.2 -- SQL Injection Exploit</ref><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-02/0138.html">20050212 Re: Advanced Guestbook 2.2 -- SQL Injection Exploit</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10209">10209</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15892">advancedguestbook-sql-injection(15892)</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1953" published="2004-12-31" seq="2004-1953" severity="Medium" type="CVE"><desc><descript source="cve">phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=21">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref><ref source="BID" url="http://www.securityfocus.com/bid/10190">10190</ref><ref source="OSVDB" url="http://www.osvdb.org/5623">5623</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11465">11465</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15930">phprofession-upload-path-disclosure(15930)</ref></refs><vuln_soft><prod name="phProfession" vendor="phProfession"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1954" published="2004-04-21" seq="2004-1954" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=21">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10190">10190</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/5624">5624</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11465">11465</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15931">phprofession-jcode-xss(15931)</ref></refs><vuln_soft><prod name="phProfession" vendor="phProfession"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1955" published="2004-12-31" seq="2004-1955" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=21">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref><ref source="BID" url="http://www.securityfocus.com/bid/10190">10190</ref><ref source="OSVDB" url="http://www.osvdb.org/5625">5625</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11465">11465</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15932">phprofession-offset-sql-injection(15932)</ref></refs><vuln_soft><prod name="phProfession" vendor="phProfession"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1956" published="2004-04-21" seq="2004-1956" severity="Medium" type="CVE"><desc><descript source="cve">PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258902000472&amp;w=2">20040421 [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=22">http://www.waraxe.us/index.php?modname=sa&amp;id=22</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10191">10191</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15933">postnuke-scripts-modules-path-disclosure(15933)</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.726"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-1957" published="2004-04-21" seq="2004-1957" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258902000472&amp;w=2">20040421 [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=22">http://www.waraxe.us/index.php?modname=sa&amp;id=22</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10191">10191</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15934">postnuke-openwindow-xss(15934)</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.726"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1958" published="2004-12-31" seq="2004-1958" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/umod-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10196">10196</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15942">unreal-umod-dotdot-file-overwrite(15942)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108267310519459&amp;w=2">20040422 Arbitrary file overwriting in Unreal engine through UMOD</ref></refs><vuln_soft><prod name="Unreal Tournament" vendor="Epic Games"><vers num="451b"/></prod><prod name="Unreal Tournament 2003" vendor="Epic Games"><vers num="2225 win32"/><vers num="2225 macOS"/><vers num="2199 win32"/><vers num="2199 macOS"/></prod><prod name="Unreal Engine" vendor="Epic Games"><vers num="436"/><vers num="433"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1959" published="2004-04-23" seq="2004-1959" severity="Medium" type="CVE"><desc><descript source="cve">blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276299810121&amp;w=2">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=25">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10206">10206</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15963">protector-blockerquery-path-disclosure(15963)</ref></refs><vuln_soft><prod name="Protector System" vendor="Protector System"><vers num="1.15b1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1960" published="2004-12-31" seq="2004-1960" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/bid/10206">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=25">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15965">protector-blockerquery-xss(15965)</ref></refs><vuln_soft><prod name="Protector System" vendor="Protector System"><vers num="1.15b1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1961" published="2004-04-23" seq="2004-1961" severity="High" type="CVE"><desc><descript source="cve">blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded &quot;&apos;&quot; characters (&quot;%27&quot;).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/bid/10206">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref><ref adv="1" patch="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=25">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref></refs><vuln_soft><prod name="Protector System" vendor="Protector System"><vers num="1.15b1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1962" published="2004-12-31" seq="2004-1962" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using &quot;/**/&quot; sequences in the targeted fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/bid/10206">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=25">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15969">protector-sql-filter-bypass(15969)</ref></refs><vuln_soft><prod name="Protector System" vendor="Protector System"><vers num="1.15b1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1963" published="2004-04-23" seq="2004-1963" severity="Medium" type="CVE"><desc><descript source="cve">nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to obtain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276405108267&amp;w=2">20040423 [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=24">http://www.waraxe.us/index.php?modname=sa&amp;id=24</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11479">11479</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15957">nqt-nqtphp-path-disclosure(15957)</ref></refs><vuln_soft><prod name="Network Query Tool" vendor="freshmeat"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1964" published="2004-04-23" seq="2004-1964" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276405108267&amp;w=2">20040423 [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=24">http://www.waraxe.us/index.php?modname=sa&amp;id=24</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10205">10205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11479">11479</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15929">nqt-nqtphp-xss(15929)</ref></refs><vuln_soft><prod name="Network Query Tool" vendor="freshmeat"><vers num="1.0"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1965" published="2004-04-25" seq="2004-1965" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2">20040425 Multiple Vulnerabilities In OpenBB</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009935">http://securitytracker.com/id?1009935</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10214">10214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11481">11481</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15966">openbb-multiple-scripts-xss(15966)</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.0 RC3"/><vers num="1.0.0 RC2"/><vers num="1.0.0 RC1"/><vers num="1.0.0 beta1"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1966" published="2004-12-31" seq="2004-1966" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2">20040425 Multiple Vulnerabilities In OpenBB</ref><ref source="MISC" url="http://securitytracker.com/id?1009935">http://securitytracker.com/id?1009935</ref><ref source="BID" url="http://www.securityfocus.com/bid/10214">10214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11481">11481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15964">openbb-multiplescripts-sql-injection(15964)</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.0 RC3"/><vers num="1.0.0 RC2"/><vers num="1.0.0 RC1"/><vers num="1.0.0 beta1"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1967" published="2004-04-25" seq="2004-1967" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2">20040425 Multiple Vulnerabilities In OpenBB</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009935">http://securitytracker.com/id?1009935</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11481">11481</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15967">openbb-tags-execute-code(15967)</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.0 RC3"/><vers num="1.0.0 RC2"/><vers num="1.0.0 RC1"/><vers num="1.0.0 beta1"/><vers num="1.0.5"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1968" published="2004-04-26" seq="2004-1968" severity="Medium" type="CVE"><desc><descript source="cve">The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2">20040425 Multiple Vulnerabilities In OpenBB</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009935">http://securitytracker.com/id?1009935</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10217">10217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11481">11481</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15970">openbb-myhomephp-obtain-information(15970)</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0 .0 RC3"/><vers num="1.0 .0 RC2"/><vers num="1.0 .0 RC1"/><vers num="1.0 .0 beta1"/><vers num="1.0 .5"/><vers num="1.0 .6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1969" published="2004-04-25" seq="2004-1969" severity="High" type="CVE"><desc><descript source="cve">The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2">20040425 Multiple Vulnerabilities In OpenBB</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1009935">http://securitytracker.com/id?1009935</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10218">10218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11481">11481</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15971">openbb-file-upload(15971)</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.0 RC3"/><vers num="1.0.0 RC2"/><vers num="1.0.0 RC1"/><vers num="1.0.0 beta1"/><vers num="1.0.5"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1970" published="2004-04-26" seq="2004-1970" severity="High" type="CVE"><desc><descript source="cve">Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108300407424571&amp;w=2">20040426 Samsung SmartEther SS6215S Switch</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10219">10219</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15973">samsung-smartether-admin-access(15973)</ref></refs><vuln_soft><prod name="SmartEther SS6215S Switch" vendor="secure computing"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1971" published="2004-04-26" seq="2004-1971" severity="Medium" type="CVE"><desc><descript source="cve">modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308660628557&amp;w=2">20040426 Multiple vulnerabilities PHP-Nuke Video Gallery Module for PHP-Nuke</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15978">video-gallery-error-path-disclosure(15978)</ref></refs><vuln_soft><prod name="Video Gallery" vendor="Oscar Fafian"><vers num="0.1 Beta 5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1972" published="2004-04-26" seq="2004-1972" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308660628557&amp;w=2">20040426 Multiple vulnerabilities PHP-Nuke Video Gallery Module for PHP-Nuke</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10215">10215</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15979">video-gallery-sql-injection(15979)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1973" published="2004-04-27" seq="2004-1973" severity="Medium" type="CVE"><desc><descript source="cve">DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes resources when DiGi converts the slashes to \ (backslash) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311170018203&amp;w=2">20040427 resources consumption in DiGi WWW Server</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/DiGiWwwServerC1-adv.txt">http://www.autistici.org/fdonato/advisory/DiGiWwwServerC1-adv.txt</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=234261">http://sourceforge.net/project/shownotes.php?release_id=234261</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10228">10228</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/5702">5702</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11490">11490</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15987">digi-www-slash-dos(15987)</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Apr/1009957.html">1009957</ref></refs><vuln_soft><prod name="DiGi WWW Server" vendor="DiGi"><vers num="Compieuw.1"/><vers num="Compieuw beta 2"/><vers num="Compieuw"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1974" published="2004-04-27" seq="2004-1974" severity="Medium" type="CVE"><desc><descript source="cve">paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311096022485&amp;w=2">20040427 Multiple vulnerabilities paFileDB</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15990">pafiledb-loginphp-path-disclosure(15990)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2004-1975" published="2004-04-27" seq="2004-1975" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311096022485&amp;w=2">20040427 Multiple vulnerabilities paFileDB</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613031414184&amp;w=2">20040925 New XSS vulnerabilities in paFileDB 3.1 final</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10229">10229</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15992">pafiledb-pafiledbphp-xss(15992)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1976" published="2004-04-28" seq="2004-1976" severity="High" type="CVE"><desc><descript source="cve">SMC Barricade broadband router 7008ABR and 7004VBR enable remote administration by default, which allows remote attackers to gain access by connecting to port 1900.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108317929931816&amp;w=2">20040428 SMC Routers have remote administration enabled by default</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020580.html">20040427 SMC Routers have remote administration enabled by default</ref><ref patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0101.html">20040605 SMC 7008ABRv2 and 7004VBRv1 updated firmware corrects port 1900 issue.</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10232">10232</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15993">barricade-router-gain-access(15993)</ref></refs><vuln_soft><prod name="SMC7004VBR" vendor="SMC Networks"><vers num="1.032"/><vers num="1.231"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1977" published="2004-04-29" seq="2004-1977" severity="Medium" type="CVE"><desc><descript source="cve">3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334887408554&amp;w=2">20040429 3com NBX VOIP NetSet Denial of Service Attack</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10240">10240</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11504">11504</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16015">3com-nbx-scan-dos(16015)</ref></refs><vuln_soft><prod name="3Com SuperStack 3 NBX" vendor="3Com"><vers num="4.0.17"/><vers num="4.1.4"/><vers num="4.1.21"/><vers num="4.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1978" published="2004-04-30" seq="2004-1978" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335043825605&amp;w=2">20040430 Cross Site Scripting in Moodle &lt; 1.3</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10251">10251</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11535">11535</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16023">moodle-help-xss(16023)</ref><ref source="OSVDB" url="http://www.osvdb.org/5747">5747</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010008">1010008</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1979" published="2004-04-30" seq="2004-1979" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108342671616155&amp;w=2">20040501 Props 0.6.1 XSS and Remote File Viewing Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433">http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10258">10258</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16035">props-dosearch-xss(16035)</ref></refs><vuln_soft><prod name="PROPS" vendor="PROPS"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1980" published="2004-04-30" seq="2004-1980" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108342671616155&amp;w=2">20040501 Props 0.6.1 XSS and Remote File Viewing Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433">http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16036">props-glossary-obtain-information(16036)</ref></refs><vuln_soft><prod name="PROPS" vendor="PROPS"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1981" published="2004-05-02" seq="2004-1981" severity="Medium" type="CVE"><desc><descript source="cve">The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2">20040502 Crystal Reports Vulnerabilities</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref></refs><vuln_soft><prod name="Crystal Enterprise" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Crystal Reports" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1982" published="2004-05-03" seq="2004-1982" severity="Medium" type="CVE"><desc><descript source="cve">Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board&apos;s .txt file via carriage return characters in the subject field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360430703935&amp;w=2">20040502 Vulnerability in YaBB forum (Perl version without SQL)</ref><ref adv="1" source="CONFIRM" url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10263">10263</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12609">12609</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16050">yabb-subject-modify-file(16050)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="1 Gold - SP 1.2"/><vers num="1 Gold - SP 1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1983" published="2004-05-02" seq="2004-1983" severity="Low" type="CVE"><desc><descript source="cve">The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360001130312&amp;w=2">20040502 PaX Linux Kernel 2.6 Patches DoS Advisory</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420555920369&amp;w=2">20040509 PaX DoS proof-of-concept</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref patch="1" source="CONFIRM" url="http://pax.grsecurity.net/">http://pax.grsecurity.net/</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10264">10264</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16037">pax-aslr-enabled-dos(16037)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="PaX linux" vendor="The PaX Team"><vers num="2.