<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0001" published="2004-02-17" seq="2004-0001" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868">oval:org.mitre.oval:def:868</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-017.html">Updated kernel packages available for Red Hat Enterprise Linux 3 Update 1</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9429">bid 9429</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14888">Linux kernel ptrace allows elevated privileges</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/337238">Red Hat Enterprise Linux kernel-2.4.21 does not perform adequate checking of eflags when in 32-bit ptrace emulation mode</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200402-06.xml">GLSA-200402-06</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2004-0002" published="2004-03-03" seq="2004-0002" severity="High" type="CVE"><desc><descript source="cve">The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html">cvs commit: src/sys/netinet ip_icmp.c tcp.h tcp_input.c tcp_subr.c tcp_usrreq.c tcp_var.h</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9572">bid 9572</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.0 Releng"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="5.1 Releng"/><vers num="5.1 p5 Release"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0003" published="2004-03-03" seq="2004-0003" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to &quot;R128 DRI limits checking.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Linuxcompatible.org" url="http://www.linuxcompatible.org/print25630.html">Updated Fedora Core 1 testing kernel</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-044.html">Updated kernel packages resolve minor security vulnerabilities</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_05_linux_kernel.html">SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:005)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1017.html">OVAL1017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval834.html">OVAL834</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-126.shtml">O-126</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-145.shtml">O-145</ref><ref source="BID" url="http://www.securityfocus.com/bid/9570">9570</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10782">10782</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10911">10911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10912">10912</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11202">11202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11361">11361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11369">11369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11370">11370</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11376">11376</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12075">12075</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15029">linux-r128-gain-priviliges(15029)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017">oval:org.mitre.oval:def:1017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834">oval:org.mitre.oval:def:834</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.22" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0004" published="2004-02-17" seq="2004-0004" severity="High" type="CVE"><desc><descript source="cve">The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer&apos;s certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate&apos;s chain is trusted by OpenCA&apos;s chain directory, allowing remote attackers to spoof requests from other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Openca.org" url="http://www.openca.org/news/CAN-2004-0004.txt">OpenCA Security Advisory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9435">bid 9435</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2">20040116 [OpenCA Advisory] Vulnerability in signature verification</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/336446">VU#336446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14847">openca-improper-signature-verification(14847)</ref><ref source="OSVDB" url="http://www.osvdb.org/3615">3615</ref></refs><vuln_soft><prod name="OpenCA" vendor="OpenCA"><vers num="0.9.1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0005" published="2004-03-03" seq="2004-0005" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">Advisory 01/2004: 12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-434">DSA-434-1 gaim -- several vulnerabilities</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190366">VU#190366</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/226974">VU#226974</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/404470">VU#404470</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/655974">VU#655974</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="GENTOO" url="http://www.linuxsecurity.com/content/view/105690/104/">GLSA-200401-04</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14942">gaim-mime-decoder-bo(14942)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14944">gaim-mime-decoder-oob(14944)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14935">gaim-yahoodecode-offbyone-bo(14935)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14938">gaim-sscanf-oob(14938)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref source="OSVDB" url="http://www.osvdb.org/3736">3736</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.75"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0006" published="2004-03-03" seq="2004-0006" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">Gentoo Linux Security Advisory</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval818.html">OVAL818</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/297198">VU#297198</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/371382">VU#371382</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/444158">VU#444158</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/503030">VU#503030</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527142">VU#527142</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/871838">VU#871838</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14947">gaim-http-proxy-bo(14947)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14940">gaim-login-name-bo(14940)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14941">gaim-login-value-bo(14941)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14945">gaim-urlparser-bo(14945)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14943">gaim-yahoopacketread-keyname-bo(14943)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14939">gaim-yahoowebpending-cookie-bo(14939)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818">oval:org.mitre.oval:def:818</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="OSVDB" url="http://www.osvdb.org/3731">3731</ref><ref source="OSVDB" url="http://www.osvdb.org/3732">3732</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.75" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0007" published="2004-03-03" seq="2004-0007" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-434">DSA-434-1 gaim -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">RHSA-2004:032</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref><ref source="CERT-VN" url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0007">VU#197142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval819.html">OVAL819</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="SUSE" url="http://www.securityfocus.com/advisories/6281">SuSE-SA:2004:004</ref><ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14946">gaim-extractinfo-bo(14946)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/197142">VU#197142</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819">oval:org.mitre.oval:def:819</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="OSVDB" url="http://www.osvdb.org/3733">3733</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.74" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0008" published="2004-03-03" seq="2004-0008" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval820.html">OVAL820</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14937">gaim-directim-bo(14937)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820">oval:org.mitre.oval:def:820</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="OSVDB" url="http://www.osvdb.org/3734">3734</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/779614">Gaim contains an integer overflow vulnerability when parsing DirectIM packets</ref><ref adv="1" patch="1" source="Security.e-matters.de" url="http://security.e-matters.de/advisories/012004.html">12 x Gaim remote overflows</ref><ref adv="1" patch="1" source="Source Forge" url="http://ultramagnetic.sourceforge.net/advisories/001.html">Ultramagnetic Advisory #001: Multiple Vulnerabilities in Gaim Code</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">Updated Gaim packages fix various vulnerabiliies</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.74" prev="1"/></prod><prod name="Ultramagnetic" vendor="Ultramagnetic"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0009" published="2004-03-03" seq="2004-0009" severity="High" type="CVE"><desc><descript source="cve">Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the &quot;one-line DN&quot; of the target user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apache-ssl.org/advisory-20040206.txt">http://www.apache-ssl.org/advisory-20040206.txt</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2">Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9590">bid 9590</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15065">Apache-SSL has a default password</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref><ref source="OSVDB" url="http://www.osvdb.org/3877">3877</ref></refs><vuln_soft><prod name="Apache-SSL" vendor="Apache-SSL"><vers num="1.3.28_1.52" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0010" published="2004-03-03" seq="2004-0010" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">Updated kernel packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9691">bid 9691</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15250">Linux Kernel ncp_lookup allows elevated privileges</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-479">DSA-479-1 linux-kernel-2.4.18-alpha+i386+powerpc -- several vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html">RHSA-2004:188</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1035.html">OVAL1035</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval835.html">OVAL835</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="TURBO" url="http://www.securityfocus.com/advisories/6759">TLSA-2004-05</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035">oval:org.mitre.oval:def:1035</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835">oval:org.mitre.oval:def:835</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23"/><vers num="2.4.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0011" published="2004-01-20" seq="2004-0011" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-416">fsp -- buffer overflow, directory traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9377">Debian FSP Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14155">FSP boundary error buffer overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-048.shtml">O-048</ref></refs><vuln_soft><prod name="FSP" vendor="Debian"><vers num="2.81.b18" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0013" published="2004-02-03" seq="2004-0013" severity="Medium" type="CVE"><desc><descript source="cve">jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-414">jabber -- denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9376">bid 9376</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005">Updated jabber packages fix DoS vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14158">Jabber SSL connections denial of service</ref><ref source="OSVDB" url="http://www.osvdb.org/3345">3345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10559">10559</ref></refs><vuln_soft><prod name="Jabber Server" vendor="Jabber Software Foundation"><vers num="1.4.3"/><vers num="1.4.2a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0014" published="2004-01-20" seq="2004-0014" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340454803706&amp;w=2">New nd packages fix buffer overflows</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9365">bid 9365</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-412">nd -- buffer overflows</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14141">nd long string buffer overflow</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008616">1008616</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10549">10549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10550">10550</ref></refs><vuln_soft><prod name="nd" vendor="nd"><vers num="0.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0015" published="2004-02-03" seq="2004-0015" severity="High" type="CVE"><desc><descript source="cve">vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-418">vbox3 -- privilege leak</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9381">bid 9381</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14170">vbox3-gain-privileges(14170)</ref></refs><vuln_soft><prod name="vbox3" vendor="vbox3"><vers num="0.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0016" published="2004-02-03" seq="2004-0016" severity="High" type="CVE"><desc><descript source="cve">The calendar module for phpgroupware 0.9.14 does not enforce the &quot;save extension&quot; feature for holiday files, which allows remote attackers to create and execute PHP files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-419">phpgroupware -- missing filename sanitising, SQL injection</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9387">bid 9387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/13489">phpgroupware-calendar-file-include(13489)</ref><ref source="OSVDB" url="http://www.osvdb.org/6860">6860</ref></refs><vuln_soft><prod name="PhPGroupware" vendor="PhPGroupware"><vers num="0.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0017" published="2004-02-03" seq="2004-0017" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-419">phpgroupware -- missing filename sanitising, SQL injection</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9386">bid 9386</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008662">1008662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10591">10591</ref></refs><vuln_soft><prod name="PhPGroupware" vendor="PHPGroupWare"><vers num="0.9.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0028" published="2004-02-03" seq="2004-0028" severity="High" type="CVE"><desc><descript source="cve">jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-420">jitterbug -- improperly sanitised input</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9397">bid 9397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14207">jitterbug-execute-code(14207)</ref></refs><vuln_soft><prod name="Jitterbug" vendor="Samba"><vers num="1.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0029" published="2004-01-20" seq="2004-0029" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9366">bid 9366</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14153">Lotus Notes and Domino notes.ini file has insecure permissions</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</ref><ref source="" url="http://www.excluded.org/advisories/advisory05.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/3424">3424</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008623">1008623</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10566">10566</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0030" published="2004-01-20" seq="2004-0030" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14159">PhpGedView $PGV_BASE_DIRECTORY PHP file include</ref><ref source="BID" url="http://www.securityfocus.com/bid/9368">9368</ref><ref source="OSVDB" url="http://www.osvdb.org/3343">3343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008632">1008632</ref></refs><vuln_soft><prod name="phpGedView" vendor="phpGedView"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0031" published="2004-01-20" seq="2004-0031" severity="High" type="CVE"><desc><descript source="cve">PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14161">PhpGedView allows administrative password modification</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref><ref source="OSVDB" url="http://www.osvdb.org/3403">3403</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0032" published="2004-01-20" seq="2004-0032" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14160">PhpGedView search.php cross-site scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/9369">9369</ref><ref source="OSVDB" url="http://www.osvdb.org/3402">3402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-02" name="CVE-2004-0033" published="2004-01-20" seq="2004-0033" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14162">PhpGedView admin.php information disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/9371">9371</ref><ref source="OSVDB" url="http://www.osvdb.org/3404">3404</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref></refs><vuln_soft><prod name="PhPGedview" vendor="PhPGedview"><vers num="2.61"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0034" published="2004-01-20" seq="2004-0034" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">Multiple Vulnerabilities in Phorum 3.4.5</ref><ref adv="1" source="Phorum.org" url="http://phorum.org/"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9361">bid 9361</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14145">Phorum common.php, profile.php, and login.php script cross-site scripting</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref><ref source="OSVDB" url="http://www.osvdb.org/3434">3434</ref><ref source="OSVDB" url="http://www.osvdb.org/3506">3506</ref><ref source="OSVDB" url="http://www.osvdb.org/3510">3510</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008633">1008633</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0035" published="2004-01-20" seq="2004-0035" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2">Multiple Vulnerabilities in Phorum 3.4.5</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9363">bid 9363</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14146">Phorum register.php script SQL injection</ref><ref source="OSVDB" url="http://www.osvdb.org/3508">3508</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-06-08" name="CVE-2004-0036" published="2004-01-20" seq="2004-0036" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.vbulletin.com/forum/showthread.php?postid=588825">http://www.vbulletin.com/forum/showthread.php?postid=588825</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2">vBulletin Forum 2.3.xx calendar.php SQL Injection</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14144">vBulletin Forum 2.3.xx calendar.php script SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/9360">9360</ref><ref source="OSVDB" url="http://www.osvdb.org/3344">3344</ref></refs><vuln_soft><prod name="VBulletin" vendor="Jelsoft"><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2004-0037" published="2004-01-20" seq="2004-0037" severity="High" type="CVE"><desc><descript source="cve">FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2">FirstClass Client 7.1: Command Execution via Email Web Link</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9370">Open Text Corporation FirstClass Local File Reference Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14151">FirstClass Client executes code without displaying a warning dialog</ref><ref source="OSVDB" url="http://www.osvdb.org/3442">3442</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10556">10556</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008609">1008609</ref></refs><vuln_soft><prod name="OpenText FirstClass Desktop Client" vendor="OpenText"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0038" published="2004-06-14" seq="2004-0038" severity="High" type="CVE"><desc><descript source="cve">McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/173">20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability</ref><ref adv="1" source="NAI" url="http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt"></ref><ref adv="1" patch="1" source="osvdb" url="http://www.osvdb.org/5626"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14166">epolicy-execute-commands(14166)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10200">bugtraq id 10200</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num="2.5 SP1"/><vers num="2.5"/><vers num="2.5.1"/><vers num="3.0 SP2a"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-03" name="CVE-2004-0039" published="2004-03-03" seq="2004-0039" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/790771">HTTP Parsing Vulnerabilities in Check Point Firewall-1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14149">Check Point FireWall-1 format string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9581">bid 9581</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">Two checkpoint fw-1/vpn-1 vulns</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/162">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/security_server.html">http://www.checkpoint.com/techsupport/alerts/security_server.html</ref><ref source="MISC" url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">http://www.us-cert.gov/cas/techalerts/TA04-036A.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-072.shtml">O-072</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-03" name="CVE-2004-0040" published="2004-03-03" seq="2004-0040" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/873334">Check Point ISAKMP vulnerable to buffer overflow via Certificate Request</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14150">Check Point VPN-1 IKE buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9582">bid 9582</ref><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2"> Two checkpoint fw-1/vpn-1 vulns</ref><ref source="MISC" url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">http://www.us-cert.gov/cas/techalerts/TA04-036A.html</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/163">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-073.shtml">O-073</ref><ref source="OSVDB" url="http://www.osvdb.org/3821">3821</ref><ref source="OSVDB" url="http://www.osvdb.org/4432">4432</ref></refs><vuln_soft><prod name="VPN-1" vendor="Checkpoint"><vers num="4.1 SP5a"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/></prod><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1 SP5a"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0041" published="2004-02-03" seq="2004-0041" severity="High" type="CVE"><desc><descript source="cve">The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-421">mod-auth-shadow -- password expiration</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9404">bid 9404</ref><ref source="OSVDB" url="http://www.osvdb.org/3454">3454</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008675">1008675</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/10612">10612</ref></refs><vuln_soft><prod name="mod_auth_shadow" vendor="mod_auth_shadow"><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0042" published="2004-02-03" seq="2004-0042" severity="Medium" type="CVE"><desc><descript source="cve">vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="Securitytracker.com" url="http://www.securitytracker.com/alerts/2004/Jan/1008628.html">vsftpd Discloses Whether Usernames are Valid or Not</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008628">1008628</ref></refs><vuln_soft><prod name="vsftpd" vendor="Beasts"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0043" published="2004-02-03" seq="2004-0043" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9383">9383</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/3437">3437</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008651">1008651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10573">10573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14171">yahoo-messenger-filename-bo(14171)</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="5.6.0.1351" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0044" published="2004-02-03" seq="2004-0044" severity="High" type="CVE"><desc><descript source="cve">Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when &quot;Allow Only Cisco CallManager Users&quot; is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml">Cisco Personal Assistant User Password Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9384">9384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14172">ciscopersonalassistant-config-file-access(14172)</ref><ref source="OSVDB" url="http://www.osvdb.org/3430">3430</ref></refs><vuln_soft><prod name="Personal Assistant" vendor="Cisco"><vers num="1.4(1)"/><vers num="1.4(2)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0045" published="2004-02-03" seq="2004-0045" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html">Buffer overflow in control message handling</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html">OpenPKG Security Advisory (inn)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9382">bid 9382</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791">SSA:2004-014-02</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759020">VU#759020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10578">10578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14190">inn-artpost-control-message-bo(14190)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0046" published="2004-02-03" seq="2004-0046" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating &apos;&quot;&apos; (double quote) character.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2">SnapStream PVS LITE Cross Site Scripting Vulnerabillity</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9375">bid 9375</ref><ref source="OSVDB" url="http://www.osvdb.org/3440">3440</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008646">1008646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10575">10575</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14164">snapstream-quotation-xss(14164)</ref></refs><vuln_soft><prod name="SnapStream PVS" vendor="SnapStream"><vers num="Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0047" published="2004-03-03" seq="2004-0047" severity="Medium" type="CVE"><desc><descript source="cve">Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-430">trr19 -- missing privilege release</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9520">bid 9520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14975">trr19-gain-privileges(14975)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10744/">10744</ref><ref source="OSVDB" url="http://www.osvdb.org/3747">3747</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008875">1008875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10745">10745</ref></refs><vuln_soft><prod name="TRR19" vendor="Yamamoto Hirotaka"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0049" published="2004-02-17" seq="2004-0049" severity="Medium" type="CVE"><desc><descript source="cve">Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Real.com" url="http://service.real.com/help/faq/security/040112_dos/">Potential Server/Proxy Denial-of-Service Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9421">bid 9421</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/security/security022604.html">http://service.real.com/help/faq/security/security022604.html</ref><ref source="VULNWATCH" url="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357834">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref></refs><vuln_soft><prod name="Helix Universal Server" vendor="RealNetworks"><vers num="9.0.2.881" prev="1"/></prod><prod name="Helix Universal Mobile Server" vendor="RealNetworks"><vers num="10.1.1.120" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0050" published="2004-06-14" seq="2004-0050" severity="Medium" type="CVE"><desc><descript source="cve">Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377388114888&amp;w=2">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" source="Bugtraq" url="http://lists.netsys.com/pipermail/full-disclosure/2004-May/020952.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16066">ultraseek-error-path-disclosure(16066)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref></refs><vuln_soft><prod name="Ultraseek" vendor="Verity"><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0051" published="2004-10-20" seq="2004-0051" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517788100063&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17337">mime-contenttransfer-filter-bypass(17337)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0052" published="2004-10-20" seq="2004-0052" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517669115891&amp;w=2">Multiple vendor MIME separator issue</ref><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17334">mime-separator-filtering-bypass(17334)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0053" published="2004-10-20" seq="2004-0053" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109520704408739&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17331">mime-rfc2047-filtering-bypass(17331)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0054" published="2004-02-17" seq="2004-0054" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml">Vulnerabilities in H.323 Message Processing</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008685">1008685</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.3T"/><vers num="12.0"/><vers num="12.0S"/><vers num="12.0T"/><vers num="12.1"/><vers num="12.1T"/><vers num="12.1E"/><vers num="12.2"/><vers num="12.2S"/><vers num="12.2T"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0055" published="2004-02-17" seq="2004-0055" severity="Medium" type="CVE"><desc><descript source="cve">The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/7090">bid 7090</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/955526">tcpdump contains vulnerability in RADIUS decoding function print_attr_string() in print-radius.c</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">Updated tcpdump packages fix various vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-425">DSA-425</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval850.html">OVAL850</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval853.html">OVAL853</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850">oval:org.mitre.oval:def:850</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853">oval:org.mitre.oval:def:853</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832">CLSA-2003:832</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008735">1008735</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.5.2"/><vers num="3.6.2"/><vers num="3.7"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0056" published="2004-02-17" seq="2004-0056" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008687">1008687</ref></refs><vuln_soft><prod name="Business Communications Manager" vendor="Nortel Networks"><vers num=""/></prod><prod name="Succession 1000 IP Trunk and IP Peer Network" vendor="Nortel Networks"><vers num=""/></prod><prod name="802.11 Wireless IP Gateway" vendor="Nortel Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0057" published="2004-02-17" seq="2004-0057" severity="Medium" type="CVE"><desc><descript source="cve">The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid &quot;len&quot; or &quot;loc&quot; values to be used in a loop, a different vulnerability than CVE-2003-0989.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">multiple vulnerabilities in tcpdump 3.8.1</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-007.html">Updated tcpdump packages fix various vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9423">bid 9423</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-425">DSA-425-1 tcpdump -- multiple vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval851.html">OVAL851</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval854.html">OVAL854</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/174086">VU#174086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10636">10636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14837">tcpdump-rawprint-isakmp-dos(14837)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851">oval:org.mitre.oval:def:851</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854">oval:org.mitre.oval:def:854</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008716">1008716</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0058" published="2004-02-17" seq="2004-0058" severity="Low" type="CVE"><desc><descript source="cve">Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</ref><ref source="OSVDB" url="http://www.osvdb.org/3496">3496</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008702">1008702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10620">10620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14214">antivir-tmpfile-insecure(14214)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.9.