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1984" published="2004-05-02" seq="2004-1984" severity="Medium" type="CVE"><desc><descript source="cve">Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16039">coppermine-multiple-path-disclosure(16039)</ref><ref source="OSVDB" url="http://www.osvdb.org/5756">5756</ref><ref source="OSVDB" url="http://www.osvdb.org/6495">6495</ref><ref source="OSVDB" url="http://www.osvdb.org/6496">6496</ref><ref source="OSVDB" url="http://www.osvdb.org/6497">6497</ref><ref source="OSVDB" url="http://www.osvdb.org/6498">6498</ref><ref source="OSVDB" url="http://www.osvdb.org/6499">6499</ref><ref source="OSVDB" url="http://www.osvdb.org/6500">6500</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1985" published="2004-04-30" seq="2004-1985" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10253">10253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16040">coppermine-menuincpho-xss(16040)</ref><ref source="OSVDB" url="http://www.osvdb.org/5757">5757</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1986" published="2004-04-04" seq="2004-1986" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10253">10253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16042">coppermine-modulesphp-directory-traversal(16042)</ref><ref source="OSVDB" url="http://www.osvdb.org/5758">5758</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1987" published="2004-04-30" seq="2004-1987" severity="High" type="CVE"><desc><descript source="cve">picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG[&apos;impath&apos;] or (2) $CONFIG[&apos;jpeg_qual&apos;] parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502  [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10253">10253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16043">coppermine-parameters-execute-commands(16043)</ref><ref source="OSVDB" url="http://www.osvdb.org/5759">5759</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1988" published="2004-04-30" seq="2004-1988" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10253">10253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16041">coppermine-multiple-file-include(16041)</ref><ref source="OSVDB" url="http://www.osvdb.org/5761">5761</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 Beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-1989" published="2004-04-30" seq="2004-1989" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10253">10253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11524">11524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16041">coppermine-multiple-file-include(16041)</ref><ref source="OSVDB" url="http://www.osvdb.org/5912">5912</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.0 RC3"/><vers num="1.1 Beta 2"/><vers num="1.1 .0"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2 b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1990" published="2004-03-03" seq="2004-1990" severity="Medium" type="CVE"><desc><descript source="cve">Aldo&apos;s Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360629031227&amp;w=2">20040503 Multible_Vulnerabilites_in_Aldos_Webserver</ref><ref adv="1" source="MISC" url="http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt">http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10262">10262</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11542">11542</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16047">aweb-path-disclosure(16047)</ref><ref source="OSVDB" url="http://www.osvdb.org/5880">5880</ref></refs><vuln_soft><prod name="Aldo&apos;s Web Server" vendor="Aldo Vargas"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1991" published="2004-05-03" seq="2004-1991" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Aldo&apos;s Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360629031227&amp;w=2">20040503 Multible_Vulnerabilites_in_Aldos_Webserver</ref><ref adv="1" source="MISC" url="http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt">http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10262">10262</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11542">11542</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16048">aweb-dotdot-directory-traversal(16048)</ref><ref source="OSVDB" url="http://www.osvdb.org/5881">5881</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1992" published="2004-04-20" seq="2004-1992" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360377119290&amp;w=2">20040503 Serv-U LIST -l Parameter Buffer Overflow</ref><ref adv="1" source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108359620108234&amp;w=2">20040503 Serv-U LIST -l Parameter Buffer Overflow</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5ZP0G2KCKA.html">http://www.securiteam.com/windowsntfocus/5ZP0G2KCKA.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10181">10181</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11430">11430</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15913">servu-list-command-bo(15913)</ref><ref source="OSVDB" url="http://www.osvdb.org/5546">5546</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009869">1009869</ref></refs><vuln_soft><prod name="Serv-U" vendor="RhinoSoft"><vers num="3.0"/><vers num="3.1"/><vers num="4.0.0.4"/><vers num="4.1.0.11"/><vers num="4.1"/><vers num="4.2"/><vers num="5.0.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1993" published="2004-05-04" seq="2004-1993" severity="High" type="CVE"><desc><descript source="cve">The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as &quot;`&quot; (backticks) in the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377215015515&amp;w=2">20040504 remote root exec vulnerability in omail</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10274">10274</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/9585">9585</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/12948">omailwebmail-checklogin-code-execution(12948)</ref></refs><vuln_soft><prod name="OMail Webmail" vendor="OMail"><vers num="0.97.3"/><vers num="0.98.3"/><vers num="0.98.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1994" published="2004-05-05" seq="2004-1994" severity="Medium" type="CVE"><desc><descript source="cve">FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377423825478&amp;w=2">20040505 Fuse Talk Vunerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10278">10278</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11555">11555</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16081">fusetalk-banning-unauth-access(16081)</ref><ref source="OSVDB" url="http://www.osvdb.org/5894">5894</ref></refs><vuln_soft><prod name="FuseTalk" vendor="e-Zone Media Inc."><vers num="2.0"/><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1995" published="2004-12-31" seq="2004-1995" severity="High" type="CVE"><desc><descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377423825478&amp;w=2">20040505 Fuse Talk Vunerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10276">10276</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11555">11555</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16080">fusetalk-get-add-users(16080)</ref><ref source="OSVDB" url="http://www.osvdb.org/5895">5895</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010080">1010080</ref></refs><vuln_soft><prod name="FuseTalk" vendor="e-Zone Media Inc."><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1996" published="2004-05-05" seq="2004-1996" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377364615934&amp;w=2">20040505 SMF SIZE Tag Script Injection Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10281">10281</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16067">smf-size-html-injection(16067)</ref></refs><vuln_soft><prod name="SMF" vendor="Simple Machines"><vers num="1.0 Beta5p"/><vers num="1.0 Beta4p"/><vers num="1.0 Beta4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-1997" published="2004-05-05" seq="2004-1997" severity="Medium" type="CVE"><desc><descript source="cve">Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://www.kolab.org/pipermail/kolab-users/2004-April/000215.html">[kolab-users] 20040420 Possible Kolab LDAP configuration information disclosure</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:052">MDKSA-2004:052</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377525924422&amp;w=2">20040505 [OpenPKG-SA-2004.019] OpenPKG Security Advisory (kolab)</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10277">10277</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11560">11560</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16068">kolab-root-password-plaintext(16068)</ref><ref source="" url="http://www.erfrakon.de/projects/kolab/download/kolab-server-1.0/src/Changelog">http://www.erfrakon.de/projects/kolab/download/kolab-server-1.0/src/Changelog</ref><ref source="OSVDB" url="http://www.osvdb.org/5898">5898</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:052">MDKSA-2004:052</ref></refs><vuln_soft><prod name="OpenPKG" vendor="OpenPKG"><vers num="2.0"/></prod><prod name="Kolab Groupware Server" vendor="Kolab"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1998" published="2004-05-05" seq="2004-1998" severity="Medium" type="CVE"><desc><descript source="cve">The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=27">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.8"/><vers num="6.9"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-1999" published="2004-05-05" seq="2004-1999" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=27">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11553">11553</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16073">phpnuke-ttitle-sid-xss(16073)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.8"/><vers num="6.9"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2000" published="2004-05-05" seq="2004-2000" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=27">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10282">10282</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11553">11553</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16074">phpnuke-orderby-sid-sql-injection(16074)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488452/100/0/threaded">20080221 PHP-Nuke Module Downloads SQL Injection(sid)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27932">27932</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2001" published="2004-05-05" seq="2004-2001" severity="Medium" type="CVE"><desc><descript source="cve">ifconfig &quot;-arp&quot; in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc">20050502-01-P</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10289">10289</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.5"/><vers num="6.5.6"/><vers num="6.5.7"/><vers num="6.5.8"/><vers num="6.5.9"/><vers num="6.5.10"/><vers num="6.5.11"/><vers num="6.5.12"/><vers num="6.5.13"/><vers num="6.5.14"/><vers num="6.5.15"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.22m"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2002" published="2004-05-05" seq="2004-2002" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc">20050502-01-P</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10287">10287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16158">irix-udp-dos(16158)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5 20"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22m"/><vers num="6.5.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2003" published="2004-05-06" seq="2004-2003" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108386181021070&amp;w=2">20040506 [0xbadc0ded #03] DeleGate (SSL-filter) &lt;= 8.9.2</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10295">10295</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11569">11569</ref><ref source="OSVDB" url="http://www.osvdb.org/5945">5945</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16078">delegate-sslway-bo(16078)</ref></refs><vuln_soft><prod name="DeleGate" vendor="DeleGate"><vers num="7.7.0"/><vers num="7.7.1"/><vers num="7.8.0"/><vers num="7.8.1"/><vers num="7.8.2"/><vers num="7.9.11"/><vers num="8.3.3"/><vers num="8.3.4"/><vers num="8.4.0"/><vers num="8.5.0"/><vers num="8.9"/><vers num="8.9.1"/><vers num="8.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2004" published="2004-05-06" seq="2004-2004" severity="High" type="CVE"><desc><descript source="cve">The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10297">10297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16084">livecd-ssh-gain-access(16084)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers edition="Personal" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2005" published="2004-05-06" seq="2004-2005" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108395487628044&amp;w=2">20040507 Eudora file URL buffer overflow</ref><ref source="CONFIRM" url="http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt">http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10298">10298</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11568">11568</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16086">eudora-long-url-bo(16086)</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="5.2.1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.3"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-2006" published="2004-05-07" seq="2004-2006" severity="Medium" type="CVE"><desc><descript source="cve">Trend Micro OfficeScan 3.0 - 6.0 has default permissions of &quot;Everyone Full Control&quot; on the installation directory and registry keys, which allows local users to disable virus protection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108395366909344&amp;w=2">20040507 Security issue with Trend OfficeScan Corporate Edition</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10300">10300</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11576">11576</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16092">officescan-configuration-modify(16092)</ref><ref source="OSVDB" url="http://www.osvdb.org/5990">5990</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers edition="Corporate" num="3.0"/><vers num="Corporate 3.5"/><vers num="Corporate 3.11"/><vers num="Corporate 3.13"/><vers num="Corporate 3.54"/><vers num="Corporate 5.02"/><vers num="Corporate 5.58"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2007" published="2004-05-08" seq="2004-2007" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10306">10306</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16096">nukejokes-modules-xss(16096)</ref></refs><vuln_soft><prod name="NukeJokes" vendor="Adam Webb"><vers num="1.7"/><vers num="2.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2008" published="2004-05-08" seq="2004-2008" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=28">http://www.waraxe.us/index.php?modname=sa&amp;id=28</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10306">10306</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11579">11579</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16099">nukejokes-sql-injection(16099)</ref></refs><vuln_soft><prod name="NukeJokes" vendor="Adam Webb"><vers num="1.7"/><vers num="2.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2009" published="2004-05-08" seq="2004-2009" severity="Medium" type="CVE"><desc><descript source="cve">NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16094">nukejokes-multiple-path-disclosure(16094)</ref></refs><vuln_soft><prod name="NukeJokes" vendor="Adam Webb"><vers num="1.7"/><vers num="2.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-2010" published="2004-12-31" seq="2004-2010" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420702317870&amp;w=2">20040509 Arbitrary code inclusion in phpShop</ref><ref source="MISC" url="http://www.fribble.net/advisories/phpshop_29-04-04.txt">http://www.fribble.net/advisories/phpshop_29-04-04.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/10313">10313</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11587">11587</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16107">phpshop-basedir-file-include(16107)</ref></refs><vuln_soft><prod name="phpShop" vendor="phpShop"><vers num="0.7"/><vers num="0.7.1"/><vers num="0.6.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2004-2011" published="2004-12-31" seq="2004-2011" severity="Low" type="CVE"><desc><descript source="cve">msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single &amp; (ampersand) in a &lt;Ref href&gt; link, which triggers a parsing error, possibly due to missing portions of the URI.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422549617947&amp;w=2">20040510 msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16112">msxml3-ampersand-dos(16112)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2600"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2012" published="2004-12-31" seq="2004-2012" severity="High" type="CVE"><desc><descript source="cve">The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108432258920570&amp;w=2">20040510 Advisory 04/2004: Net(Free)BSD Systrace local root vulnerabilitiy</ref><ref source="BID" url="http://www.securityfocus.com/bid/10320">10320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11585">11585</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16110">systrace-gain-privileges(16110)</ref></refs><vuln_soft><prod name="Systrace Port for FreeBSD" vendor="Vladimir Kotal"><vers num="2004-06-02"/><vers num="2004-03-09"/></prod><prod name="Provos Systrace" vendor="Niels"><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2013" published="2004-12-31" seq="2004-2013" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-05/0091.html">20040511 Linux Kernel sctp_setsockopt() Integer Overflow</ref><ref patch="1" source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108456230815842&amp;w=2">2004-0029</ref><ref source="BID" url="http://www.securityfocus.com/bid/10326">10326</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16117">linux-sctpsetsockopt-integer-bo(16117)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/><vers num="2.0.15"/><vers num="2.0.16"/><vers num="2.0.17"/><vers num="2.0.18"/><vers num="2.0.19"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.24"/><vers num="2.0.25"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="2.0.28"/><vers num="2.0.29"/><vers num="2.0.30"/><vers num="2.0.31"/><vers num="2.0.32"/><vers num="2.0.33"/><vers num="2.0.34"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.1"/><vers num="2.1.89"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.2.25"/><vers num="2.3"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2014" published="2004-12-31" seq="2004-2014" severity="Low" type="CVE"><desc><descript source="cve">Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481268725276&amp;w=2">20040516 Wget race condition vulnerability</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=wget&amp;m=108482747906833&amp;w=2">[wget] 20040517 Wget race condition vulnerability (fwd)</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=wget&amp;m=108483270227139&amp;w=2">[wget] 20040517 Re: Wget race condition vulnerability (fwd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10361">10361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16167">wget-lock-race-condition(16167)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1">USN-145-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-771.html">RHSA-2005:771</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:204">MDKSA-2005:204</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17399">17399</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:204">MDKSA-2005:204</ref></refs><vuln_soft><prod name="wget" vendor="GNU"><vers num="1.5.3"/><vers num="1.6"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-2015" published="2004-12-31" seq="2004-2015" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481256731404&amp;w=2">20040517 WebCT: Cross Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/10357">10357</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16156">webct-iframe-img-tags-xss(16156)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0851.html">20040516 