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0059" published="2004-02-17" seq="2004-0059" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0060" published="2004-02-17" seq="2004-0060" severity="Medium" type="CVE"><desc><descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0061" published="2004-02-17" seq="2004-0061" severity="High" type="CVE"><desc><descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref></refs><vuln_soft><prod name="WWW File Share Pro" vendor="LionMax Software"><vers num="2.42" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0062" published="2004-02-17" seq="2004-0062" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to &quot;cause negative totals&quot; via an order with a large quantity.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2">FishCart Integer Overflow / Rounding Error</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9426">bid 9426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008731">1008731</ref></refs><vuln_soft><prod name="FishCart" vendor="FishNet"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0063" published="2004-02-17" seq="2004-0063" severity="High" type="CVE"><desc><descript source="cve">The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ncipher.com" url="http://www.ncipher.com/support/advisories/advisory8_payshield.html">payShield library may verify bad requests</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2">20040114 nCipher Advisory #8: payShield library may verify bad requests</ref><ref source="BID" url="http://www.securityfocus.com/bid/9422">9422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14832">payshield-incorrect-request-verification(14832)</ref><ref source="OSVDB" url="http://www.osvdb.org/3537">3537</ref></refs><vuln_soft><prod name="PayShield SPP library" vendor="nCipher"><vers num="1.3.12"/><vers num="1.5.18"/><vers num="1.6.18"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0064" published="2004-02-17" seq="2004-0064" severity="Low" type="CVE"><desc><descript source="cve">The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9411">bid 9411</ref><ref source="OSVDB" url="http://www.osvdb.org/3460">3460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10623">10623</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008703">1008703</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0065" published="2004-02-17" seq="2004-0065" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/11910">11910</ref><ref source="BID" url="http://www.securityfocus.com/bid/11925">11925</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0066" published="2004-02-17" seq="2004-0066" severity="Medium" type="CVE"><desc><descript source="cve">phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/3464">3464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14215">phpgedview-path-disclosure(14215)</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2004-0067" published="2004-02-17" seq="2004-0067" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2">More phpGedView Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded">20070827 PhpGedView login page multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/11868">11868</ref><ref source="BID" url="http://www.securityfocus.com/bid/11880">11880</ref><ref source="BID" url="http://www.securityfocus.com/bid/11882">11882</ref><ref source="BID" url="http://www.securityfocus.com/bid/11888">11888</ref><ref source="BID" url="http://www.securityfocus.com/bid/11890">11890</ref><ref source="BID" url="http://www.securityfocus.com/bid/11891">11891</ref><ref source="BID" url="http://www.securityfocus.com/bid/11894">11894</ref><ref source="BID" url="http://www.securityfocus.com/bid/11903">11903</ref><ref source="BID" url="http://www.securityfocus.com/bid/11904">11904</ref><ref source="BID" url="http://www.securityfocus.com/bid/11905">11905</ref><ref source="BID" url="http://www.securityfocus.com/bid/11906">11906</ref><ref source="BID" url="http://www.securityfocus.com/bid/11907">11907</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2995">ADV-2007-2995</ref><ref source="OSVDB" url="http://www.osvdb.org/3473">3473</ref><ref source="OSVDB" url="http://www.osvdb.org/3474">3474</ref><ref source="OSVDB" url="http://www.osvdb.org/3475">3475</ref><ref source="OSVDB" url="http://www.osvdb.org/3476">3476</ref><ref source="OSVDB" url="http://www.osvdb.org/3477">3477</ref><ref source="OSVDB" url="http://www.osvdb.org/3478">3478</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018613">1018613</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26628">26628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36285">phpgedview-login-xss(36285)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14212">phpgedview-multiple-xss(14212)</ref></refs><vuln_soft><prod name="phpGedView" vendor="PhPGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0068" published="2004-02-17" seq="2004-0068" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2">PhpDig 1.6.x: remote command execution</ref><ref patch="1" source="Phpdig.net" url="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9424">bid 9424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14826">phpdig-config-file-include(14826)</ref></refs><vuln_soft><prod name="PhpDig" vendor="PhpDig.net"><vers num="1.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0069" published="2004-02-17" seq="2004-0069" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2">Windows FTP Server Format String Vulnerability</ref><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2">exploit for HD Soft Windows FTP Server 1.6</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9385">bid 9385</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008658">1008658</ref></refs><vuln_soft><prod name="Windows FTP Server" vendor="HD Soft"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0070" published="2004-02-17" seq="2004-0070" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2">Remote Code Execution in ezContents</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9396">bid 9396</ref><ref source="CONFIRM" url="http://www.ezcontents.org/forum/viewtopic.php?t=361">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14199">ezcontents-php-file-include(14199)</ref><ref source="OSVDB" url="http://www.osvdb.org/6878">6878</ref></refs><vuln_soft><prod name="ezContents" vendor="VisualShapers"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0071" published="2004-02-17" seq="2004-0071" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2">PHP Manpage lookup directory transversal / file disclosing</ref><ref source="BID" url="http://www.securityfocus.com/bid/9395">9395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14203">manpagelookup-directory-traversal(14203)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008689">1008689</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0072" published="2004-02-17" seq="2004-0072" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., &quot;%5c%2e%2e&quot;) sequences in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2">Directory Traversal in Accipiter Direct Server 6.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14198">Accipiter Direct Server dot dot directory traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9389">bid 9389</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref><ref source="OSVDB" url="http://www.osvdb.org/3433">3433</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10600">10600</ref></refs><vuln_soft><prod name="Accipiter Direct Server" vendor="Accipiter"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0073" published="2004-02-17" seq="2004-0073" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9338">bid 9338</ref><ref source="OSVDB" url="http://www.osvdb.org/3318">3318</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008584">1008584</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10535">10535</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14136">easydynamicpages-php-file-include(14136)</ref><ref source="OSVDB" url="http://www.osvdb.org/3408">3408</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2">20040102 include() vuln in EasyDynamicPages v.2.0</ref></refs><vuln_soft><prod name="EasyDynamicPages" vendor="Stoitsov"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0074" published="2004-02-17" seq="2004-0074" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9352">bid 9352</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9341">bid 9341</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14906">xsok long -xsokdir buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14910">xsok-lang-bo(14910)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2">20040102 xsok local games exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2">20040103 xsok local games exploit (2)</ref></refs><vuln_soft><prod name="xsok" vendor="Michael Bischoff"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0075" published="2004-03-15" seq="2004-0075" severity="Low" type="CVE"><desc><descript source="cve">The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">Updated kernel packages resolve security vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15246">Linux kernel Vicam USB driver denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9690">bid 9690</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836">oval:org.mitre.oval:def:836</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0076" published="2004-08-18" reject="1" seq="2004-0076" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was removed from consideration by its Candidate Numbering Authority.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0077" published="2004-03-03" seq="2004-0077" severity="High" type="CVE"><desc><descript source="cve">The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2">Second critical mremap() bug found in all Linux, kernel,s</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-439">linux-kernel-2.4.16-arm -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15244">Linux kernel do_mremap allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9686">bid 9686</ref><ref adv="1" patch="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200403-02.xml">Linux kernel do_mremap local privilege escalation vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html">20040218 Second critical mremap() bug found in all Linux kernels</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-438">DSA-438</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-440">DSA-440</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-441">DSA-441</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-444">DSA-444</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-450">DSA-450</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-453">DSA-453</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-454">DSA-454</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-456">DSA-456</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-466">DSA-466</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-470">DSA-470</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-514">DSA-514</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-475">DSA-475</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-066.html">RHSA-2004:066</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">RHSA-2004:069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2">2004-0007</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2">2004-0008</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/981222">VU#981222</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref><ref source="OSVDB" url="http://www.osvdb.org/3986">3986</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825">oval:org.mitre.oval:def:825</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837">oval:org.mitre.oval:def:837</ref></refs><vuln_soft><prod name="Netwosix Linux" vendor="Netwosix"><vers num="1.0"/></prod><prod name="kernel_BOOT" vendor="Red Hat"><vers edition="i386" num="2.4.20.8"/></prod><prod name="kernel_doc" vendor="Red Hat"><vers edition="i386" num="2.4.20.8"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.2"/></prod><prod name="kernel" vendor="Red Hat"><vers edition="Athlon" num="2.4.20.8"/><vers edition="i386" num="2.4.20.8"/><vers edition="i686" num="2.4.20.8"/><vers edition="athlon smp" num="2.4.20.8"/><vers edition="i686 smp" num="2.4.20.8"/></prod><prod name="kernel_bigmem" vendor="Red Hat"><vers edition="i686" num="2.4.20.8"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="1.5"/><vers num="2.0"/></prod><prod name="kernel_source" vendor="Red Hat"><vers edition="i386 src" num="2.4.20.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0078" published="2004-03-03" seq="2004-0078" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://bugs.debian.org/126336">http://bugs.debian.org/126336</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-050.html">Updated mutt packages fix remotely-triggerable crash</ref><ref adv="1" patch="1" source="Mandrakesecure.net" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:010">mutt</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-051.html">Updated mutt packages fix remotely-triggerable crash</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9641">bid 9641</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15134">Mutt index menu buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2">20040211 Mutt-1.4.2 fixes buffer overflow.</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt">CSSA-2004-013.0</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010">MDKSA-2004:010</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2">20040215 LNSA-#2004-0001: mutt remote crash</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</ref><ref source="OSVDB" url="http://www.osvdb.org/3918">3918</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811">oval:org.mitre.oval:def:811</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838">oval:org.mitre.oval:def:838</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="1.2.1"/><vers num="1.2.5.1"/><vers num="1.2.5.5"/><vers num="1.2.5.4"/><vers num="1.2.5.12 OL"/><vers num="1.2.5.12"/><vers num="1.2.5"/><vers num="1.3.12.1"/><vers num="1.3.12"/><vers num="1.3.16"/><vers num="1.3.17"/><vers num="1.3.22"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.4.0"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0079" published="2004-11-23" seq="2004-0079" severity="Medium" type="CVE"><desc><descript source="cve">The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">Multiple Vulnerabilities in OpenSSL</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15505">OpenSSL do_change_cipher_spec function denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20040317.txt">http://www.openssl.org/news/secadv_20040317.txt</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-465">DSA-465</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html">ESA-20040317-003</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc">FreeBSD-SA-04:05</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">NetBSD-SA2004-005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html">SuSE-SA:2004:007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/288574">VU#288574</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2621.html">OVAL2621</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval870.html">OVAL870</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval975.html">OVAL975</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-095.shtml">FEDORA-2004-095</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-139.html">RHSA-2004:139</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-101.shtml">O-101</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-830.html">RHSA-2005:830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17401">17401</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html">FEDORA-2005-1042</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-829.html">RHSA-2005:829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17381">17381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17398">17398</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2">SSRT4717</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961">SSA:2004-077</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18247">18247</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621">oval:org.mitre.oval:def:2621</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870">oval:org.mitre.oval:def:870</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975">oval:org.mitre.oval:def:975</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="StoneGate VPN Client" vendor="Stonesoft"><vers num="1.7"/><vers num="1.7.2"/><vers num="2.0"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0080" published="2004-03-03" seq="2004-0080" severity="Medium" type="CVE"><desc><descript source="cve">The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2004-056.html">Updated util-linux packages fix information leak</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9558">bid 9558</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-06.xml">GLSA-200404-06</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2">20040331 OpenLinux: util-linux could leak sensitive data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2">20040408 LNSA-#2004-0010: login may leak sensitive data</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/801526">VU#801526</ref><ref source="OSVDB" url="http://www.osvdb.org/3796">3796</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10773">10773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15016">utillinux-information-leak(15016)</ref></refs><vuln_soft><prod name="util-linux" vendor="Andries Brouwer"><vers num="2.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0081" published="2004-11-23" seq="2004-0081" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/465542">OpenSSL does not properly handle unknown message types</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15509">OpenSSL unknown TLS message types denial of service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107955049331965&amp;w=2">20040317 Re: New OpenSSL releases fix denial of service attacks [17  March 2004]</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html">ESA-20040317-003</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-465">DSA-465</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-119.html">RHSA-2004:119</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc">20040304-01-U</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">TA04-078A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval871.html">OVAL871</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval902.html">OVAL902</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-095.shtml">FEDORA-2004-095</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-139.html">RHSA-2004:139</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871">oval:org.mitre.oval:def:871</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902">oval:org.mitre.oval:def:902</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="StoneGate VPN Client" vendor="Stonesoft"><vers num="1.7"/><vers num="1.7.2"/><vers num="2.0"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0082" published="2004-03-03" seq="2004-0082" severity="High" type="CVE"><desc><descript source="cve">The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</ref><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-064.html">Updated samba packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9637">bid 9637</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15132">Samba mksmbpasswd.sh could allow an attacker to gain access to user&apos;s account</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-078.shtml">O-078</ref><ref source="OSVDB" url="http://www.osvdb.org/3919">3919</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827">oval:org.mitre.oval:def:827</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0 alpha"/><vers num="3.0.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0083" published="2004-03-03" seq="2004-0083" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Xfree86" url="http://www.xfree86.org/cvs/changes">Recent Changes to XFree86</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9636">bid 9636</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2">XFree86FontInformationFileBufferOverflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15130">XFree86 font.alias file buffer overflow</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-02.xml">XFree86 Font Information File Buffer Overflow</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=72">http://www.idefense.com/application/poi/display?id=72</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval806.html">OVAL806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval830.html">OVAL830</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820006">VU#820006</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2">20040211 XFree86 vulnerability exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806">oval:org.mitre.oval:def:806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830">oval:org.mitre.oval:def:830</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0084" published="2004-03-03" seq="2004-0084" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9652">bid 9652</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15200">XFree86 CopyISOLatin1Lowered buffer overflow</ref><ref source="MISC" url="http://www.idefense.com/application/poi/display?id=73">http://www.idefense.com/application/poi/display?id=73</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval807.html">OVAL807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval831.html">OVAL831</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/667502">VU#667502</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807">oval:org.mitre.oval:def:807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831">oval:org.mitre.oval:def:831</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0085" published="2004-03-03" seq="2004-0085" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14992">Mac OS X mail undisclosed security issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/9504">bid 9504</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.1.5"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0086" published="2004-03-03" seq="2004-0086" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0087" published="2004-03-03" seq="2004-0087" severity="Low" type="CVE"><desc><descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14997">macosx-configd-file-manipulation(14997)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="OSVDB" url="http://www.osvdb.org/6819">6819</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0088" published="2004-03-03" seq="2004-0088" severity="Low" type="CVE"><desc><descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="OSVDB" url="http://www.osvdb.org/6820">6820</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0089" published="2004-03-03" seq="2004-0089" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9509">bid 9509</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a012704-1.txt">A012704-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/902374">VU#902374</ref><ref source="OSVDB" url="http://www.osvdb.org/6821">6821</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14968">macosx-trublue-environmentvariable-bo(14968)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0090" published="2004-12-31" seq="2004-0090" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not &quot;shutdown properly,&quot; which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3791&amp;cid=1">ESB-2004.0072</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10723/">10723</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2004-0091" published="2004-02-17" seq="2004-0091" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying &quot;There is no hidden field called &apos;reg_site&apos;, nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2">vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2">vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2"> RE: vBulletin Security Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2">:    Re: vBulletin Security Vulnerability</ref><ref source="MISC" url="http://securitytracker.com/alerts/2004/Jan/1008780.html">http://securitytracker.com/alerts/2004/Jan/1008780.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008780">1008780</ref></refs><vuln_soft><prod name="Vbulletin" vendor="Jelsoft"><vers num="3.0 beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0092" published="2004-03-03" seq="2004-0092" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Apple.com" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref source="APPLE" url="http://www.zone-h.org/advisories/read/id=3818">APPLE-SA-2004-01-26</ref><ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0093" published="2004-03-15" seq="2004-0093" severity="High" type="CVE"><desc><descript source="cve">XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-443">xfree86 -- several vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9701">bid 9701</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15272">XFree86 GLX array index denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0094" published="2004-03-15" seq="2004-0094" severity="High" type="CVE"><desc><descript source="cve">Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-443">xfree86 -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15273">XFree86 GLX integer signedness denial of service</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref><ref source="BID" url="http://www.securityfocus.com/bid/9701">9701</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0095" published="2004-02-17" seq="2004-0095" severity="Medium" type="CVE"><desc><descript source="cve">McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9476">bid 9476</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14989">epolicy-contentlength-post-dos(14989)</ref><ref source="OSVDB" url="http://www.osvdb.org/3744">3744</ref></refs><vuln_soft><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0096" published="2004-03-03" seq="2004-0096" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ModPython.org" url="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html">Mod_python 2.7.10</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-03.xml">GLSA-200401-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-058.html">RHSA-2004:058</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-063.html">RHSA-2004:063</ref></refs><vuln_soft><prod name="mod_python" vendor="Apache Software Foundation"><vers num="2.7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0097" published="2004-03-03" seq="2004-0097" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-047.html">Updated PWLib packages fix protocol security issues</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html">CERT Advisory CA-2004-01 Multiple H.323 Message Vulnerabilities</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/749342">Multiple vulnerabilities in H.323 implementations</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15202">PWLib message denial of service</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-448">DSA-448-1 pwlib -- several vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval803.html">OVAL803</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval826.html">OVAL826</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803">oval:org.mitre.oval:def:803</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826">oval:org.mitre.oval:def:826</ref><ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref></refs><vuln_soft><prod name="PWLib" vendor="OpenH323 Project"><vers num="1.6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0099" published="2004-03-03" seq="2004-0099" severity="Medium" type="CVE"><desc><descript source="cve">mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc">mksnap_ffs clears file system options</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9533">bid 9533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15005">freebsd-mksnapffs-bypass-security(15005)</ref><ref source="OSVDB" url="http://www.osvdb.org/3790">3790</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.1 Release"/><vers num="5.2 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2004-0103" published="2004-03-03" seq="2004-0103" severity="Medium" type="CVE"><desc><descript source="cve">crawl before 4.0.0 beta23 does not properly &quot;apply a size check&quot; when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-432">crawl -- buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9566">9566</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10788/">10788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15032">crawl-long-environment-bo(15032)</ref></refs><vuln_soft><prod name="Crawl" vendor="Linley Henzell"><vers num="4.0.0 b23" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0104" published="2004-03-03" seq="2004-0104" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-073.html">Updated metamail packages fix vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9692">bid 9692</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15259">Metamail header format string attack</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15245">metamail-contenttype-format-string(15245)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/518518">VU#518518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7" prev="1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0105" published="2004-03-03" seq="2004-0105" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-073.html">Updated metamail packages fix vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15258">Metamail splitmail file Subject header buffer overflow</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15247">metamail-printheader-nonascii-bo(15247)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/513062">VU#513062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref><ref source="BID" url="http://www.securityfocus.com/bid/9692">9692</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7" prev="1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0106" published="2004-03-03" seq="2004-0106" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">Updated XFree86 packages fix privilege escalation vulnerability</ref><ref adv="1" patch="1" source="Slackware.com" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">XFree86 security update</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9655">bid 9655</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15206">XFree86 improper handling of multiple font files</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval809.html">OVAL809</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval832.html">OVAL832</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809">oval:org.mitre.oval:def:809</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832">oval:org.mitre.oval:def:832</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.2.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0107" published="2004-04-15" seq="2004-0107" severity="Medium" type="CVE"><desc><descript source="cve">The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-053.html">Updated sysstat packages fix security vulnerabilities</ref><ref patch="1" source="SGI.com" url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc">SGI Advanced Linux Environment security update #14</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9838">bid 9838</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-093.html">RHSA-2004:093</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-097.shtml">O-097</ref><ref source="OSVDB" url="http://www.osvdb.org/6884">6884</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval849.html">OVAL849</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval862.html">OVAL862</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15428">sysstat-post-trigger-symlink(15428)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849">oval:org.mitre.oval:def:849</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862">oval:org.mitre.oval:def:862</ref></refs><vuln_soft><prod name="Sysstat" vendor="Sysstat"><vers num="4.0.7"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.1.6"/><vers num="4.1.7"/><vers num="5.0.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="sysstat" vendor="Red Hat"><vers edition="i386" num="4.0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0108" published="2004-04-15" seq="2004-0108" severity="Medium" type="CVE"><desc><descript source="cve">The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-053.html">Updated sysstat packages fix security vulnerabilities</ref><ref patch="1" source="SGI.com" url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc">SGI Advanced Linux Environment security update #14</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9844">bid 9844</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-460">DSA-460</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15437">sysstat-isag-symlink(15437)</ref></refs><vuln_soft><prod name="Sysstat" vendor="Sysstat"><vers num="4.0.7"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.1.6"/><vers num="4.1.7"/><vers num="5.0.