WebCT: Cross Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="WebCT" vendor="WebCT"><vers num="Campus 4.0 SP3 Hotfix 40833"/><vers num="Campus 4.0"/><vers num="Campus 4.1 SP2 Hotfix 40832"/><vers num="Campus 4.1"/><vers num="Campus 4.1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2016" published="2004-12-31" seq="2004-2016" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481422130354&amp;w=2">20040517 NetChat HTTP Server Stack Overflow</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10353">10353</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11637">11637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16165">netchat-sprintf-bo(16165)</ref></refs><vuln_soft><prod name="Subnet Chat Application" vendor="NetChat"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2017" published="2004-12-31" seq="2004-2017" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481571131866&amp;w=2">20040517 Multiple TTT-C XSS vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10359">10359</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11623">11623</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16164">turbotraffictraderc-multiple-xss(16164)</ref><ref source="OSVDB" url="http://www.osvdb.org/6339">6339</ref><ref source="OSVDB" url="http://www.osvdb.org/6340">6340</ref><ref source="OSVDB" url="http://www.osvdb.org/6341">6341</ref><ref source="OSVDB" url="http://www.osvdb.org/6342">6342</ref><ref source="OSVDB" url="http://www.osvdb.org/6343">6343</ref><ref source="OSVDB" url="http://www.osvdb.org/6344">6344</ref></refs><vuln_soft><prod name="TurboTrafficTrader C" vendor="TurboTrafficTrader"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-2018" published="2004-12-31" seq="2004-2018" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482888621896&amp;w=2">20040517 [waraxe-2004-SA#029 - Possible remote file inclusion in PhpNuke 6.x - 7.3]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=29">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref><ref source="BID" url="http://www.securityfocus.com/bid/10365">10365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11625">11625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16218">phpnuke-modpath-file-include(16218)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0870.html">20040517 [waraxe-2004-SA#029 - Possible remote file inclusion in PhpNuke 6.x - 7.3]</ref><ref source="OSVDB" url="http://www.osvdb.org/6222">6222</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2019" published="2004-12-31" seq="2004-2019" severity="Medium" type="CVE"><desc><descript source="cve">The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482957715299&amp;w=2">20040517 [waraxe-2004-SA#030 - Multiple vulnerabilities in PhpNuke 6.x - 7.3]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=29">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref><ref source="BID" url="http://www.securityfocus.com/bid/10367">10367</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11625">11625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16170">phpnuke-show-weblink-path-disclosure(16170)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2020" published="2004-12-31" seq="2004-2020" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482957715299&amp;w=2">20040517 [waraxe-2004-SA#030 - Multiple vulnerabilities in PhpNuke 6.x - 7.3]</ref><ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=29">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref><ref source="BID" url="http://www.securityfocus.com/bid/10367">10367</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11625">11625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16172">phpnuke-multi-xss(16172)</ref><ref source="OSVDB" url="http://www.osvdb.org/6225">6225</ref><ref source="OSVDB" url="http://www.osvdb.org/6226">6226</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2021" published="2004-12-31" seq="2004-2021" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482902101519&amp;w=2">20040517 oscommerce 2.2 file_manager.php file browsing</ref><ref source="BID" url="http://www.securityfocus.com/bid/10364">10364</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11624">11624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16174">oscommerce-dotdot-directory-traversal(16174)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0378.html">20050322 osCommerce File Manager Directory Traversal Vulnerability</ref><ref source="MISC" url="http://www.excluded.org/advisories/advisory13.txt">http://www.excluded.org/advisories/advisory13.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/6308">6308</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010176">1010176</ref></refs><vuln_soft><prod name="osCommerce" vendor="osCommerce"><vers num="2.1"/><vers num="2.2 ms3"/><vers num="2.2 ms2"/><vers num="2.2 ms1"/><vers num="2.2 cvs"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2022" published="2004-12-31" seq="2004-2022" severity="Low" type="CVE"><desc><descript source="cve">ActivePerl 5.8.x and others, and Larry Wall&apos;s Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow.  NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108482796105922&amp;w=2">20040517 Buffer Overflow in ActivePerl ?</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108489894009025&amp;w=2">20040518 RE: [Full-Disclosure] Re: Buffer Overflow in ActivePerl ?</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108483058514596&amp;w=2">20040517 RE: Buffer Overflow in ActivePerl ?</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108489112131099&amp;w=2">20040518 Re: Buffer Overflow in ActivePerl ?</ref><ref source="MISC" url="http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt">http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt</ref><ref source="MISC" url="http://www.perlmonks.org/index.pl?node_id=354145">http://www.perlmonks.org/index.pl?node_id=354145</ref><ref source="BID" url="http://www.securityfocus.com/bid/10375">10375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16169">perl-system-bo(16169)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html">20040518 Re[2]: [Full-Disclosure] Buffer Overflow in ActivePerl ?</ref></refs><vuln_soft><prod name="ActivePerl" vendor="ActiveState"><vers num="5.6.1.630"/><vers num="5.6.1"/><vers num="5.6.2"/><vers num="5.6.3"/><vers num="5.7.1"/><vers num="5.7.2"/><vers num="5.7.3"/><vers num="5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2023" published="2004-12-31" seq="2004-2023" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108489697219781&amp;w=2">20040518 Zen Cart login.php SQL Injection Vulnerability</ref><ref adv="1" source="CONFIRM" url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=4835">http://www.zen-cart.com/modules/ipb/index.php?showtopic=4835</ref><ref patch="1" source="CONFIRM" url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref><ref source="MISC" url="http://securitytracker.com/id?1010172">http://securitytracker.com/id?1010172</ref><ref source="BID" url="http://www.securityfocus.com/bid/10378">10378</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11649">11649</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16176">zencart-login-sql-injection(16176)</ref><ref source="MISC" url="http://www.packetstormsecurity.org/0405-advisories/zencart112d.txt">http://www.packetstormsecurity.org/0405-advisories/zencart112d.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/6298">6298</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434237/30/4950/threaded">
20060517 Re: Zen Cart login.php SQL Injection Vulnerability</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.1.2d"/><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2024" published="2004-12-31" seq="2004-2024" severity="High" type="CVE"><desc><descript source="cve">The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=4873">http://www.zen-cart.com/modules/ipb/index.php?showtopic=4873</ref><ref patch="1" source="CONFIRM" url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2025" published="2004-12-31" seq="2004-2025" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref><ref source="" url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=3731">http://www.zen-cart.com/modules/ipb/index.php?showtopic=3731</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2026" published="2004-12-31" seq="2004-2026" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0343.html">20040507 Pound &lt;=1.5 Remote Exploit (Format string bug)</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-08.xml">GLSA-200405-08</ref><ref source="CONFIRM" url="http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000">http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000</ref><ref source="MISC" url="http://securitytracker.com/id?1010034">http://securitytracker.com/id?1010034</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10267">10267</ref><ref source="OSVDB" url="http://www.osvdb.org/5746">5746</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11528">11528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16033">pound-logmsg-format-string(16033)</ref></refs><vuln_soft><prod name="Pound" vendor="Apsis"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2027" published="2004-05-10" seq="2004-2027" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0378.html">20040509 Icecast 2.0.0 preauth overflow</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-10.xml">GLSA-200405-10</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10311">10311</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6075">6075</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11578">11578</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16103">icecast-auth-request-bo(16103)</ref></refs><vuln_soft><prod name="Icecast" vendor="Icecast"><vers num="2.0.0"/><vers num="1.3.9.2"/><vers num="1.3.9.1"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7.1"/><vers num="1.3.7"/><vers num="1.3.5.1"/><vers num="1.3.5"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10.1"/><vers num="1.3.10"/><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2028" published="2004-05-21" seq="2004-2028" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515632622796&amp;w=2">20040521 e107 web portal Referers HTTP Injection</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10395">10395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11693">11693</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16231">e107-log-xss(16231)</ref><ref source="OSVDB" url="http://www.osvdb.org/6345">6345</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.6_15a"/><vers num="0.6_15"/><vers num="0.6_14"/><vers num="0.6_13"/><vers num="0.6_12"/><vers num="0.6_11"/><vers num="0.6_10"/><vers num="0.545"/><vers num="0.554"/><vers num="0.555 Beta"/><vers num="0.603"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2029" published="2004-05-22" seq="2004-2029" severity="Medium" type="CVE"><desc><descript source="cve">The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a &quot;A==&quot; value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108526361421535&amp;w=2">20040522 BNBT BitTorrent Tracker Denial Of Service</ref><ref adv="1" source="MISC" url="http://fux0r.phathookups.com/advisory/sp-x12-advisory.txt">http://fux0r.phathookups.com/advisory/sp-x12-advisory.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10399">10399</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11684">11684</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16228">bittorrent-http-get-dos(16228)</ref><ref source="OSVDB" url="http://www.osvdb.org/6336">6336</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010254">1010254</ref></refs><vuln_soft><prod name="BNBT" vendor="Trevor Hogan"><vers num="7.5 Beta Release2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-2030" published="2004-05-22" seq="2004-2030" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject abitrary web script or HTML, as demonstrated using the message subject.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108526683823840&amp;w=2">20040522 Liferay Cross Site Scripting Flaw</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110141194202856&amp;w=2">20041125 Re: Liferay Cross Site Scripting Flaw</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10402">10402</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6346">6346</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11692">11692</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16232">liferay-message-xss(16232)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=252060"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010259">1010259</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="2.1.1" prev="1"/><vers num="2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2031" published="2004-05-21" seq="2004-2031" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108541119526279&amp;w=2">20040522 e107 web portal user.php XSS (Cross Site Scripting)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10405">10405</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6410">6410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11696">11696</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16241">e107-user-xss(16241)</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.615a"/><vers num="0.615"/><vers num="0.614"/><vers num="0.613"/><vers num="0.612"/><vers num="0.611"/><vers num="0.610"/><vers num="0.545"/><vers num="0.554"/><vers num="0.555 Beta"/><vers num="0.603"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2032" published="2004-05-24" seq="2004-2032" severity="High" type="CVE"><desc><descript source="cve">Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108541203427391&amp;w=2">20040524 Netgear RP114 URL filter fails if URL is too long</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10404">10404</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6411">6411</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11698">11698</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16238">netgearrp114-long-url-filter-bypass(16238)</ref></refs><vuln_soft><prod name="RP114" vendor="NetGear"><vers num="3.26"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2033" published="2004-05-26" seq="2004-2033" severity="Medium" type="CVE"><desc><descript source="cve">Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108559623703422&amp;w=2">20040526 Orenosv HTTP/FTP Server Denial Of Service</ref><ref adv="1" source="CONFIRM" url="http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html">http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10420">10420</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6419">6419</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11706">11706</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16250">orenosv-http-get-dos(16250)</ref></refs><vuln_soft><prod name="Orenosv HTTP FTP Server" vendor="Orenosv"><vers num="0.5.9f"/><vers num="0.5.9e"/><vers num="0.5.9c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2034" published="2004-01-29" seq="2004-2034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108569235217149&amp;w=2">20040527 WildTangent Web Driver Long FileName Stack Overflow</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/wildtangent.txt">http://www.ngssoftware.com/advisories/wildtangent.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10421">10421</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6445">6445</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11727">11727</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16266">wildtangent-wthoster-webdriver-bo(16266)</ref></refs><vuln_soft><prod name="WebDriver" vendor="WildTangent"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2035" published="2004-05-26" seq="2004-2035" severity="Medium" type="CVE"><desc><descript source="cve">MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108563992129877&amp;w=2">20040527 DoS in MiniShare 1.3.2</ref><ref adv="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/MiniShare1.3.2-adv.txt">http://www.autistici.org/fdonato/advisory/MiniShare1.3.2-adv.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=241158">http://sourceforge.net/project/shownotes.php?release_id=241158</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6432">6432</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10417">10417</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11715">11715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16260">minishare-get-head-dos(16260)</ref></refs><vuln_soft><prod name="Minimal HTTP Server" vendor="MiniShare"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-2036" published="2004-05-28" seq="2004-2036" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108577011129476&amp;w=2">20040528 JPortal SQL Injects</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/unixfocus/5HP020KD5K.html">http://www.securiteam.com/unixfocus/5HP020KD5K.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10430">10430</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6503">6503</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11737">11737</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16272">jportal-printincphp-sql-injection(16272)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010327">1010327</ref></refs><vuln_soft><prod name="JPortal Web Portal" vendor="JPortal"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2037" published="2004-03-24" seq="2004-2037" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the &quot;cd&quot; command in an interactive FTP client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108577846011604&amp;w=2">20040528 Mollensoft ftp Server ver 3.6 Buffer overflow</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611230015042&amp;w=2">20040601 Mollensoft Lightweight FTP Server CWD Buffer Overflow</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10409">10409</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10429">10429</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6412">6412</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16237">mollensoft-cwd-command-bo(16237)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16303">mollensoft-cd-bo(16303)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010328">1010328</ref></refs><vuln_soft><prod name="Lightweight FTP Server" vendor="Mollensoft Software"><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-2038" published="2004-05-29" seq="2004-2038" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108585789220174&amp;w=2">20040529 LDU (land down under) xss vulnerability</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6508">6508</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6510">6510</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6511">6511</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11739">11739</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16284">ldu-bbcode-xss(16284)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10435">10435</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/May/1010335.html">1010335</ref></refs><vuln_soft><prod name="Land Down Under" vendor="Neocrome"><vers num="700.03" prev="1"/><vers num="700.02"/><vers num="700.01"/><vers num="602"/><vers num="601"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2039" published="2004-05-29" seq="2004-2039" severity="Medium" type="CVE"><desc><descript source="cve">e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=31">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6525">6525</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11740">11740</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16277">e107-multiplescripts-path-disclosure(16277)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10436">10436</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.6_15a"/><vers num="0.6_15"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2040" published="2004-05-29" seq="2004-2040" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) &quot;email article to a friend&quot; field, (3) &quot;submit news&quot; field, or (4) avmsg parameter to usersettings.