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="sysstat" vendor="Red Hat"><vers edition="i386" num="4.0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0109" published="2004-06-01" seq="2004-0109" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc">20040405-01-U</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc">20040504-01-U</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval940.html">OVAL940</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-105.html">RHSA-2004:105</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-183.html">RHSA-2004:183</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html">SuSE-SA:2004:009</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="BID" url="http://www.securityfocus.com/bid/10141">10141</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11361">11361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11373">11373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11469">11469</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11470">11470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11486">11486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11494">11494</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11518">11518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11626">11626</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11861">11861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11986">11986</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12003">12003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15866">linux-iso9660-bo(15866)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940">oval:org.mitre.oval:def:940</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.5"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0110" published="2004-03-15" seq="2004-0110" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-090.html">Updated libxml2 packages fix security vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9718">bid 9718</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15301">Libxml2 nanohttp buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2">[OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-455">DSA-455</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-01.xml">GLSA-200403-01</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-091.html">RHSA-2004:091</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15302">libxml2-nanoftp-bo(15302)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10958/">10958</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval833.html">OVAL833</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval875.html">OVAL875</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/493966">VU#493966</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-086.shtml">O-086</ref><ref source="" url="http://www.xmlsoft.org/news.html">http://www.xmlsoft.org/news.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2">20040306 TSLSA-2004-0010 - libxml2</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-650.html">RHSA-2004:650</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833">oval:org.mitre.oval:def:833</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875">oval:org.mitre.oval:def:875</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">
SUSE-SR:2005:001</ref></refs><vuln_soft><prod name="Libxml2" vendor="XMLSoft"><vers num="2.4.19"/><vers num="2.4.23"/><vers num="2.5.4"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/></prod><prod name="Libxml" vendor="XMLSoft"><vers num="1.8.17"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0111" published="2004-04-15" seq="2004-0111" severity="Medium" type="CVE"><desc><descript source="cve">gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mandrakesecure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:020"></ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-103.html">Updated gdk-pixbuf packages fix crash</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9842">bid 9842</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-464">DSA-464</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020">MDKSA-2004:020</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-102.html">RHSA-2004:102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15426">gdk-pixbuf-bitmap-dos(15426)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845">oval:org.mitre.oval:def:845</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846">oval:org.mitre.oval:def:846</ref></refs><vuln_soft><prod name="GdkPixbuf" vendor="GNOME"><vers num="0.18"/><vers num="0.20"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="gdk_pixbuf" vendor="Red Hat"><vers edition="i386" num="0.18.0.7"/><vers edition="i386 Dev" num="0.18.0.7"/><vers edition="i386 Gnome" num="0.18.0.7"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0112" published="2004-11-23" seq="2004-0112" severity="Medium" type="CVE"><desc><descript source="cve">The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9899">OpenSSL Denial of Service Vulnerabilities</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html">Multiple Vulnerabilities in OpenSSL</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15508">OpenSSL on a server configured with Kerberos ciphersuites denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref><ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20040317.txt">http://www.openssl.org/news/secadv_20040317.txt</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834">CLA-2004:834</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">NetBSD-SA2004-005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-121.html">RHSA-2004:121</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt">SCOSA-2004.10</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html">SuSE-SA:2004:007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524">57524</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2">SSRT4717</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/484726">VU#484726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1049.html">OVAL1049</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval928.html">OVAL928</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml">20040317 Cisco OpenSSL Implementation Vulnerability</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-03.xml">GLSA-200403-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-120.html">RHSA-2004:120</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0012">2004-0012</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-101.shtml">O-101</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11139">11139</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961">SSA:2004-077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049">oval:org.mitre.oval:def:1049</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928">oval:org.mitre.oval:def:928</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023">MDKSA-2004:023</ref></refs><vuln_soft><prod name="Clientless VPN Gateway 4400 Series" vendor="Symantec"><vers num="5.0"/></prod><prod name="CacheOS CA_SA" vendor="Blue Coat Systems"><vers num="4.1.10"/><vers num="4.1.12"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2 .111"/><vers num="6.2.2"/><vers num="6.2.3"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2"/></prod><prod name="CSS Secure Content Accelerator" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.3"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/></prod><prod name="StoneBeat WebCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="CSS11000 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="CSS11500 Content Services Switch" vendor="Cisco"><vers num=""/></prod><prod name="GSX Server" vendor="VMWare"><vers num="2.0"/><vers num="2.0.1 build 2129"/><vers num="2.5.1 build 5336"/><vers num="2.5.1"/><vers num="3.0 build 7592"/></prod><prod name="SG203" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="FireWall-1" vendor="Checkpoint"><vers num="GX 2.0"/><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="VPN-1" vendor="Checkpoint"><vers num="Next Generation FP2"/><vers num="Next Generation FP1"/><vers num="Next Generation FP0"/><vers num="VSX NG with Application Intelligence"/></prod><prod name="WebNS" vendor="Cisco"><vers num="6.10 B4"/><vers num="6.10"/><vers num="7.1 0.2.06"/><vers num="7.1 0.1.02"/><vers num="7.2 0.0.03"/><vers num="7.10 .0.06s"/><vers num="7.10"/></prod><prod name="StoneBeat FullCluster" vendor="Stonesoft"><vers num="1 2.0"/><vers num="1 3.0"/><vers num="2.0"/><vers num="3.0"/><vers num="2.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="8.5"/><vers num="11.0"/><vers num="11.11"/><vers num="11.23"/></prod><prod name="SG5X" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Okena Stormwatch" vendor="Cisco"><vers num="3.2"/></prod><prod name="Instant Virtual Extranet" vendor="Neoteris"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="eDirectory" vendor="Novell"><vers num="8.0"/><vers num="8.5"/><vers num="8.5.12a"/><vers num="8.5.27"/><vers num="8.6.2"/><vers num="8.7"/><vers num="8.7.1 SU1"/><vers num="8.7.1"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.20"/><vers num="3.30"/><vers num="3.40"/></prod><prod name="SG200" vendor="Avaya"><vers num="4.4"/><vers num="4.31.29"/></prod><prod name="BSAFE SSL-J SDK" vendor="RSA"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.1"/></prod><prod name="WBEM" vendor="HP"><vers num="A.02.00.01"/><vers num="A.02.00.00"/><vers num="A.01.05.08"/></prod><prod name="Threat Response" vendor="Cisco"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num=""/></prod><prod name="Intuity" vendor="Avaya"><vers num="S3400"/><vers num="S3210"/><vers num="LX"/><vers num="R5 R5.1.46"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="SG208" vendor="Avaya"><vers num=""/><vers num="4.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod><prod name="Provider-1" vendor="Checkpoint"><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/></prod><prod name="Secure Content Accelerator" vendor="Cisco"><vers num="10000"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/><vers num="3.0"/></prod><prod name="AAA Server" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.8 Releng"/><vers num="4.8"/><vers num="4.9"/><vers num="5.1 Releng"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod><prod name="Apache-Based Web Server" vendor="HP"><vers num="2.0.43.04"/><vers num="2.0.43.00"/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="GSS 4480 Global Site Selector" vendor="Cisco"><vers num=""/></prod><prod name="SG5" vendor="Avaya"><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/></prod><prod name="Sidewinder" vendor="Secure Computing"><vers num="5.2.1.02"/><vers num="5.2.1"/><vers num="5.2.0.04"/><vers num="5.2.0.03"/><vers num="5.2.0.02"/><vers num="5.2.0.01"/><vers num="5.2"/></prod><prod name="iManager" vendor="Novell"><vers num="1.5"/><vers num="2.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="Speed Technologies LiteSpeed Web Server" vendor="Lite"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2 RC2"/><vers num="1.2 RC1"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3 RC3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="VSU" vendor="Avaya"><vers num="100 R2.0.1"/><vers num="10000 R2.0.1"/><vers num="2000 R2.0.1"/><vers num="5"/><vers num="500"/><vers num="5000 R2.0.1"/><vers num="5x"/><vers num="7500 R2.0.1"/></prod><prod name="ProxySG" vendor="Blue Coat Systems"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.2"/><vers num="7.3"/><vers num="8.0"/></prod><prod name="StoneGate" vendor="Stonesoft"><vers num="1.5.17"/><vers num="1.5.18"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="2.0.1"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.4"/></prod><prod name="WebSTAR" vendor="4D"><vers num="4.0"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.2.2"/><vers num="5.2.3"/><vers num="5.2.4"/><vers num="5.3"/><vers num="5.3.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.6"/><vers num="5.0.7"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.1"/></prod><prod name="openssl" vendor="Red Hat"><vers edition="i386" num="0.9.7a2"/><vers edition="i386 Dev" num="0.9.7a2"/><vers edition="i386 Perl" num="0.9.7a2"/><vers edition="i386" num="0.9.6.15"/><vers edition="i386" num="0.9.6b3"/></prod><prod name="StoneBeat SecurityCluster" vendor="Stonesoft"><vers num="2.0"/><vers num="2.5"/></prod><prod name="Firewall Services Module" vendor="Cisco"><vers num=""/><vers num="1.1 (3.005)"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.1 (0.208)"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.3"/></prod><prod name="Access Registrar" vendor="Cisco"><vers num=""/></prod><prod name="Crypto Accelerator 4000" vendor="Sun"><vers num="1.0"/></prod><prod name="ServerCluster" vendor="Stonesoft"><vers num="2.5"/><vers num="2.5.2"/></prod><prod name="MDS" vendor="Cisco"><vers num="9000"/></prod><prod name="GSS 4490 Global Site Selector" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0113" published="2004-03-29" seq="2004-0113" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://nagoya.apache.org/bugzilla/show_bug.cgi?id=27106">http://nagoya.apache.org/bugzilla/show_bug.cgi?id=27106</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15419">Apache HTTP Server mod_ssl plain HTTP request denial of service</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638">cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</ref><ref adv="1" source="Apacheweek.com" url="http://www.apacheweek.com/features/security-20">Overview of security vulnerabilities in Apache httpd 2.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9826">bid 9826</ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106"></ref><ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839">CLSA-2004:839</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-04.xml">GLSA-200403-04</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043">MDKSA-2004:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-084.html">RHSA-2004:084</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-182.html">RHSA-2004:182</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref><ref source="OSVDB" url="http://www.osvdb.org/4182">4182</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876">oval:org.mitre.oval:def:876</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0114" published="2004-03-03" seq="2004-0114" severity="Medium" type="CVE"><desc><descript source="cve">The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment&apos;s reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.pine.nl/press/pine-cert-20040201.txt">http://www.pine.nl/press/pine-cert-20040201.txt</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc">shmat reference counting bug</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15061">Multiple vendor BSD platforms allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9586">bid 9586</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2"> [PINE-CERT-20040201] reference count overflow in shmat()</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc">NetBSD-SA2004-004</ref><ref source="" url="http://www.openbsd.org/errata33.html#sysvshm"></ref><ref source="OSVDB" url="http://www.osvdb.org/3836">3836</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.2" prev="1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.6" prev="1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0115" published="2004-03-03" seq="2004-0115" severity="Medium" type="CVE"><desc><descript source="cve">VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp">Vulnerability in Virtual PC for Mac Could Allow Privilege Elevation (835150)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9632">bid 9632</ref><ref adv="1" source="Atstake" url="http://www.atstake.com/research/advisories/2004/a021004-1.txt">Virtual PC Services Insecure Temporary File Creation</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-076.shtml">O-076</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15113">virtual-pc-gain-privileges(15113)</ref><ref source="OSVDB" url="http://www.osvdb.org/3893">3893</ref></refs><vuln_soft><prod name="Virtual PC" vendor="Microsoft"><vers edition="Mac2" num="6.0"/><vers edition="Mac1" num="6.0"/><vers edition="Mac" num="6.0"/><vers edition="Mac" num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0116" published="2004-06-01" seq="2004-0116" severity="Medium" type="CVE"><desc><descript source="cve">An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="eEye" url="http://www.eeye.com/html/Research/Advisories/AD20040413A.html">AD20040413A</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx">MS04-012</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/417052">VU#417052</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp">MS04-012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval955.html">OVAL955</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval957.html">OVAL957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval958.html">OVAL958</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-115.shtml">O-115</ref><ref