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=31">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10436">10436</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6526">6526</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6527">6527</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6528">6528</ref><ref source="OSVDB" url="http://www.osvdb.org/6529">6529</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11740">11740</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16281">e107-user-setting-xss(16281)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16279">e107-clock-menu-xss(16279)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16280">e107-email-friend-xss(16280)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.6_15a"/><vers num="0.6_15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-2041" published="2004-05-29" seq="2004-2041" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=31">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10436">10436</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6530">6530</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11740">11740</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16282">e107-secure-img-render-file-include(16282)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.6_15a"/><vers num="0.6_15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2042" published="2004-05-29" seq="2004-2042" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref><ref adv="1" patch="1" source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=31">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/10436">10436</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6531">6531</ref><ref adv="1" sig="1" source="OSVDB" url="http://www.osvdb.org/6532">6532</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/6533">6533</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11740">11740</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16283">e107-content-news-sql-injection(16283)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.615a"/><vers num="0.615"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-2043" published="2004-05-01" seq="2004-2043" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611386202493&amp;w=2">20040601 Firebird Database Remote Database Name Overflow</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/unixfocus/5AP0P0UCUO.html">http://www.securiteam.com/unixfocus/5AP0P0UCUO.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10446">10446</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6408">6408</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11756">11756</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16229">firebird-database-name-bo(16229)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0027.html">20040602 Firebird [ AND Interbase 7 ] Database Remote Database Name Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/6624">6624</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010381">1010381</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16316">interbase-database-name-bo(16316)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1014">DSA-1014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19350">19350</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="1.0"/></prod><prod name="InterBase SuperServer" vendor="Borland Software"><vers num="6.0"/></prod><prod name="Interbase" vendor="Borland Software"><vers num="4.0"/><vers num="5.0"/><vers num="6.0"/><vers num="6.4"/><vers num="6.5"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2044" published="2004-06-01" seq="2004-2044" severity="High" type="CVE"><desc><descript source="cve">PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER[&apos;PHP_SELF&apos;] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the &quot;admin.php&quot; string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611643614881&amp;w=2">20040601 [Squid 2004-Nuke-001] Inadequate Security Checking in PHPNuke</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108662955105757&amp;w=2">20040606 Re: [Squid 2004-Nuke-001] Inadequate Security Checking in PHPNuke</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611606320559&amp;w=2">20040601 [Squid 2004-betaNC-001] Inadequate Security Checking in NukeCops</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10447">10447</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/6593">6593</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11766">11766</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16296">osc2nuke-eregi-path-disclosure(16296)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16297">oscnukelite-eregi-path-disclosure(16297)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16294">phpnuke-eregi-path-disclosure(16294)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16298">nukecops-ergei-path-disclosure(16298)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0006.html">20040601 [Squid 2004-OSC2Nuke-001] Inadequate Security Checking in OSC2Nuke</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0005.html">20040601 [Squid 2004-betaNC-001] Inadequate Security Checking in NukeCops betaNC Bundle</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/></prod><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.2a"/><vers num="5.2"/><vers num="5.3.1"/><vers num="5.4"/><vers num="5.5"/><vers num="5.6"/><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/></prod><prod name="Osc2Nuke" vendor="osCommerce"><vers num="7x 1.0"/></prod><prod name="BetaNC PHP-Nuke" vendor="Paul Laudanski"><vers num="Bundle"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2045" published="2004-12-31" seq="2004-2045" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109045084522857&amp;w=2">20040721 Denial of Service in Conceptronic CADSLR1 Router</ref><ref source="MISC" url="http://www.shellsec.net/leer_advisory.php?id=5">http://www.shellsec.net/leer_advisory.php?id=5</ref><ref source="BID" url="http://www.securityfocus.com/bid/10769">10769</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12110">12110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16746">conceptronic-long-username-dos(16746)</ref></refs><vuln_soft><prod name="CADSLR1 ADSL router" vendor="Conceptronic"><vers num="3.04n"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-2046" published="2004-12-31" seq="2004-2046" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109061480026378&amp;w=2">20040721 APC Security Advisory  Denial of Service Vulnerability with PowerChute Business Edition</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2004/Jul/1010745.html">http://www.securitytracker.com/alerts/2004/Jul/1010745.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10777">10777</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12124">12124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16767">powerchute-console-dos(16767)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010745">1010745</ref><ref source="OSVDB" url="http://www.osvdb.org/8187">8187</ref></refs><vuln_soft><prod name="PowerChute" vendor="APC"><vers num="Business 6.0"/><vers num="Business 7.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2047" published="2004-07-23" seq="2004-2047" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068482605241&amp;w=2">20040724 EasyWeb FileManager Directory Traversal</ref><ref adv="1" source="MISC" url="http://www.cirt.net/advisories/ew_file_manager.shtml">http://www.cirt.net/advisories/ew_file_manager.shtml</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10792">10792</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/8193">8193</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12151">12151</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16806">filemanager-pathext-view-directory-traversal(16806)</ref></refs><vuln_soft><prod name="EasyWeb FileManager" vendor="EasyWeb"><vers num="1.0 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2048" published="2004-12-31" seq="2004-2048" severity="High" type="CVE"><desc><descript source="cve">radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default &quot;jstwo&quot; password, which allows remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10794">10794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12154">12154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16790">thintune-password-gain-access(16790)</ref><ref source="OSVDB" url="http://www.osvdb.org/8246">8246</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010770">1010770</ref></refs><vuln_soft><prod name="Thintune XS" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune Mobile" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune S" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune XM" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune M" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune eXtreme" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune L" vendor="eSeSIX"><vers num="2.4.38"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2049" published="2004-12-31" seq="2004-2049" severity="Medium" type="CVE"><desc><descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10794">10794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12154">12154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16795">thintune-plaintext-passwords(16795)</ref><ref source="OSVDB" url="http://www.osvdb.org/8247">8247</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010770">1010770</ref></refs><vuln_soft><prod name="Thintune XS" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune Mobile" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune S" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune XM" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune M" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune eXtreme" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune L" vendor="eSeSIX"><vers num="2.4.38"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2050" published="2004-12-31" seq="2004-2050" severity="Medium" type="CVE"><desc><descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the &quot;maertsJ&quot; password, which is hard-coded into lshell.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10794">10794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12154">12154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16808">thintune-password-gain-privileges(16808)</ref><ref source="OSVDB" url="http://www.osvdb.org/8248">8248</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010770">1010770</ref></refs><vuln_soft><prod name="Thintune XS" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune Mobile" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune S" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune XM" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune M" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune eXtreme" vendor="eSeSIX"><vers num="2.4.38"/></prod><prod name="Thintune L" vendor="eSeSIX"><vers num="2.4.38"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2051" published="2004-07-24" seq="2004-2051" severity="Medium" type="CVE"><desc><descript source="cve">The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10794">10794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12154">12154</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16798">thintune-url-obtain-information(16798)</ref><ref source="OSVDB" url="http://www.osvdb.org/8249">8249</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010770">1010770</ref></refs><vuln_soft><prod name="Thintune XS" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune Mobile" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune S" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune XM" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune M" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune eXtreme" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod><prod name="Thintune L" vendor="eSeSIX"><vers num="2.4.38 Firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2052" published="2004-12-31" seq="2004-2052" severity="High" type="CVE"><desc><descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref></refs><vuln_soft><prod name="Thintune" vendor="eSeSIX"><vers num="2.4.38" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2053" published="2004-07-24" seq="2004-2053" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109069241512694&amp;w=2">20040724 Easyins Stadtportal</ref><ref source="MISC" url="http://securitytracker.com/id?1010769">http://securitytracker.com/id?1010769 </ref><ref source="BID" url="http://www.securityfocus.com/bid/10795">10795</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16797">easyins-php-file-include(16797)</ref><ref source="OSVDB" url="http://www.osvdb.org/8233">8233</ref></refs><vuln_soft><prod name="EasyIns" vendor="EasyIns"><vers num="Stadtportal 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2054" published="2004-12-31" seq="2004-2054" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034476122723&amp;w=2">20040720 PhpBB HTTP Response Splitting &amp; Cross Site Scripting vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/10753">10753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16759">phpbb-search-response-splitting(16759)</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2055" published="2004-07-19" seq="2004-2055" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034476122723&amp;w=2">20040720 PhpBB HTTP Response Splitting &amp; Cross Site Scripting vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10753">10753</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16758">phpbb-search-searchauthor-xss(16758)</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2056" published="2004-12-31" seq="2004-2056" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers execute arbitrary SQL statements via the itemid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109087144509299&amp;w=2">20040725 NucleusCMS 3.01 SQL Injection Vulnerability</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13136">13136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18002">nucleus-sql-injection(18002)</ref></refs><vuln_soft><prod name="Nucleus CMS" vendor="Nucleus Group"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2057" published="2004-12-31" seq="2004-2057" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="MISC" url="http://ferruh.mavituna.com/article/?574">http://ferruh.mavituna.com/article/?574</ref><ref source="BID" url="http://www.securityfocus.com/bid/10799">10799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12164">12164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16799">asprunner-sql-injection(16799)</ref><ref source="OSVDB" url="http://www.osvdb.org/8251">8251</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010777">1010777</ref></refs><vuln_soft><prod name="ASPRunner" vendor="XLineSoft"><vers num="1.0"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2058" published="2004-12-31" seq="2004-2058" severity="Medium" type="CVE"><desc><descript source="cve">ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="MISC" url="http://ferruh.mavituna.com/article/?574">http://ferruh.mavituna.com/article/?574</ref><ref source="BID" url="http://www.securityfocus.com/bid/10799">10799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12164">12164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16800">asprunner-information-disclosure(16800)</ref><ref source="OSVDB" url="http://www.osvdb.org/8252">8252</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010777">1010777</ref></refs><vuln_soft><prod name="ASPRunner" vendor="XLineSoft"><vers num="1.0"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2059" published="2004-12-31" seq="2004-2059" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="MISC" url="http://ferruh.mavituna.com/article/?574">http://ferruh.mavituna.com/article/?574</ref><ref source="BID" url="http://www.securityfocus.com/bid/10799">10799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12164">12164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16801">asprunner-xss(16801)</ref><ref source="OSVDB" url="http://www.osvdb.org/8254">8254</ref><ref source="OSVDB" url="http://www.osvdb.org/8255">8255</ref><ref source="OSVDB" url="http://www.osvdb.org/8256">8256</ref><ref source="OSVDB" url="http://www.osvdb.org/8257">8257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010777">1010777</ref></refs><vuln_soft><prod name="ASPRunner" vendor="XLineSoft"><vers num="1.0"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2060" published="2004-12-31" seq="2004-2060" severity="Medium" type="CVE"><desc><descript source="cve">ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html">20040726 ASPRunner Multiple Vulnerabilities</ref><ref source="MISC" url="http://ferruh.mavituna.com/article/?574">http://ferruh.mavituna.com/article/?574</ref><ref source="BID" url="http://www.securityfocus.com/bid/10799">10799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12164">12164</ref><ref source="OSVDB" url="http://www.osvdb.org/8253">8253</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010777">1010777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16802">asprunner-database-file-access(16802)</ref></refs><vuln_soft><prod name="ASPRunner" vendor="XLineSoft"><vers num="1.0"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2061" published="2004-07-27" seq="2004-2061" severity="High" type="CVE"><desc><descript source="cve">RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109095196526490&amp;w=2">20040727 IRM 009: RiSearch and RiSearch ProPro are vulnerable to open FTP/HTTP proxy, directory listings and file disclosure vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10812">10812</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12173">12173</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16817">risearch-show-open-proxy(16817)</ref><ref source="OSVDB" url="http://www.osvdb.org/8265">8265</ref><ref source="OSVDB" url="http://www.osvdb.org/8266">8266</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010788">1010788</ref></refs><vuln_soft><prod name="RiSearch Pro" vendor="RiSearch Software"><vers num="3.2.6"/></prod><prod name="RiSearch" vendor="RiSearch Software"><vers num="0.99.1"/><vers num="0.99.2"/><vers num="0.99.3"/><vers num="0.99.4"/><vers num="0.99.5"/><vers num="0.99.6"/><vers num="0.99.7"/><vers num="0.99.