source="BID" url="http://www.securityfocus.com/bid/10127">10127</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Apr/1009758.html">1009758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11065/">11065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15708">win-rpcss-rpcmessage-dos(15708)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955">oval:org.mitre.oval:def:955</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957">oval:org.mitre.oval:def:957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958">oval:org.mitre.oval:def:958</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0117" published="2004-06-01" seq="2004-0117" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/353956">VU#353956</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval907.html">OVAL907</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval946.html">OVAL946</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval964.html">OVAL964</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15710">win-h323-bo(15710)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907">oval:org.mitre.oval:def:907</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946">oval:org.mitre.oval:def:946</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964">oval:org.mitre.oval:def:964</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="NetMeeting" vendor="Microsoft"><vers num="3" prev="1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0118" published="2004-06-01" seq="2004-0118" severity="High" type="CVE"><desc><descript source="cve">The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Full-Disclosure" url="http://lists.netsys.com/pipermail/full-disclosure/2004-April/020070.html">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref><ref adv="1" patch="1" source="eEye" url="http://www.eeye.com/html/Research/Advisories/AD20040413E.html">AD20040413E</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/783748">VU#783748</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1512.html">OVAL1512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1718.html">OVAL1718</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10117">10117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15714">win-vdm-gain-privileges(15714)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512">oval:org.mitre.oval:def:1512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718">oval:org.mitre.oval:def:1718</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0119" published="2004-06-01" seq="2004-0119" severity="High" type="CVE"><desc><descript source="cve">The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/638548">VU#638548</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html">20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1808.html">OVAL1808</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1962.html">OVAL1962</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1997.html">OVAL1997</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10113">10113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15715">win-spp-bo(15715)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808">oval:org.mitre.oval:def:1808</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962">oval:org.mitre.oval:def:1962</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997">oval:org.mitre.oval:def:1997</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="IIS" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0120" published="2004-06-01" seq="2004-0120" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/150236">VU#150236</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval885.html">OVAL885</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval886.html">OVAL886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval892.html">OVAL892</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10115">10115</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15712">ssl-message-dos(15712)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885">oval:org.mitre.oval:def:885</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886">oval:org.mitre.oval:def:886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892">oval:org.mitre.oval:def:892</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-18" name="CVE-2004-0121" published="2004-04-15" seq="2004-0121" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=79&amp;type=vulnerabilities">Microsoft Outlook &quot;mailto:&quot; Parameter Passing Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp">Vulnerability in Microsoft Outlook Could Allow Code Execution (828040)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9827">bid 9827</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893704602842&amp;w=2">20040310 Outlook mailto: URL argument injection vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-070A.html">TA04-070A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/305206">VU#305206</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-096.shtml">O-096</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:843">oval:org.mitre.oval:def:843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15414">outlook-mailtourl-execute-code(15414)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15429">outlook-ms04009-patch(15429)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="XP SP2"/><vers num="XP SP1"/><vers num="XP"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0122" published="2004-04-15" seq="2004-0122" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-010.asp">Vulnerability in MSN Messenger Could Allow Information Disclosure (838512)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9828">bid 9828</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/688094">VU#688094</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:844">oval:org.mitre.oval:def:844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15427">msn-ms04010-patch(15427)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15415">msn-request-view-files(15415)</ref></refs><vuln_soft><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2004-0123" published="2004-06-01" seq="2004-0123" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx">MS04-011</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/255924">VU#255924</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp">MS04-011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1007.html">OVAL1007</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1076.html">OVAL1076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval924.html">OVAL924</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref><ref source="BID" url="http://www.securityfocus.com/bid/10118">10118</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15713">win-asn1-double-free(15713)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007">oval:org.mitre.oval:def:1007</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076">oval:org.mitre.oval:def:1076</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924">oval:org.mitre.oval:def:924</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2004-0124" published="2004-06-01" seq="2004-0124" severity="Low" type="CVE"><desc><descript source="cve">The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an &quot;alter context&quot; call that contains additional data, aka the &quot;Object Identity Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx">MS04-012</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/212892">VU#212892</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp">MS04-012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1041.html">OVAL1041</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1062.html">OVAL1062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1066.html">OVAL1066</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1072.html">OVAL1072</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-115.shtml">O-115</ref><ref source="BID" url="http://www.securityfocus.com/bid/10121">10121</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11065/">11065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15711">win-objectidentifier-open-port(15711)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041">oval:org.mitre.oval:def:1041</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062">oval:org.mitre.oval:def:1062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066">oval:org.mitre.oval:def:1066</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072">oval:org.mitre.oval:def:1072</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0"/><vers num="Server 4.0"/><vers num="4.0"/><vers num="Terminal Server 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2004-0125" published="2004-08-06" seq="2004-0125" severity="High" type="CVE"><desc><descript source="cve">The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10485">FreeBSD jail() Process Unauthorized Routing Table Modification Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16342">FreeBSD jailed process routing table modification</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc">FreeBSD-SA-04:12</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.10 pre"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0126" published="2004-03-29" seq="2004-0126" severity="Medium" type="CVE"><desc><descript source="cve">The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn&apos;t have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD.org" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc">Jailed processes can attach to other jails</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9762">bid 9762</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15344">FreeBSD jail_attach allows elevated privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/4101">4101</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Release"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0127" published="2004-03-03" seq="2004-0127" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/352355">PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9529">bid 9529</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=3768">3768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15129">phpgedview-editconfig-directory-traversal(15129)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1008892">1008892</ref></refs><vuln_soft><prod name="PhpGedView" vendor="PhpGedView"><vers num="2.52.3"/><vers num="2.60"/><vers num="2.61"/><vers num="2.61.1"/><vers num="2.65"/><vers num="2.65.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-02" name="CVE-2004-0128" published="2004-03-03" seq="2004-0128" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/352355">Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref><ref adv="1" source="SourceForge.net" url="http://sourceforge.net/project/shownotes.php?release_id=141517">PhpGedView v2.65.2</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9531">bid 9531</ref><ref source="OSVDB" url="http://www.osvdb.org/3769">3769</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14987">phpgedview-gedfilconf-file-include(14987)</ref></refs><vuln_soft><prod name="PhpGedView" vendor="PhpGedView"><vers num="2.52.3"/><vers num="2.60"/><vers num="2.61"/><vers num="2.61.1"/><vers num="2.65"/><vers num="2.65.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0129" published="2004-03-03" seq="2004-0129" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=350228">http://sourceforge.net/forum/forum.php?forum_id=350228</ref><ref source="CONFIRM" url="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2">Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-05.xml">phpMyAdmin &lt; 2.5.6-rc1: possible attack against export.php</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9564">bid 9564</ref><ref source="OSVDB" url="http://www.osvdb.org/3800">3800</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10769">10769</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15021">phpmyadmin-dotdot-directory-traversal(15021)</ref></refs><vuln_soft><prod name="PhpMyAdmin" vendor="PhpMyAdmin"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.2 rc3"/><vers num="2.2 rc2"/><vers num="2.2 rc1"/><vers num="2.2 pre1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.4.0"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.4"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0130" published="2004-03-03" seq="2004-0130" severity="Medium" type="CVE"><desc><descript source="cve">login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SecuriTeam.com" url="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html">PhpGedView Path Disclosure Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Jan/1008844.html">1008844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15128">phpgedview-loginphp-path-disclosure(15128)</ref><ref source="" url="http://www.netvigilance.com/advisory0001"></ref><ref source="OSVDB" url="http://www.osvdb.org/6886">6886</ref></refs><vuln_soft><prod name="phpGedView" vendor="phpGedView"><vers num="2.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0131" published="2004-03-03" seq="2004-0131" severity="Medium" type="CVE"><desc><descript source="cve">The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</ref><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/016721.html">GNU Radius Remote Denial of Service Vulnerability</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/277396">GNU Radius accounting service fails to properly handle exceptional Acct-Status-Type and Acct-Session-Id attributes</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9578">bid 9578</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15046">GNU Radius rad_print_request denial of service</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true">20040204 GNU Radius Remote Denial of Service Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3824">3824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10799">10799</ref></refs><vuln_soft><prod name="Radius" vendor="GNU"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0132" published="2004-03-03" seq="2004-0132" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2">PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9638">bid 9638</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15135">ezContents multiple .php PHP file inclusion</ref></refs><vuln_soft><prod name="ezContents" vendor="VisualShapers"><vers num="1.40"/><vers num="1.41"/><vers num="1.42"/><vers num="1.43"/><vers num="1.44"/><vers num="1.45b"/><vers num="1.45"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0.1"/><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0133" published="2004-06-01" seq="2004-0133" severity="Low" type="CVE"><desc><descript source="cve">The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc">20040405-01-U</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="BID" url="http://www.securityfocus.com/bid/10151">10151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15901">linux-xfs-info-disclosure(15901)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0134" published="2004-08-18" seq="2004-0134" severity="High" type="CVE"><desc><descript source="cve">cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10418">IRIX Checkpoint and Restart libcpr Library Loading Privilege Escalation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16259">SGI IRIX cpr allows elevated privileges</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc">20040507-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="4.0"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5B"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5 20"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22m"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0135" published="2004-08-06" seq="2004-0135" severity="High" type="CVE"><desc><descript source="cve">The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16413">SGI IRIX SGI_IOPROBE allows root privileges</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10548/">SGI IRIX SYSSGI() System Call Unprivileged User Kernel Memory Access Vulnerability</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7122">7122</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3.2"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="4.0"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5B"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5 20"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.19"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.22m"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0136" published="2004-08-06" seq="2004-0136" severity="Low" type="CVE"><desc><descript source="cve">The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a &quot;corrupted binary.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10547">SGI IRIX Undisclosed MapElf32Exec Local Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16416">SGI IRIX mapelf32exec denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">Updated kernel packages fix security vulnerabilities</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7123">7123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0137" published="2004-08-06" seq="2004-0137" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of &quot;page invalidation issues.