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2062" published="2004-12-31" seq="2004-2062" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109105610220965&amp;w=2">20040728 AntiBoard &lt;= 0.7.2 XSS/SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/10821">10821</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12137">12137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16828">antiboard-get-sql-injection(16828)</ref></refs><vuln_soft><prod name="AntiBoard" vendor="AntiBoard"><vers num="0.6"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2063" published="2004-12-31" seq="2004-2063" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109105610220965&amp;w=2">20040728 AntiBoard &lt;= 0.7.2 XSS/SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/10821">10821</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12137">12137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16830">antiboard-feedback-xss(16830)</ref><ref source="OSVDB" url="http://www.osvdb.org/8269">8269</ref></refs><vuln_soft><prod name="AntiBoard" vendor="AntiBoard"><vers num="0.6"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.61"/><vers num="0.62"/><vers num="0.63"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-2064" published="2004-07-29" seq="2004-2064" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109112282611808&amp;w=2">20040729 lostBook v1.1 Javascript Execution</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10825">10825</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12190">12190</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16835">lostbook-email-website-xss(16835)</ref><ref source="OSVDB" url="http://www.osvdb.org/8271">8271</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010812">1010812</ref></refs><vuln_soft><prod name="lostBook" vendor="Verylost"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2065" published="2004-12-31" seq="2004-2065" severity="High" type="CVE"><desc><descript source="cve">DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109113126217408&amp;w=2">20040729 DansGuardian Hex Encoding URL Banned Extension Filter Bypass</ref><ref source="CONFIRM" url="http://dansguardian.org/?page=history">http://dansguardian.org/?page=history</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/10823">10823</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12191">12191</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16836">dansguardian-filename-bypass-filtering(16836)</ref><ref source="OSVDB" url="http://www.osvdb.org/8270">8270</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010817">1010817</ref></refs><vuln_soft><prod name="DansGuardian" vendor="Daniel Barron"><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7.1"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9.1"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.4.5.1"/><vers num="2.6.1.5"/><vers num="2.7.3.1"/><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2066" published="2004-07-29" seq="2004-2066" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109112246805277&amp;w=2">20040729 Linpha 0.9.4: authentication bypass</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10827">10827</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12189">12189</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16834">linpha-cookie-gain-access(16834)</ref><ref source="OSVDB" url="http://www.osvdb.org/8272">8272</ref></refs><vuln_soft><prod name="LinPHA" vendor="LinPHA"><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-2067" published="2004-07-29" seq="2004-2067" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109116345930380&amp;w=2">20040729 Jaws 0.4: authentication bypass</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/10826">10826</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/16847">jaws-controlpanel-sql-injection(16847)</ref><ref source="OSVDB" url="http://www.osvdb.org/8320">8320</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1010815">1010815</ref></refs><vuln_soft><prod name="JAWS" vendor="JAWS"><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2068" published="2004-12-31" seq="2004-2068" severity="Medium" type="CVE"><desc><descript source="cve">fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an emptry NNTP news article with missing mandatory headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://leafnode.sourceforge.net/leafnode-SA-2004-01.txt">http://leafnode.sourceforge.net/leafnode-SA-2004-01.txt</ref><ref source="VULNWATCH" url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2004-01/0009.html">20040109 leafnode -1.9.47 security announcement SA-2004-01</ref><ref source="OSVDB" url="http://www.osvdb.org/3441">3441</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10590">10590</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14189">leafnode-fetchnews-nntp-dos(14189)</ref></refs><vuln_soft><prod name="Leafnode" vendor="Leafnode"><vers num="1.9.47"/><vers num="1.9.46"/><vers num="1.9.45"/><vers num="1.9.44"/><vers num="1.9.43"/><vers num="1.9.42"/><vers num="1.9.41"/><vers num="1.9.40"/><vers num="1.9.39"/><vers num="1.9.38"/><vers num="1.9.37"/><vers num="1.9.36"/><vers num="1.9.35"/><vers num="1.9.34"/><vers num="1.9.33"/><vers num="1.9.32"/><vers num="1.9.31"/><vers num="1.9.30"/><vers num="1.9.29"/><vers num="1.9.28"/><vers num="1.9.27"/><vers num="1.9.26"/><vers num="1.9.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-2069" published="2004-12-31" seq="2004-2069" severity="Medium" type="CVE"><desc><descript source="cve">sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107520317020444&amp;w=2">[openssh-unix-dev] 20040127 OpenSSH - Connection problem when LoginGraceTime exceeds time</ref><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107529205602320&amp;w=2">[openssh-unix-dev] 20040128 Re: OpenSSH - Connection problem when LoginGraceTime exceeds time</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107520317020444&amp;w=2">[openssh-unix-dev] 20040127 OpenSSH - Connection problem when LoginGraceTime exceeds time</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107529205602320&amp;w=2">[openssh-unix-dev] 20040128 Re: OpenSSH - Connection problem when LoginGraceTime exceeds time</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded">FLSA-2006:168935</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-550.html">RHSA-2005:550</ref><ref source="BID" url="http://www.securityfocus.com/bid/14963">14963</ref><ref source="OSVDB" url="http://www.osvdb.org/16567">16567</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20930">openssh-sshdc-logingracetime-dos(20930)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17252">17252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17000">17000</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23680">23680</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.6.1 p2"/><vers num="3.7.1 p2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2004-2070" published="2004-12-31" seq="2004-2070" severity="High" type="CVE"><desc><descript source="cve">The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/381649">20041119 Privilege escalation flaw in AClient Service for Windows (Version 5.6.181).</ref></refs><vuln_soft><prod name="Client Service" vendor="Altiris"><vers edition="Windows SP1 Hotfix E" num="5.6.181"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2071" published="2004-12-31" seq="2004-2071" severity="High" type="CVE"><desc><descript source="cve">Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes (&quot;//&quot;) after the server name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9646">9646</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15194">macallan-gain-unauthorized-access(15194)</ref><ref source="OSVDB" url="http://www.osvdb.org/3926">3926</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009030">1009030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10861">10861</ref></refs><vuln_soft><prod name="Mail Solution" vendor="Macallan"><vers num="2.8.4.6 Build 260"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2072" published="2004-12-31" seq="2004-2072" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.systemsecure.org/advisories/ssadvisory06022004.php">http://www.systemsecure.org/advisories/ssadvisory06022004.php</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15062">mambo-itemid-xss(15062)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9588">9588</ref></refs><vuln_soft><prod name="Mambo Open Source" vendor="Mambo"><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2073" published="2004-02-06" seq="2004-2073" severity="High" type="CVE"><desc><descript source="cve">Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353003">20040206 Linux 2.4.24 with vserver 1.24 exploit</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.linux-vserver.org/index.php?page=ChangeLog">http://www.linux-vserver.org/index.php?page=ChangeLog</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15073">linux-vserver-gain-privileges(15073)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9596">9596</ref><ref source="OSVDB" url="http://www.osvdb.org/3875">3875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10816">10816</ref></refs><vuln_soft><prod name="Linux-VServer" vendor="VServer"><vers num="1.20"/><vers num="1.21"/><vers num="1.22"/><vers num="1.23"/><vers num="1.24"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2074" published="2004-12-31" seq="2004-2074" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/9800">9800</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009295">1009295</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15380">dreamftp-command-format-string(15380)</ref></refs><vuln_soft><prod name="Dream FTP Server" vendor="BolinTech"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-2075" published="2004-12-31" seq="2004-2075" severity="Medium" type="CVE"><desc><descript source="cve">Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.sophos.com/support/news/#mime-378">http://www.sophos.com/support/news/#mime-378</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9648">9648</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15191">sophos-mime-header-dos(15191)</ref><ref source="OSVDB" url="http://www.osvdb.org/3925">3925</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009042">1009042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10855">10855</ref></refs><vuln_soft><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.46"/><vers num="3.78"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2076" published="2004-12-31" seq="2004-2076" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353869">20040213 vBulletin PHP Forum Version</ref><ref source="BID" url="http://www.securityfocus.com/bid/9656">9656</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15208">vbulletin-search-xss(15208)</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2077" published="2004-02-08" seq="2004-2077" severity="Medium" type="CVE"><desc><descript source="cve">Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353182">20040208 TrackMania Demo Denial of Service</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353226">20040209 Re: TrackMania Demo Denial of Service</ref><ref adv="1" source="MISC" url="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9604">9604</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15081">trackmania-dos(15081)</ref></refs><vuln_soft><prod name="Virtual Skipper" vendor="Nadeo"><vers num="3"/></prod><prod name="Game Engine" vendor="Nadeo"><vers num=""/></prod><prod name="TrackMania" vendor="Nadeo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2078" published="2004-02-09" seq="2004-2078" severity="Medium" type="CVE"><desc><descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9618">9618</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009001">1009001</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10832">10832</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/3891">3891</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15086">redalert-long-request-dos(15086)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Red-Alert" vendor="Red-M"><vers num="2.7.5 v3.1 build 24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2079" published="2004-02-09" seq="2004-2079" severity="High" type="CVE"><desc><descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9618">9618</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009001">1009001</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15088">redalert-gain-access(15088)</ref><ref source="OSVDB" url="http://www.osvdb.org/3952">3952</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Red-Alert" vendor="Red-M"><vers num="2.7.5 v3.1 build 24"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2080" published="2004-02-09" seq="2004-2080" severity="Medium" type="CVE"><desc><descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://genhex.org/releases/031003.txt">http://genhex.org/releases/031003.txt</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9618">9618</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009001">1009001</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15089">redalert-bypass-security(15089)</ref><ref source="OSVDB" url="http://www.osvdb.org/3953">3953</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Red-Alert" vendor="Red-M"><vers num="2.7.5 v3.1 build 24"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-2081" published="2004-12-31" seq="2004-2081" severity="Medium" type="CVE"><desc><descript source="cve">The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353753">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.karja.com/samiftp/news.html">http://www.karja.com/samiftp/news.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9657">9657</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15204">sami-cd-get-dos(15204)</ref></refs><vuln_soft><prod name="Sami FTP Server" vendor="KarjaSoft"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-2082" published="2004-02-13" seq="2004-2082" severity="Medium" type="CVE"><desc><descript source="cve">The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading &quot;/&quot; (slash) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353753">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.karja.com/samiftp/news.html">http://www.karja.com/samiftp/news.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9657">9657</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15204">sami-cd-get-dos(15204)</ref></refs><vuln_soft><prod name="Sami FTP Server" vendor="KarjaSoft"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2083" published="2004-02-11" seq="2004-2083" severity="Low" type="CVE"><desc><descript source="cve">Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka &quot;File Download Extension Spoofing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="MISC" url="http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/">http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10760">10760</ref><ref source="BID" url="http://www.securityfocus.com/bid/9640">9640</ref><ref source="" url="http://www.opera.com/docs/changelogs/windows/750b1/"></ref><ref source="OSVDB" url="http://www.osvdb.org/3917">3917</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21698">opera-cslid-extension-spoof(21698)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers num="7.10"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.21"/><vers num="7.22"/><vers num="7.23"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2084" published="2004-02-07" seq="2004-2084" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.systemsecure.org/advisories/ssadvisory09022004.php">http://www.systemsecure.org/advisories/ssadvisory09022004.php</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9609">9609</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/3889">3889</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1008988">1008988</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10825">10825</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15100">jshop-searchphp-xss(15100)</ref></refs><vuln_soft><prod name="JShop Professional" vendor="JShop E-Commerce"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/></prod><prod name="JShop Server" vendor="JShop E-Commerce"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.1.0"/><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2085" published="2004-02-04" seq="2004-2085" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=214860">http://sourceforge.net/project/shownotes.php?release_id=214860</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5</ref><ref adv="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9601">9601</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9645">9645</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/3885">3885</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/3886">3886</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/3887">3887</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15190">phpcodecabinet-multiple-xss(15190)</ref><ref source="OSVDB" url="http://www.osvdb.org/16710">16710</ref><ref source="OSVDB" url="http://www.osvdb.org/16711">16711</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009012">1009012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10862">10862</ref></refs><vuln_soft><prod name="phpCodeCabinet" vendor="Brad Fears"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2086" published="2004-02-06" seq="2004-2086" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="VULN-DEV" url="http://www.securityfocus.com/archive/82/353087">20040207 Sambar 6.0 stack overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.sambar.com/security.htm">http://www.sambar.com/security.htm</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9607">9607</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/5786">5786</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1008979">1008979</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15071">sambar-http-post-bo(15071)</ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="6.0"/><vers num="6.0 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2087" published="2004-02-08" seq="2004-2087" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=351705">http://sourceforge.net/forum/forum.php?forum_id=351705</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9647">9647</ref><ref source="OSVDB" url="http://www.osvdb.org/3922">3922</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1009110">1009110</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10829">10829</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15193">sandsurfer-gain-access(15193)</ref></refs><vuln_soft><prod name="SandSurfer" vendor="SandSurfer"><vers num="1.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-2088" published="2004-02-12" seq="2004-2088" severity="Medium" type="CVE"><desc><descript source="cve">Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.sophos.com/support/news/#mime-378">http://www.sophos.com/support/news/#mime-378</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9650">9650</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15192">sophos-email-virus-undetected(15192)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009042">1009042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10855">10855</ref></refs><vuln_soft><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.78"/><vers num="3.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2089" published="2004-02-06" seq="2004-2089" severity="Medium" type="CVE"><desc><descript source="cve">Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1008970">1008970</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15075">matrixftp-login-list-dos(15075)</ref></refs><vuln_soft><prod name="Matrix FTP Server" vendor="Matrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2090" published="2004-02-07" seq="2004-2090" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html">20040207 (no subject)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9611">9611</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10820">10820</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15078">ie-error-obtain-information(15078)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2091" published="2004-02-10" seq="2004-2091" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353324">20040210 Another Low Blow From Microsoft: MBSA Failure!</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9634">9634</ref></refs><vuln_soft><prod name="baseline security analyzer" vendor="Microsoft"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2092" published="2004-02-09" seq="2004-2092" severity="Medium" type="CVE"><desc><descript source="cve">eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application&apos;s registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref><ref source="BID" url="http://www.securityfocus.com/bid/9616">9616</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/3896">3896</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10833">10833</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15103">etrust-inoculateit-insecure-permissions(15103)</ref></refs><vuln_soft><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2093" published="2004-02-09" seq="2004-2093" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable.  NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user.  Therefore this issue may be REJECTED in the future.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2004-q1/0091.html">20040209 rsync &lt;= 2.5.7 local buffer overflow (no root today:)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15108">linux-rsync-opensocketout-bo(15108)</ref></refs><vuln_soft><prod name="rsync" vendor="Linux"><vers num="2.5.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2094" published="2004-12-31" seq="2004-2094" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107471195326270&amp;w=2">20040121 WebcamXP v1.06.945 Cross Site Scripting Vulnerabillity</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14904">webcamxp-xss(14904)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9465">9465</ref></refs><vuln_soft><prod name="WebCam XP" vendor="Darkwet"><vers num="1.6.945"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-2095" published="2004-12-31" seq="2004-2095" severity="Medium" type="CVE"><desc><descript source="cve">Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107471181426047&amp;w=2">20040121 Honeyd Security Advisory 2004-001: Remote Detection Via Simple Probe Packet</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107473095118505&amp;w=2">20040121 [ GLSA 200401-02 ] Honeyd remote detection vulnerability via a probe</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14905">honeyd-nmap-information-disclosure(14905)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9464">9464</ref><ref source="OSVDB" url="http://www.osvdb.org/3690">3690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008818">1008818</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10695">10695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10694">10694</ref></refs><vuln_soft><prod name="Honeyd" vendor="Niels Provos"><vers num="0.5"/><vers num="0.6a"/><vers num="0.6"/><vers num="0.7a"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-2096" published="2004-12-31" seq="2004-2096" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107470433714179&amp;w=2">20040121 Mephistoles Httpd 0.6.0final XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14899">mephistoles-httpd-xss(14899)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9470">9470</ref><ref source="OSVDB" url="http://www.osvdb.org/3689">3689</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10693">10693</ref></refs><vuln_soft><prod name="Mephistoles HTTPD" vendor="Mephistoles Internet Suite"><vers num="0.6 p2"/><vers num="0.6 p1"/><vers num="0.6 final"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2097" published="2004-12-31" seq="2004-2097" severity="Low" type="CVE"><desc><descript source="cve">Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by winpopup-send.sh, or (6) /tmp/initrd created by lvmcreate_initrd.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107461582413923&amp;w=2">20040121 [SuSE 9.0] possible symlink attacks in some scripts</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107478920006258&amp;w=2">20040122 Re: [SuSE 9.0] possible symlink attacks in some scripts</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14963">suse-multiple-symlink-attack(14963)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9457">9457</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008781">1008781</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2098" published="2004-12-31" seq="2004-2098" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107479071808330&amp;w=2">20040122 TBE - the banner engine server-side script execution vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14911">tbe-xss(14911)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9472">9472</ref></refs><vuln_soft><prod name="TBE Banner Engine" vendor="Native Solutions"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2099" published="2004-12-31" seq="2004-2099" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/nfshp2cbof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/9473">9473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14909">hotpursuit2-bo(14909)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107479094508691&amp;w=2">20040122 Need for Speed Hot pursuit 2 &lt;= 242 client&apos;s buffer overflow</ref></refs><vuln_soft><prod name="Need for Speed Hot Pursuit 2" vendor="Electronic Arts"><vers num="242.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2100" published="2004-12-31" seq="2004-2100" severity="Medium" type="CVE"><desc><descript source="cve">GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480261825214&amp;w=2">20040122 GeoHttpServer Authentification Bypass Vulnerability &amp; D.O.S (Denial Of Service)</ref></refs><vuln_soft><prod name="GeoHttpServer" vendor="GeoVision"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2101" published="2004-12-31" seq="2004-2101" severity="Medium" type="CVE"><desc><descript source="cve">The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480261825214&amp;w=2">20040122 GeoHttpServer Authentification Bypass Vulnerability D.O.S (Denial Of Service)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008807">1008807</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14913">geohttpserver-long-password-bo(14913)</ref></refs><vuln_soft><prod name="GeoHttpServer" vendor="GeoVision"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2102" published="2004-12-31" seq="2004-2102" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480309925905&amp;w=2">20040122 FREESCO public http server - Cross Site Scripting Vulnerabillity</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14916">freesco-thttpd-xss(14916)</ref></refs><vuln_soft><prod name="FREESCO" vendor="FREESCO"><vers num="2.05"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2103" published="2004-12-31" seq="2004-2103" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (5) a URL request for a .bas file with script in the filename.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref><ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htm</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14919">netware-enterprise-cgi2perl-xss(14919)</ref><ref source="OSVDB" url="http://www.osvdb.org/4949">4949</ref></refs><vuln_soft><prod name="NetWare Enterprise Web Server" vendor="Novell"><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2104" published="2004-12-31" seq="2004-2104" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10711">10711</ref><ref source="BID" url="http://www.securityfocus.com/bid/9479">9479</ref><ref source="OSVDB" url="http://www.osvdb.org/3715">3715</ref><ref source="OSVDB" url="http://www.osvdb.org/3720">3720</ref><ref source="OSVDB" url="http://www.osvdb.org/3721">3721</ref><ref source="OSVDB" url="http://www.osvdb.org/3722">3722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14921">netware-enterprise-path-disclosure(14921)</ref></refs><vuln_soft><prod name="NetWare Enterprise Web Server" vendor="Novell"><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2105" published="2004-12-31" seq="2004-2105" severity="Medium" type="CVE"><desc><descript source="cve">The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="NetWare Enterprise Web Server" vendor="Novell"><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2106" published="2004-12-31" seq="2004-2106" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/13402">13402</ref><ref source="OSVDB" url="http://www.osvdb.org/13403">13403</ref><ref source="OSVDB" url="http://www.osvdb.org/13404">13404</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21749">netware-enterprise-directory-disclosure(21749)</ref></refs><vuln_soft><prod name="NetWare Enterprise Web Server" vendor="Novell"><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2107" published="2004-12-31" seq="2004-2107" severity="High" type="CVE"><desc><descript source="cve">Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487999406339&amp;w=2">20040123 Finjan SurfinGate Vulnerability</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522480913629&amp;w=2">20040126 RE: Finjan SurfinGate Vulnerability</ref><ref patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0929.html">20040123 Finjan SurfinGate Vulnerability</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10714">10714</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9478">9478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14934">finjan-surfingate-execute-commands(14934)</ref></refs><vuln_soft><prod name="SurfinGate" vendor="Finjan Software"><vers num="6.0 5"/><vers num="6.0 1"/><vers num="6.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2108" published="2004-12-31" seq="2004-2108" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107488132208229&amp;w=2">20040123 QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040123.txt">http://www.s-quadra.com/advisories/Adv-20040123.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9481">9481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14922">qshop-multiple-sql-injection(14922)</ref><ref source="OSVDB" url="http://www.osvdb.org/3698">3698</ref><ref source="OSVDB" url="http://www.osvdb.org/3699">3699</ref><ref source="OSVDB" url="http://www.osvdb.org/3700">3700</ref><ref source="OSVDB" url="http://www.osvdb.org/3701">3701</ref><ref source="OSVDB" url="http://www.osvdb.org/3702">3702</ref><ref source="OSVDB" url="http://www.osvdb.org/3703">3703</ref><ref source="OSVDB" url="http://www.osvdb.org/3704">3704</ref><ref source="OSVDB" url="http://www.osvdb.org/3705">3705</ref><ref source="OSVDB" url="http://www.osvdb.org/3706">3706</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Jan/1008837.html">1008837</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10704">10704</ref></refs><vuln_soft><prod name="Q-Shop" vendor="QuadComm"><vers num="2.0"/><vers num="2.1"/><vers num="2.5 beta"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2109" published="2004-12-31" seq="2004-2109" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107488132208229&amp;w=2">20040123 QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9480">9480</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14923">qshop-url-xss(14923)</ref><ref source="OSVDB" url="http://www.osvdb.org/3696">3696</ref><ref source="OSVDB" url="http://www.osvdb.org/3697">3697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10704">10704</ref></refs><vuln_soft><prod name="Q-Shop" vendor="QuadComm"><vers num="2.0"/><vers num="2.1"/><vers num="2.5 beta"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2110" published="2004-12-31" seq="2004-2110" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487971405960&amp;w=2">20040123 Multiple Vulnerabilities in Phorum 3.4.5</ref><ref source="CONFIRM" url="http://phorum.org/">http://phorum.org/</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2004-2111" published="2004-12-31" seq="2004-2111" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0249.html">20040124 [SST]ServU MDTM command remote buffero verflow adv</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513654005840&amp;w=2">20040126 Serv-U ftp 4.2 site chmod long_file_name exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/9483">9483</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008841">1008841</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14931">servu-chmodcommand-execute-code(14931)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9675">9675</ref></refs><vuln_soft><prod name="Serv-U" vendor="RhinoSoft"><vers num="3.0"/><vers num="3.1"/><vers num="4.0.0.4"/><vers num="4.1.0.11"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2112" published="2004-12-31" seq="2004-2112" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via &quot;..&quot; (dot dot) sequences in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513747107031&amp;w=2">20040126 Directory traversal and XSS in BremsServer 1.2.4</ref><ref source="BID" url="http://www.securityfocus.com/bid/9493">9493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14954">bremsserver-dotdot-directory-traversal(14954)</ref><ref source="OSVDB" url="http://www.osvdb.org/3755">3755</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008853">1008853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10731">10731</ref></refs><vuln_soft><prod name="BremsServer" vendor="Herberlin"><vers num="1.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2113" published="2004-12-31" seq="2004-2113" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513747107031&amp;w=2">20040126 Directory traversal and XSS in BremsServer 1.2.4</ref><ref source="BID" url="http://www.securityfocus.com/bid/9491">9491</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14953">bremsserver-xss(14953)</ref><ref source="OSVDB" url="http://www.osvdb.org/3754">3754</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10731">10731</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008853">1008853</ref></refs><vuln_soft><prod name="BremsServer" vendor="Herberlin"><vers num="1.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2114" published="2004-12-31" seq="2004-2114" severity="High" type="CVE"><desc><descript source="cve">Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107515550931508&amp;w=2">20040126 ProxyNow! 2.x Multiple Overflow Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/9500">9500</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14955">proxynow-get-bo(14955)</ref></refs><vuln_soft><prod name="ProxyNow" vendor="InternetNow"><vers num="2.6"/><vers num="2.75"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2004-2115" published="2004-12-31" seq="2004-2115" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496560106967&amp;w=2">20040124 Oracle HTTP Server Cross Site Scripting Vulnerabillity</ref><ref source="BID" url="http://www.securityfocus.com/bid/9484">9484</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14930">oraclehttpserver-isqlplus-xss(14930)</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="8.1.7"/><vers num="9.0.1"/><vers num="9.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2116" published="2004-12-31" seq="2004-2116" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9485">9485</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14927">tinyserver-dotdot-directory-traversal(14927)</ref><ref source="OSVDB" url="http://www.osvdb.org/3708">3708</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10707">10707</ref></refs><vuln_soft><prod name="TinyServer" vendor="TinyServer"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2117" published="2004-01-24" seq="2004-2117" severity="Medium" type="CVE"><desc><descript source="cve">Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9485">9485</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14928">tinyserver-string-dos(14928)</ref><ref source="OSVDB" url="http://www.osvdb.org/3709">3709</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10707">10707</ref></refs><vuln_soft><prod name="TinyServer" vendor="TinyServer"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2118" published="2004-12-31" seq="2004-2118" severity="Medium" type="CVE"><desc><descript source="cve">Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via a GET request with a long filename, possibly due to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9485">9485</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14928">tinyserver-string-dos(14928)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10707">10707</ref></refs><vuln_soft><prod name="TinyServer" vendor="TinyServer"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2119" published="2004-12-31" seq="2004-2119" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9485">9485</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14929">tinyserver-xss(14929)</ref><ref source="OSVDB" url="http://www.osvdb.org/3710">3710</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10707">10707</ref></refs><vuln_soft><prod name="TinyServer" vendor="TinyServer"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2120" published="2004-01-23" seq="2004-2120" severity="Medium" type="CVE"><desc><descript source="cve">Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497355713434&amp;w=2">20040124 Resources consumption in Reptile webserver daily version</ref><ref adv="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt">http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9482">9482</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1008842">1008842</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14932">reptilewebserver-get-dos(14932)</ref></refs><vuln_soft><prod name="Reptile Web Server" vendor="Reptile Web Server"><vers num="2002-01-05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2121" published="2004-12-31" seq="2004-2121" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot &quot;......&quot; sequences, or (2) &quot;%5c%2e%2e&quot; (encoded &quot;\..