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10549">SGI IRIX Undisclosed Init Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16417">SGI IRIX page denial of service</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc">20040601-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/7124">7124</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11872">11872</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-31" name="CVE-2004-0138" published="2004-12-31" seq="2004-0138" severity="Medium" type="CVE"><desc><descript source="cve">The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20162">20162</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="" url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes"></ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="BID" url="http://www.securityfocus.com/bid/18174">18174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-549.html">RHSA-2004:549</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43124">linux-kernel-elfloader-dos(43124)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.24"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0139" published="2005-01-10" seq="2004-0139" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which &quot;t_unbind changes t_bind&apos;s behavior,&quot; has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11276">SGI IRIX T_Bind/T_UnBind Undisclosed Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17547">SGI IRIX bsd.a kernel t_bind and t_unbind</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc">20040905-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12682">12682</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.22"/><vers num="6.5.23"/><vers num="6.5.24"/><vers num="6.5.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0143" published="2004-03-03" seq="2004-0143" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2">ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref><ref adv="1" patch="1" source="Pentest.co.uk" url="http://www.pentest.co.uk/documents/ptl-2004-01.html">Multiple vulnerabilities in Nokia phones</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9603">bid 9603</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15107">Nokia OBEX denial of service</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref></refs><vuln_soft><prod name="Nokia" vendor="Nokia"><vers num="6310i"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0148" published="2004-04-15" seq="2004-0148" severity="High" type="CVE"><desc><descript source="cve">wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-457">wu-ftpd -- several vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-096.html">Updated wu-ftpd package fixes security issues</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9832">bid 9832</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2">SSRT4704</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1867">ADV-2006-1867</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147">oval:org.mitre.oval:def:1147</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636">oval:org.mitre.oval:def:1636</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637">oval:org.mitre.oval:def:1637</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648">oval:org.mitre.oval:def:648</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11055">11055</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20168">20168</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1">102356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15423">wuftpd-restrictedgid-gain-access(15423)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.1"/><vers edition="academ" num="2.4.2 Beta2"/><vers edition="academ" num="2.4.2 Beta18"/><vers num="2.4.2 VR17"/><vers num="2.4.2 VR16"/><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18 VR8"/><vers num="2.4.2 Beta18 VR7"/><vers num="2.4.2 Beta18 VR6"/><vers num="2.4.2 Beta18 VR5"/><vers num="2.4.2 Beta18 VR4"/><vers num="2.4.2 Beta18 VR15"/><vers num="2.4.2 Beta18 VR14"/><vers num="2.4.2 Beta18 VR13"/><vers num="2.4.2 Beta18 VR12"/><vers num="2.4.2 Beta18 VR11"/><vers num="2.4.2 Beta18 VR10"/><vers num="2.5.0"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0149" published="2004-05-04" seq="2004-0149" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-451">DSA-451-1 xboing -- buffer overflows</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9764">xboing Local Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15347">xboing buffer overflow</ref></refs><vuln_soft><prod name="xboing" vendor="xboing"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0150" published="2004-04-15" seq="2004-0150" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-458">python2.2 -- buffer overflow</ref><ref adv="1" patch="1" source="Mandrakesecure" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:019">python</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9836">bid 9836</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml">GLSA-200409-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019">MDKSA-2004:019</ref><ref source="OSVDB" url="http://www.osvdb.org/4172">4172</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15409">python-getaddrinfo-bo(15409)</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.2"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0151" published="2004-04-15" seq="2004-0151" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-462">xitalk -- missing privilege release</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9851">bid 9851</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15456">xitalk allows attacker to gain elevated privileges</ref><ref source="MISC" url="http://shellcode.org/Advisories/XITALK.txt">http://shellcode.org/Advisories/XITALK.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11114/">11114</ref></refs><vuln_soft><prod name="xitalk" vendor="XInterceptTalk"><vers num="1.1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0152" published="2004-04-15" seq="2004-0152" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15601">emil email multiple buffer overflows</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2">New emil packages fix multiple vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-468">emil -- several vulnerabilities</ref></refs><vuln_soft><prod name="emil" vendor="emil"><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.0 Beta9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0153" published="2004-04-15" seq="2004-0153" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2">New emil packages fix multiple vulnerabilities</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-468">emil -- several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15602">emil format string attack</ref></refs><vuln_soft><prod name="emil" vendor="emil"><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.1.0 Beta9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0154" published="2004-06-14" seq="2004-0154" severity="Medium" type="CVE"><desc><descript source="cve">rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-072.html">RHSA-2004:072</ref><ref adv="1" patch="1" source="Trustix" url="http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt">2004-0009</ref><ref adv="1" source="Red Hat" url="http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15418">nfs-utils-dns-dos(15418)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9813">bugtraq id 9813</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval861.html">OVAL861</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861">oval:org.mitre.oval:def:861</ref></refs><vuln_soft><prod name="nfs-utils" vendor="nfs"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0155" published="2004-06-01" seq="2004-0155" severity="High" type="CVE"><desc><descript source="cve">The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136746911000&amp;w=2">20040407 CAN-2004-0155: The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:027">MDKSA-2004:027</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-165.html">RHSA-2004:165</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml">GLSA-200406-17</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:027">MDKSA-2004:027</ref><ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069">MDKSA-2004:069</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt">SCOSA-2005.10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval945.html">OVAL945</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/552398">VU#552398</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11328">11328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945">oval:org.mitre.oval:def:945</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:027">MDKSA-2004:027</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0156" published="2004-06-01" seq="2004-0156" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-485">DSA-485</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308904205272&amp;w=2">20040426 [ GLSA 200404-18 ] Multiple Vulnerabilities in ssmtp</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-18.xml">GLSA-200404-18</ref><ref source="BID" url="http://www.securityfocus.com/bid/10150">10150</ref><ref source="OSVDB" url="http://www.osvdb.org/5360">5360</ref><ref source="OSVDB" url="http://www.osvdb.org/5361">5361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009788">1009788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11378">11378</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11384">11384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11485">11485</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11571">11571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15872">ssmtp-die-logevent-format-string(15872)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403772130855&amp;w=2">20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)</ref></refs><vuln_soft><prod name="ssmtp" vendor="ssmtp"><vers num="2.49" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0157" published="2004-06-01" seq="2004-0157" severity="Medium" type="CVE"><desc><descript source="cve">x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-484">DSA-484</ref><ref source="" url="http://shellcode.org/Advisories/XONIX.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10149">10149</ref><ref source="OSVDB" url="http://www.osvdb.org/5358">5358</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009789">1009789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11382">11382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15873">xonix-privilege-dropping(15873)</ref></refs><vuln_soft><prod name="xonix" vendor="xonix"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0158" published="2004-03-29" seq="2004-0158" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in lbreakout2 allows local users to gain &apos;games&apos; group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2">lbreakout2 &lt; 2.4beta-2 local exploit</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-445"> lbreakout2 -- buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9712">bid 9712</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15229">LBreakout2 HOME environment variable buffer overflow</ref><ref source="CONFIRM" url="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</ref></refs><vuln_soft><prod name="LBreakout2" vendor="Lgames"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0159" published="2004-03-15" seq="2004-0159" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an &quot;ls&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2">New hsftp packages fix format string vulnerability</ref><ref adv="1" patch="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017737.html">New hsftp packages fix format string vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9715">bid 9715</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15276">hsftp format string attack</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/4029">4029</ref></refs><vuln_soft><prod name="hsftp" vendor="Samhain Labs"><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.9"/><vers num="1.10"/><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0160" published="2004-03-29" seq="2004-0160" severity="High" type="CVE"><desc><descript source="cve">Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-446">synaesthesia -- insecure file creation</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15279">Synaesthesia configuration file symlink attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9713">bid 9713</ref></refs><vuln_soft><prod name="Synaesthesia" vendor="Synaesthesia"><vers num="2.1.0"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0161" published="2004-10-20" seq="2004-0161" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524928232568&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/9274">mime-tools-parameter-encoding(9274)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2004-0162" published="2004-10-20" seq="2004-0162" severity="High" type="CVE"><desc><descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Uniras.gov" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm">NISCC Vulnerability Advisory 380375/MIME</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11157">bid 11157</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517563513776&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17332">mime-rfc822-filtering-bypass(17332)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.3"/><vers num="6.4"/><vers num="6.31"/><vers num="6.32"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/><vers num="4.3.14"/><vers num="4.3.15"/></prod><prod name="ripMime" vendor="Paul L Daniels"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.3.2.3"/><vers num="1.3.2.2"/><vers num="1.3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2004-0163" published="2004-09-28" seq="2004-0163" severity="Medium" type="CVE"><desc><descript source="cve">Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="corsaire" url="http://www.corsaire.com/advisories/c031120-002.txt">Sygate Secure Enterprise replay issue</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16945">Sygate Secure Enterprise replay denial of service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215685731675&amp;w=2">20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue</ref></refs><vuln_soft><prod name="Secure Enterprise" vendor="Sygate Technologies"><vers num="3.5MR3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0164" published="2004-03-03" seq="2004-0164" severity="Medium" type="CVE"><desc><descript source="cve">KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2">Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14117">OpenBSD ISAKMP daemon Invalid SPI could allow an attacker to delete IPsec SAs</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc">NetBSD-SA2004-001</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14118">openbsd-isakmp-initialcontact-delete-sa(14118)</ref><ref source="BID" url="http://www.securityfocus.com/bid/9417">9417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval947.html">OVAL947</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref><ref source="BID" url="http://www.securityfocus.com/bid/9416">9416</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947">oval:org.mitre.oval:def:947</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num="all versions"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0165" published="2004-03-15" seq="2004-0165" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref adv="1" patch="1" source="Atstake.com" url="http://www.atstake.com/research/advisories/2004/a022304-1.txt">Mac OS X pppd Format String Vulnerability</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15297">Mac OS X ppp daemon format string attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9730">bid 9730</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/841742">Apple Mac OS X Point-to-Point Protocol daemon (pppd) contains format string vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="OSVDB" url="http://www.osvdb.org/6822">6822</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0166" published="2004-03-15" seq="2004-0166" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to &quot;the display of URLs in the status bar.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14993">Mac OS X Safari Web browser undisclosed security issue</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/194238">Apple Mac OS X Safari fails to properly display URLs in the status bar</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14993">macosx-safari-unknown(14993)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0167" published="2004-03-15" seq="2004-0167" severity="High" type="CVE"><desc><descript source="cve">DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15300">Mac OS X unknown issue in DiskArbitration implementation</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/578886">VU#578886</ref><ref source="BID" url="http://www.securityfocus.com/bid/9731">9731</ref><ref source="OSVDB" url="http://www.osvdb.org/6824">6824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15300">macos-diskarbitration-unknown(15300)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0168" published="2004-03-15" seq="2004-0168" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to &quot;notification logging.