&quot;) sequences, in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497413413907&amp;w=2">20040124 BWS v1.0b3 Directory Transversal Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9486">9486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008840">1008840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14948">bws-directory-traversal(14948)</ref></refs><vuln_soft><prod name="Web Server for Corel Paradox" vendor="Borland Software"><vers num="1.0 b3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2122" published="2004-01-24" seq="2004-2122" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497803617071&amp;w=2">20040124 Inrtra Forum Cross Site Scripting Vulnerabillity</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14933">intraforum-intraforumcgi-xss(14933)</ref></refs><vuln_soft><prod name="Intra Forum" vendor="Intra Forum"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2123" published="2004-12-31" seq="2004-2123" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513601805018&amp;w=2">20040124 NextPlace.com E-Commerce ASP Engine</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14952">nextplace-multiple-xss(14952)</ref></refs><vuln_soft><prod name="E-Commerce ASP Engine" vendor="NextPlace"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-2124" published="2004-12-31" seq="2004-2124" severity="Medium" type="CVE"><desc><descript source="cve">The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107524414317693&amp;w=2">20040127 Remote exploit in Gallery 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=index">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=index</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14950">gallery-gallerybasedir-file-include(14950)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200402-04.xml">GLSA-200402-04</ref><ref source="BID" url="http://www.securityfocus.com/bid/9490">9490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10712/">10712</ref><ref source="OSVDB" url="http://www.osvdb.org/3737">3737</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2125" published="2004-12-31" seq="2004-2125" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530966524193&amp;w=2">20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM</ref><ref source="BID" url="http://www.securityfocus.com/bid/9514">9514</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14965">blackice-blackdexe-bo(14965)</ref><ref source="MLIST" url="http://archives.neohapsis.com/archives/iss/2004-q1/0157.html">[ISSForum] 20040128 Third party BlackICE advisory</ref><ref source="OSVDB" url="http://www.osvdb.org/3740">3740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10739">10739</ref></refs><vuln_soft><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6cbd"/></prod><prod name="RealSecure Desktop" vendor="Internet Security Systems"><vers num="3.6eca"/><vers num="7.0ebg"/></prod><prod name="BlackICE Server Protection" vendor="Internet Security Systems"><vers num="3.6cbz"/></prod><prod name="BlackICE Agent Server" vendor="Internet Security Systems"><vers num="3.6eca"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2126" published="2004-12-31" seq="2004-2126" severity="Medium" type="CVE"><desc><descript source="cve">The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530966524193&amp;w=2">20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM</ref><ref source="BID" url="http://www.securityfocus.com/bid/9513">9513</ref></refs><vuln_soft><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6cbz" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2127" published="2004-01-20" seq="2004-2127" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531194527602&amp;w=2">20040128 ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.zone-h.org/en/advisories/read/id=3822/">http://www.zone-h.org/en/advisories/read/id=3822/</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9517">9517</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14978">webblog-dotdot-directory-traversal(14978)</ref><ref source="OSVDB" url="http://www.osvdb.org/3739">3739</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10740">10740</ref></refs><vuln_soft><prod name="Web Blog" vendor="Leif M. Wright"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2128" published="2004-12-31" seq="2004-2128" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531020924977&amp;w=2">20040128 BRS WebWeaver Webserver Cross Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9516">9516</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10741">10741</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14977">webweaver-isapiskeleton-xss(14977)</ref><ref source="OSVDB" url="http://www.osvdb.org/3741">3741</ref><ref source="" url="http://www.brswebweaver.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=1"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008880">1008880</ref></refs><vuln_soft><prod name="WebWeaver" vendor="BRS"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2129" published="2004-12-31" seq="2004-2129" severity="Medium" type="CVE"><desc><descript source="cve">SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530924723559&amp;w=2">20040128 Denial Of Service in SurfNOW 2.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/9519">9519</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14976">surfnow-get-dos(14976)</ref></refs><vuln_soft><prod name="SurfNOW Standard" vendor="Loom Software"><vers num="1.2"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SurfNOW Professional" vendor="Loom Software"><vers num="1.2"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2130" published="2004-12-23" seq="2004-2130" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530946123822&amp;w=2">20040128 phpBB privmsg.php XSS vulnerability patch.</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9290">9290</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2131" published="2004-01-27" seq="2004-2131" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539878804074&amp;w=2">20040129 ----------========== OPEN3S-2003-08-08-eng-informix-ontape</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21153336">http://www-1.ibm.com/support/docview.wss?uid=swg21153336</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9512">9512</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14970">informix-ontape-binary-bo(14970)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10737/">10737</ref><ref source="OSVDB" url="http://www.osvdb.org/3759">3759</ref></refs><vuln_soft><prod name="Informix Extended Parallel Server" vendor="IBM"><vers num="8.40 UC1"/></prod><prod name="Informix IDS" vendor="IBM"><vers num="9.40.UC2"/><vers num="9.40.UC1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2132" published="2004-01-29" seq="2004-2132" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a ..  (dot dot) in the p parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539804702913&amp;w=2">20040129 ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving</ref><ref adv="1" source="MISC" url="http://www.zone-h.org/advisories/read/id=3824">http://www.zone-h.org/advisories/read/id=3824</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9524">9524</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14980">pjcgineoreview-dotdot-directory-traversal(14980)</ref><ref source="SECUNIA" url="http://www.secunia.com/advisories/10734/">10734</ref><ref source="OSVDB" url="http://www.osvdb.org/3746">3746</ref></refs><vuln_soft><prod name="PJ CGI Neo Review" vendor="PJ CGI Neo Review"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2133" published="2004-01-29" seq="2004-2133" severity="Medium" type="CVE"><desc><descript source="cve">Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539776002450&amp;w=2">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9523">9523</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14994">cvsup-rpath-gain-privileges(14994)</ref></refs><vuln_soft><prod name="CVSup" vendor="CVSup"><vers num="cvsup-16.1h-2.i386.rpm"/><vers num="cvsup-16.1h-36.i586.rpm"/><vers num="cvsup-16.1h-43.i586.rpm"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2134" published="2004-01-28" seq="2004-2134" severity="Medium" type="CVE"><desc><descript source="cve">Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531028325112&amp;w=2">20040128 Oracle toplink mapping workbench password algorithm</ref><ref adv="1" source="VULN-DEV" url="http://www.securityfocus.com/archive/82/351719">20040128 Re: Oracle toplink mapping workbench password algorithm</ref><ref source="MISC" url="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5">http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/9515">9515</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/352315/30/21430/threaded">20040128 Re: Oracle toplink mapping workbench password algorithm</ref></refs><vuln_soft><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.2 .3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num="9.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2135" published="2004-05-26" seq="2004-2135" severity="Low" type="CVE"><desc><descript source="cve">cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain &quot;IV computation&quot; weaknesses that allow watermarked files to be detected without decryption.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</ref><ref source="MISC" url="http://mareichelt.de/pub/notmine/diskenc.pdf">http://mareichelt.de/pub/notmine/diskenc.pdf</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/exploits/5UP0P1PFPM.html">http://www.securiteam.com/exploits/5UP0P1PFPM.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13775">13775</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12 -rc4"/><vers num="2.6.11 .8"/><vers num="2.6.11 .7"/><vers num="2.6.11 .6"/><vers num="2.6.11 .5"/><vers num="2.6.11 -rc4"/><vers num="2.6.11 -rc3"/><vers num="2.6.11 -rc2"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6 .10"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5 .0"/><vers num="2.4.31 -pre1"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.29 -rc2"/><vers num="2.4.29 -rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2136" published="2004-02-19" seq="2004-2136" severity="Low" type="CVE"><desc><descript source="cve">dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain &quot;IV computation&quot; weaknesses that allow watermarked files to be detected without decryption.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</ref><ref source="MISC" url="http://mareichelt.de/pub/notmine/diskenc.pdf">http://mareichelt.de/pub/notmine/diskenc.pdf</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/exploits/5UP0P1PFPM.html">http://www.securiteam.com/exploits/5UP0P1PFPM.html</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2137" published="2004-12-31" seq="2004-2137" severity="Medium" type="CVE"><desc><descript source="cve">Outlook Express 6.0, when sending multipart e-mail messages using the &quot;Break apart messages larger than&quot; setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.networksecurity.fi/advisories/outlook-bcc.html">http://www.networksecurity.fi/advisories/outlook-bcc.html</ref><ref adv="1" patch="1" source="MSKB" url="http://support.microsoft.com/kb/843555">843555</ref><ref source="BID" url="http://www.securityfocus.com/bid/11040">11040</ref><ref source="OSVDB" url="http://www.osvdb.org/9167">9167</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011067">1011067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12376">12376</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17098">outlook-email-address-disclosure(17098)</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/><vers num="6.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2138" published="2004-12-31" seq="2004-2138" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.computerknights.org/forum_viewtopic.php?2.122">http://www.computerknights.org/forum_viewtopic.php?2.122</ref><ref source="BID" url="http://www.securityfocus.com/bid/11234">11234</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011376">1011376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17462">mysqlguest-awsguestphp-xss(17462)</ref></refs><vuln_soft><prod name="MySQLGuest" vendor="AllWebScripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2139" published="2004-12-31" seq="2004-2139" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12609/">12609</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17459">yabb-admineditpl-xss(17459)</ref><ref source="BID" url="http://www.securityfocus.com/bid/11235">11235</ref><ref source="OSVDB" url="http://www.osvdb.org/10222">10222</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="1 Gold - SP 1.3.1"/><vers num="1 Gold - SP 1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2140" published="2004-12-31" seq="2004-2140" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12609/">12609</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17459">yabb-admineditpl-xss(17459)</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="1 Gold - SP 1.3.1"/><vers num="1 Gold - SP 1.3"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2004-2141" published="2004-12-31" reject="1" seq="2004-2141" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1827.  Reason: This candidate is a duplicate of CVE-2004-1827.  Notes: All CVE users should reference CVE-2004-1827 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2142" published="2004-12-31" seq="2004-2142" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="ftp://ftp.berlios.de/pub/sdd/AN-1.52">ftp://ftp.berlios.de/pub/sdd/AN-1.52</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12584/">12584</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17442">sdd-rmt(17442)</ref></refs><vuln_soft><prod name="sdd" vendor="Jorg Schilling"><vers num="1.28"/><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2143" published="2004-12-31" seq="2004-2143" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mamboportal.com/content/view/1615/">http://www.mamboportal.com/content/view/1615/</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011356">1011356</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12597/">12597</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0215.html">20040917 Mambo Portal lasted version 4.5.1 (1.09) and lower vesion : SQL injection Vulnerability.</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0249.html">20040919 Re: Mambo Portal lasted version 4.5.1 (1.09) and lower vesion : SQL injection Vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/11219">11219</ref><ref source="OSVDB" url="http://www.osvdb.org/10040">10040</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17441">remository-filecatid-sql-injection(17441)</ref></refs><vuln_soft><prod name="Mambo Portal" vendor="Mambo"><vers num="4.5.1_1.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2144" published="2004-12-31" seq="2004-2144" severity="High" type="CVE"><desc><descript source="cve">Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011416">1011416</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12649/">12649</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17499">baal-admin-password-modify(17499)</ref></refs><vuln_soft><prod name="Baal Smart Forms" vendor="Baal Systems"><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2145" published="2004-12-31" seq="2004-2145" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0962.html">20040926 HTTP Response Splitting and SQL injection in megabbs forum</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109631200701134&amp;w=2">20040926 Re: HTTP Response Splitting and SQL injection in megabbs forum</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17497">megabbs-sql-injection(17497)</ref></refs><vuln_soft><prod name="MegaBBS" vendor="PD9 Software"><vers num="2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2146" published="2004-12-31" seq="2004-2146" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0962.html">20040926 HTTP Response Splitting and SQL injection in megabbs forum</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109631200701134&amp;w=2">20040926 Re: HTTP Response Splitting and SQL injection in megabbs forum</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17495">megabbs-response-splitting(17495)</ref><ref source="" url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924"></ref></refs><vuln_soft><prod name="MegaBBS" vendor="PD9 Software"><vers num="2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2004-2147" published="2004-12-31" seq="2004-2147" severity="Medium" type="CVE"><desc><descript source="cve">Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return (&quot;\n&quot;) separating the headers from the body.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="VULN-DEV" url="http://www.securityfocus.com/archive/82/376487/2004-09-24/2004-09-30/0">20040925 No body emails and Norton antivirus</ref><ref source="BID" url="http://www.securityfocus.com/bid/11259">11259</ref></refs><vuln_soft><prod name="Norton AntiVirus" vendor="Symantec"><vers edition="MS Exchange" num="2.1"/><vers num="2003"/><vers num="2002"/><vers num="2001"/><vers num="Corporate 8.0"/><vers num="Corporate 7.61"/><vers num="Corporate 7.51"/><vers num="Corporate 7.6"/><vers num="Corporate 7.5"/><vers num="Corporate 7.2"/><vers num="Corporate 7.0"/><vers num="Corporate 7.60.build 926"/><vers num="Professional 2004"/><vers num="Professional 2003"/><vers num="Professional 2002"/><vers num="Professional 2001"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2148" published="2004-12-31" seq="2004-2148" severity="High" type="CVE"><desc><descript source="cve">Unknown local vulnerability in the &quot;change user&quot; feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=269807">http://sourceforge.net/project/shownotes.php?release_id=269807</ref><ref source="BID" url="http://www.securityfocus.com/bid/11255">11255</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011417">1011417</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12648/">12648</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17494">fprobe-change-user(17494)</ref></refs><vuln_soft><prod name="fprobe" vendor="Slava Astashonok"><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-2149" published="2004-12-31" seq="2004-2149" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://dev.mysql.com/doc/mysql/en/news-4-1-5.html">http://dev.mysql.com/doc/mysql/en/news-4-1-5.html</ref><ref adv="1" source="" url="http://bugs.mysql.com/bug.php?id=5194">http://bugs.mysql.com/bug.php?id=5194</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11261">11261</ref><ref source="OSVDB" url="http://www.osvdb.org/10244">10244</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011408">1011408</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17493">mysql-libmysqlclient-insert-bo(17493)</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1.4"/><vers num="4.1.3 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2150" published="2004-12-31" seq="2004-2150" severity="Medium" type="CVE"><desc><descript source="cve">Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/11257">11257</ref><ref source="OSVDB" url="http://www.osvdb.org/10349">10349</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011425">1011425</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12661/">12661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17510">intellipeer-username-obtain-information(17510)</ref></refs><vuln_soft><prod name="INTELLIPEER Email Server" vendor="Nettica Corporation"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-30" name="CVE-2004-2151" published="2004-12-31" seq="2004-2151" severity="Medium" type="CVE"><desc><descript source="cve">Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/376569">20040927 Broadcast crash in Chatman 1.5.1 RC1</ref><ref source="BID" url="http://www.securityfocus.com/bid/11263">11263</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011431">1011431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12665/">12665</ref><ref source="OSVDB" url="http://www.osvdb.org/10365">10365</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17513">chatman-dos(17513)</ref></refs><vuln_soft><prod name="Chatman" vendor="Virtual Projects"><vers num="1.5.1"/><vers num="1.5.0 RC1"/><vers num="1.4.0 Beta"/><vers num="1.3.1 Beta"/><vers num="1.3.0 Beta"/><vers num="1.2.1 Beta"/><vers num="1.1.5 Beta"/><vers num="1.1.4 Beta"/><vers num="1.1.3 Beta"/><vers num="1.1.2 Beta"/><vers num="1.1.1 Beta"/><vers num="1.1.0 Beta"/><vers num="1.0.4 Beta"/><vers num="1.0.3 Beta"/><vers num="1.0.2 Beta"/><vers num="1.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2152" published="2004-12-31" seq="2004-2152" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in &apos;raw&apos; page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=34373&amp;release_id=271848">http://sourceforge.net/project/shownotes.php?group_id=34373&amp;release_id=271848</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11302">11302</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/10454">10454</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12692/">12692</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17578">mediawiki-raw-output-xss(17578)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3.4"/><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2153" published="2004-12-31" seq="2004-2153" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html">[fm-news] 20041001 Newsletter for Thursday, September 30th 2004</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11304">11304</ref><ref source="OSVDB" url="http://www.osvdb.org/10480">10480</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12721">12721</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17598">real-estate-management-software(17598)</ref></refs><vuln_soft><prod name="Real Estate Management Software" vendor="Real Estate Management Software"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2154" published="2004-12-31" seq="2004-2154" severity="High" type="CVE"><desc><descript source="cve">CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405</ref><ref patch="1" source="" url="http://www.cups.org/str.php?L700">http://www.cups.org/str.php?L700</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-571.html">RHSA-2005:571</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274">FLSA:163274</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-185-1">USN-185-1</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2155" published="2004-12-31" seq="2004-2155" severity="High" type="CVE"><desc><descript source="cve">Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&amp;release_id=174401">http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&amp;release_id=174401</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11305">11305</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12728/">12728</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17602">online-bookmarks-resrtictions-bypass(17602)</ref></refs><vuln_soft><prod name="Web Based Bookmark Application" vendor="online-bookmarks"><vers num="0.4.4"/><vers num="0.4.2"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2156" published="2004-12-31" seq="2004-2156" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html">http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11306">11306</ref><ref source="OSVDB" url="http://www.osvdb.org/10479">10479</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12720/">12720</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011539">1011539</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17586">online-recruitment-agency(17586)</ref></refs><vuln_soft><prod name="Online Recruitment Agency" vendor="Recruitment Agency Software"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2157" published="2004-12-31" seq="2004-2157" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026955.html">20040928 Serendipity 0.7-beta1 SQL Injection PoC</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11269">11269</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011448">1011448</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12673/">12673</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17536">serendipity-commentphp-xss(17536)</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2158" published="2004-12-31" seq="2004-2158" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026955.html">20040928 Serendipity 0.7-beta1 SQL Injection PoC</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11269">11269</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011448">1011448</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12673/">12673</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17533">serendipity-sql-injection(17533)</ref><ref source="OSVDB" url="http://www.osvdb.org/10370">10370</ref><ref source="OSVDB" url="http://www.osvdb.org/10371">10371</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2159" published="2004-12-31" seq="2004-2159" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=268962">http://sourceforge.net/project/shownotes.php?release_id=268962</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11270">11270</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/10074">10074</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1011496">1011496</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17580">xmlstarlet-bo(17580)</ref></refs><vuln_soft><prod name="Command Line XML Toolkit" vendor="XMLStarlet"><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2160" published="2004-12-31" seq="2004-2160" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=268962">http://sourceforge.net/project/shownotes.php?release_id=268962</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xmlstar/xmlstarlet/src/xml_elem.c?r1=1.17&amp;r2=1.18">http://cvs.sourceforge.net/viewcvs.py/xmlstar/xmlstarlet/src/xml_elem.c?r1=1.17&amp;r2=1.18</ref></refs><vuln_soft><prod name="Command Line XML Toolkit" vendor="XMLStarlet"><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2161" published="2004-12-31" seq="2004-2161" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/375757">20040918 Vulnerabilities in TUTOS</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/file/file_overview.php?r1=1.11.2.1&amp;r2=1.11.2.2">http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/file/file_overview.php?r1=1.11.2.1&amp;r2=1.11.2.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/11221">11221</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12606/">12606</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17444">tutos-sql-injection(17444)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-980">DSA-980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18954">18954</ref><ref source="OSVDB" url="http://www.osvdb.org/10164">10164</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011363">1011363</ref></refs><vuln_soft><prod name="Tutos" vendor="Tutos"><vers num="1.1_2004-04-14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2162" published="2004-12-31" seq="2004-2162" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to app_new.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/375757">20040918 Vulnerabilities in TUTOS</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/app_new.php?r1=1.58&amp;r2=1.59">http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/app_new.php?r1=1.58&amp;r2=1.59</ref><ref source="BID" url="http://www.securityfocus.com/bid/11221">11221</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12606/">12606</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17445">tutos-xss(17445)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-980">DSA-980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18954">18954</ref></refs><vuln_soft><prod name="Tutos" vendor="Tutos"><vers num="1.1_2004-04-14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2163" published="2004-12-31" seq="2004-2163" severity="High" type="CVE"><desc><descript source="cve">login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0058.html">20040921 OpenBSD radius authentication vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.reseau.nl/advisories/0400-openbsd-radius.txt">http://www.reseau.nl/advisories/0400-openbsd-radius.txt</ref><ref patch="1" source="" url="http://www.openbsd.org/errata35.html#radius">http://www.openbsd.org/errata35.html#radius</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11227">11227</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12617">12617</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17456">openbsd-radius-auth-bypass(17456)</ref><ref source="OSVDB" url="http://www.osvdb.org/10203">10203</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.5"/><vers num="3.4"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2164" published="2004-12-31" seq="2004-2164" severity="Medium" type="CVE"><desc><descript source="cve">shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.vpasp.com/virtprog/info/faq_securityfixes.htm">http://www.vpasp.com/virtprog/info/faq_securityfixes.htm</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11228">11228</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Sep/1011359.html">1011359</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17436">vpasp-shoprestoreopenasp-dos(17436)</ref><ref source="OSVDB" url="http://www.osvdb.org/10071">10071</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12611">12611</ref></refs><vuln_soft><prod name="VP-ASP" vendor="Virtual Programming"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2165" published="2004-12-31" seq="2004-2165" severity="Medium" type="CVE"><desc><descript source="cve">Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2004/Sep/0660.html">20040914 Crash in Lords of the Realm III 1.01</ref><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/lotr3boom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/11223">11223</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12589/">12589</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17438">lordsoftherealm-username-dos(17438)</ref><ref source="OSVDB" url="http://www.osvdb.org/10078">10078</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011361">1011361</ref></refs><vuln_soft><prod name="Lords of the Realm III" vendor="Impressions Games"><vers num="1.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2166" published="2004-12-31" seq="2004-2166" severity="High" type="CVE"><desc><descript source="cve">The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/376242">20040923 Promiscuous email printing in Canon imageRunner</ref><ref source="BID" url="http://www.securityfocus.com/bid/11247">11247</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12659/">12659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17512">canon-imagerunner-dos(17512)</ref></refs><vuln_soft><prod name="ImageRUNNER" vendor="Canon"><vers num="5000i"/><vers num="C3200"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2167" published="2004-12-31" seq="2004-2167" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/latex2rtf/latex2rtf/definitions.c?rev=1.22&amp;view=log">http://cvs.sourceforge.net/viewcvs.py/latex2rtf/latex2rtf/definitions.c?rev=1.22&amp;view=log</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/11233">11233</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=10216">10216</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Sep/1011367.html">1011367</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17460">latex2rtf-expandmacro-bo(17460)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17487">latex2rtf-multiple-bo(17487)</ref></refs><vuln_soft><prod name="LaTeX2rtf" vendor="LaTeX2rtf"><vers num="1.9.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2168" published="2004-12-31" seq="2004-2168" severity="Medium" type="CVE"><desc><descript source="cve">BaSoMail 1.24 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections to TCP port (1) 25 (SMTP) or (2) 110 (POP3).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://members.lycos.co.uk/r34ct/main/Baso_mail/Baso_1.24.txt">http://members.lycos.co.uk/r34ct/main/Baso_mail/Baso_1.24.txt</ref><ref adv="1" source="SECUNIA" url="http://www.secunia.com/advisories/10761/">10761</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15002">basomail-multiple-connection-dos(15002)</ref><ref source="OSVDB" url="http://www.osvdb.org/3789">3789</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008912">1008912</ref></refs><vuln_soft><prod name="BaSoMail Server" vendor="Baardsen Software"><vers num="1.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2169" published="2004-12-31" seq="2004-2169" severity="Low" type="CVE"><desc><descript source="cve">Application Access Server (A-A-S) 1.0.37 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long file request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://members.lycos.co.uk/r34ct/main/A-A-S/AAS1_0_3.TXT">http://members.lycos.co.uk/r34ct/main/A-A-S/AAS1_0_3.TXT</ref><ref adv="1" source="SECUNIA" url="http://www.secunia.com/advisories/10762/">10762</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15003">aas-longhttp-request-dos(15003)</ref></refs><vuln_soft><prod name="A-A-S Application Access Server" vendor="A-A-S Application Access Server"><vers num="1.0.37"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2170" published="2004-12-31" seq="2004-2170" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://members.lycos.co.uk/r34ct/main/Caravan/Caravan.txt">http://members.lycos.co.uk/r34ct/main/Caravan/Caravan.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/9555">9555</ref><ref adv="1" source="SECUNIA" url="http://www.secunia.com/advisories/10763/">10763</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15004">caravan-dotdot-directory-traveral(15004)</ref><ref source="OSVDB" url="http://www.osvdb.org/3787">3787</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008913">1008913</ref></refs><vuln_soft><prod name="Caravan Business Server" vendor="Niti Telecom"><vers num="2.00-03D"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2171" published="2004-12-31" seq="2004-2171" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/9496">9496</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/3707">3707</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/10701/">10701</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/14936">cherokee-error-xss(14936)</ref></refs><vuln_soft><prod name="Cherokee HTTPD" vendor="Cherokee"><vers num="0.4.7"/><vers num="0.4.6"/><vers num="0.2.7"/><vers num="0.2.6"/><vers num="0.2.5"/><vers num="0.2"/><vers num="0.1.6"/><vers num="0.1.5"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-2172" published="2004-12-31" seq="2004-2172" severity="Medium" type="CVE"><desc><descript source="cve">EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html">20040216 EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/354288">20040216 EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html">20040218 Re: EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040216.txt">http://www.s-quadra.com/advisories/Adv-20040216.txt </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9669">9669</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15231">productcart-keystream-obtain-information(15231)</ref><ref source="" url="http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3979">3979</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Feb/1009085.html">1009085</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10898">10898</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.5"/><vers num="2.0 br000"/><vers num="2.0"/><vers num="1.6003"/><vers num="1.6002"/><vers num="1.5004"/><vers num="1.5003r"/><vers num="1.5003"/><vers num="1.5002"/><vers num="1.6 br003"/><vers num="1.6 br001"/><vers num="1.6 br"/><vers num="1.6 b003"/><vers num="1.6 b002"/><vers num="1.6 b001"/><vers num="1.6 b"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-2173" published="2004-12-31" seq="2004-2173" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html">20040216 EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/354288">20040216 EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html">20040218 Re: EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040216.txt">http://www.s-quadra.com/advisories/Adv-20040216.txt </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9669">9669</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15233">productcart-advsearchhasp-sql-injection(15233)</ref><ref source="" url="http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3981">3981</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Feb/1009085.html">1009085</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10898">10898</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.5"/><vers num="2.0br000"/><vers num="2.0"/><vers num="1.6003"/><vers num="1.6002"/><vers num="1.5004"/><vers num="1.5003r"/><vers num="1.5003"/><vers num="1.5002"/><vers num="1.6br003"/><vers num="1.6br001"/><vers num="1.6br"/><vers num="1.6b003"/><vers num="1.6b002"/><vers num="1.6b001"/><vers num="1.6b"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2004-2174" published="2004-12-31" seq="2004-2174" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0503.html">20040218 Re: EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0871.html">20040216 EarlyImpact ProductCart shopping cart software multiple security vulnerabilities</ref><ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20040216.txt">http://www.s-quadra.com/advisories/Adv-20040216.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9669">9669</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15234">productcart-custva-xss(15234)</ref><ref source="" url="http://www.earlyimpact.com/productcart/support/updates/ReadMe_ProductCart_Security_Patch_013004.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3980">3980</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Feb/1009085.html">1009085</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10898">10898</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.5"/><vers num="2.0br000"/><vers num="2.0"/><vers num="1.6003"/><vers num="1.6002"/><vers num="1.5004"/><vers num="1.5003r"/><vers num="1.5003"/><vers num="1.5002"/><vers num="1.6br003"/><vers num="1.6br001"/><vers num="1.6br"/><vers num="1.6b003"/><vers num="1.6b002"/><vers num="1.6b001"/><vers num="1.6b"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2175" published="2004-12-31" seq="2004-2175" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/352598">20040204 ZH2004-04SA (security advisory): Multiple Sql Injection Vulnerabilities in ReviewPost PHP Pro</ref><ref patch="1" source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3864/">http://www.zone-h.org/en/advisories/read/id=3864/</ref><ref source="BID" url="http://www.securityfocus.com/bid/9574">9574</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10786/">10786</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/15035">reviewpostpro-showproduct-sql-injection(15035)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="All Enthusiast Inc"><vers num="2.5.1"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2176" published="2004-12-31" seq="2004-2176" severity="Medium" type="CVE"><desc><descript source="cve">The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/378508">20041012 Writing Trojans that bypass Windows XP Service Pack 2 Firewall</ref><ref source="BID" url="http://www.securityfocus.com/bid/11410">11410</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP2" num="Media Center"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-2177" published="2004-12-31" seq="2004-2177" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.maxpatrol.com/advdetails.asp?id=11">http://www.maxpatrol.com/advdetails.asp?id=11</ref><ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=273104">http://sourceforge.net/project/shownotes.php?release_id=273104</ref><ref source="BID" url="http://www.securityfocus.com/bid/11428">11428</ref></refs><vuln_soft><prod name="DevoyBB Web Forum" vendor="DevoyBB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-2178" published="2004-12-31" seq="2004-2178" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.maxpatrol.com/advdetails.asp?id=11">http://www.maxpatrol.com/advdetails.asp?id=11</ref><ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=273104">http://sourceforge.net/project/shownotes.php?release_id=273104</ref><ref source="BID" url="http://www.securityfocus.com/bid/11428">11428</ref></refs><vuln_soft><prod name="DevoyBB Web Forum" vendor="DevoyBB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-2179" published="2004-12-31" seq="2004-2179" severity="Medium" type="CVE"><desc><descript source="cve">asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/378431">20041014 New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/378619">20041015 Re: New Remote Microsoft JPEG DoS Vulnerability + Other Potential Security Vulnerabilitys in asycpict.dll 1.0 Advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/11412">11412</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num="98"/><vers num="97"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 95" num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-2180" published="2004-12-31" seq="2004-2180" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show parameter to index.php, (6) q parameter to search.php, (7) Referer header to admin.php, or the (8) user_email parameter to login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.maxpatrol.com/advdetails.asp?id=7">http://www.maxpatrol.com/advdetails.asp?id=7</ref><ref source="BID" url="http://www.securityfocus.com/bid/11429">11429</ref></refs><vuln_soft><prod name="WowBB Web Forum" vendor="WowBB"><vers num="1.6