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15299">Mac OS X unknown issue in CoreFoundation notification logging</ref><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15299">macos-corefoundation-unknown(15299)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10959/">10959</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8" prev="1"/><vers num="10.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0169" published="2004-03-15" seq="2004-0169" severity="Medium" type="CVE"><desc><descript source="cve">QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00046.html">http://lists.apple.com/mhonarc/security-announce/msg00046.html</ref><ref patch="1" source="Apple" url="http://docs.info.apple.com/article.html?artnum=61798">Apple Security Updates</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15291">Darwin Streaming Server DESCRIBE request denial of service</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765514003396&amp;w=2">Darwin Streaming Server Remote Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9735">bid 9735</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/460350">Apple Quicktime/Darwin Streaming Server fails to properly parse DESCRIBE requests</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/6826">6826</ref><ref source="OSVDB" url="http://www.osvdb.org/6837">6837</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.3"/></prod><prod name="Quicktime Streaming Server" vendor="Apple"><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0171" published="2004-03-15" seq="2004-0171" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15369">FreeBSD memory buffers (mbufs) denial of service</ref><ref adv="1" patch="1" source="iDefense.com" url="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities">FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9792">bid 9792</ref><ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc">FreeBSD-SA-04:04</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395670">VU#395670</ref><ref source="OSVDB" url="http://www.osvdb.org/4124">4124</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.6.2"/><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.3"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0172" published="2004-03-15" seq="2004-0172" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2003-October/011610.html">ltrace bug</ref><ref adv="1" source="SecurityTracker.com" url="http://www.securitytracker.com/alerts/2003/Oct/1007896.html">ltrace Heap Overflow May Let Local Users Execute Arbitrary Code With Root Privileges</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/13389">ltrace search_for_command buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/8790">bid 8790</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html">20031008 ltrace bug</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html">20031008 ltrace bug</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1007896">1007896</ref></refs><vuln_soft><prod name="ltrace" vendor="Juan Cespedes"><vers num="0.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0173" published="2004-04-15" seq="2004-0173" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing &quot;..%5C&quot; (dot dot encoded backslash) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.apacheweek.com/issues/04-03-12">http://www.apacheweek.com/issues/04-03-12</ref><ref source="CONFIRM" url="http://nagoya.apache.org/bugzilla/show_bug.cgi?id=26152">http://nagoya.apache.org/bugzilla/show_bug.cgi?id=26152</ref><ref adv="1" patch="1" source="Netsys" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017740.html">Apache for cygwin directory traversal vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9733">bid 9733</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15293">Apache for Cygwin dot dot directory traversal</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/10962">10962</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="0.8.11"/><vers num="0.8.14"/><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.5"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0174" published="2004-05-04" seq="2004-0174" severity="Medium" type="CVE"><desc><descript source="cve">Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a &quot;short-lived connection on a rarely-accessed listening socket.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107973894328806&amp;w=2">[ANNOUNCE] Apache HTTP Server 2.0.49 Released</ref><ref adv="1" patch="1" source="The aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066914830552&amp;w=2">TSLSA-2004-0017 - apache</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15540">Apache HTTP Server socket starvation denial of service</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-405.html">Stronghold 4: New release fixes Apache, mod_ssl, and PHP issues</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1982.html">OVAL1982</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/132110">VU#132110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11170">11170</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref><ref source="BID" url="http://www.securityfocus.com/bid/9921">9921</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009495.html">1009495</ref><ref source="" url="http://www.apache.org/dist/httpd/CHANGES_1.3"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100110.html">OVAL100110</ref><ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110">oval:org.mitre.oval:def:100110</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982">oval:org.mitre.oval:def:1982</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.49" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2004-0175" published="2004-08-18" seq="2004-0175" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9986">OpenSSH SCP Client File Corruption Vulnerability</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/security/2004_09_kernel.html">[suse-security-announce] SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:009)</ref><ref adv="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831">Vulnerabilidade no comando scp</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147</ref><ref source="CONFIRM" url="http://www.juniper.net/support/security/alerts/adv59739.txt">http://www.juniper.net/support/security/alerts/adv59739.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831">CLSA-2004:831</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html">SuSE-SA:2004:009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-106.html">RHSA-2005:106</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-212.shtml">O-212</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16323">openssh-scp-file-overwrite(16323)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-074.html">RHSA-2005:074</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-165.html">RHSA-2005:165</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-481.html">RHSA-2005:481</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-495.html">RHSA-2005:495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt">SCOSA-2006.11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19243">19243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="OSVDB" url="http://www.osvdb.org/9550">
9550</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.0 p1"/><vers num="3.0"/><vers num="3.0.1 p1"/><vers num="3.0.1"/><vers num="3.0.2 p1"/><vers num="3.0.2"/><vers num="3.1 p1"/><vers num="3.1"/><vers num="3.2"/><vers num="3.2.2 p1"/><vers num="3.2.3 p1"/><vers num="3.3 p1"/><vers num="3.3"/><vers num="3.4 p1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0176" published="2004-05-04" seq="2004-0176" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108007072215742&amp;w=2">Advisory 03/2004: Multiple (13) Ethereal remote overflows</ref><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2">LNSA-#2004-0007: Multiple security problems in Ethereal</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15569">Ethereal multiple dissectors buffer overflows</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-511">DSA-511-1 ethereal -- buffer overflows</ref><ref source="MISC" url="http://security.e-matters.de/advisories/032004.html">http://security.e-matters.de/advisories/032004.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00013.html">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-07.xml">GLSA-200403-07</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-136.html">RHSA-2004:136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-137.html">RHSA-2004:137</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval878.html">OVAL878</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval887.html">OVAL887</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/119876">VU#119876</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/125156">VU#125156</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433596">VU#433596</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/591820">VU#591820</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/644886">VU#644886</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/659140">VU#659140</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/740188">VU#740188</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/864884">VU#864884</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/931588">VU#931588</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11185">11185</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835">CLA-2004:835</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878">oval:org.mitre.oval:def:878</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887">oval:org.mitre.oval:def:887</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024">MDKSA-2004:024</ref><ref source="OSVDB" url="http://www.osvdb.org/6893">6893</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0177" published="2004-06-01" seq="2004-0177" severity="Medium" type="CVE"><desc><descript source="cve">The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref adv="1" patch="1" source="Red Hat" url="http://rhn.redhat.com/errata/RHSA-2004-166.html">RHSA-2004:166</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="LinuxSecurity" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ">http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-126.shtml">O-126</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="BID" url="http://www.securityfocus.com/bid/10152">10152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15867">linux-ext3-info-disclosure(15867)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-505.html">RHSA-2004:505</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0178" published="2004-06-01" seq="2004-0178" severity="Low" type="CVE"><desc><descript source="cve">The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-413.html">RHSA-2004:413</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-437.html">RHSA-2004:437</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc">20040804-01-U</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA">http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-193.shtml">O-193</ref><ref source="BID" url="http://www.securityfocus.com/bid/9985">9985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15868">linux-sound-blaster-dos(15868)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0179" published="2004-06-01" seq="2004-0179" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-487">DSA-487</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-157.html">RHSA-2004:157</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1552">FEDORA-2004-1552</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-158.html">RHSA-2004:158</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-159.html">RHSA-2004:159</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-160.html">RHSA-2004:160</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-01.xml">GLSA-200405-01</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-04.xml">GLSA-200405-04</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1065.html">OVAL1065</ref><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html">SuSE-SA:2004:008</ref><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html">SuSE-SA:2004:009</ref><ref adv="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:032">MDKSA-2004:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/10136">10136</ref><ref source="OSVDB" url="http://www.osvdb.org/5365">5365</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/11363">11363</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108214147022626&amp;w=2">20040416 void.at - neon format string bugs</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213873203477&amp;w=2">20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065">oval:org.mitre.oval:def:1065</ref></refs><vuln_soft><prod name="Cadaver WebDAV Client" vendor="Cadaver"><vers num="0.22.1"/><vers num="0.22.0"/><vers num="0.21.0"/><vers num="0.20.5"/><vers num="0.20.4"/><vers num="0.20.3"/><vers num="0.20.2"/><vers num="0.20.1"/><vers num="0.20.0"/></prod><prod name="Subversion" vendor="Subversion"><vers num=""/></prod><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.2"/></prod><prod name="Neon Client Library" vendor="Neon"><vers num="0.24.4"/><vers num="0.24.3"/><vers num="0.24.2"/><vers num="0.24.1"/><vers num="0.24"/><vers num="0.23.8"/><vers num="0.23.7"/><vers num="0.23.6"/><vers num="0.23.5"/><vers num="0.23.4"/><vers num="0.23.3"/><vers num="0.23.2"/><vers num="0.23.1"/><vers num="0.23"/><vers num="0.19.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0180" published="2004-06-01" seq="2004-0180" severity="Low" type="CVE"><desc><descript source="cve">The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-486">DSA-486</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc">FreeBSD-SA-04:07</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:028">MDKSA-2004:028</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-153.html">RHSA-2004:153</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-154.html">RHSA-2004:154</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:028">MDKSA-2004:028</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1042.html">OVAL1042</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-13.xml">GLSA-200404-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11368">11368</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11371">11371</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11374">11374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11375">11375</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11377">11377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11380">11380</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11391">11391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11400">11400</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11405">11405</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11548">11548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15864">cvs-rcs-create-files(15864)</ref><ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2">FEDORA-2004-1620</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181">SSA:2004-108-02</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042">oval:org.mitre.oval:def:1042</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:028">MDKSA-2004:028</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0181" published="2004-06-01" seq="2004-0181" severity="Low" type="CVE"><desc><descript source="cve">The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref adv="1" patch="1" source="Linux Security" url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html">ESA-20040428-004</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2">2004-0020</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">GLSA-200407-02</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref><ref source="BID" url="http://www.securityfocus.com/bid/10143">10143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15902">linux-jfs-info-disclosure(15902)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-504.html">RHSA-2004:504</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029">MDKSA-2004:029</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0182" published="2004-06-01" seq="2004-0182" severity="Medium" type="CVE"><desc><descript source="cve">Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-156.html">RHSA-2004:156</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.0.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0183" published="2004-05-04" seq="2004-0183" severity="Medium" type="CVE"><desc><descript source="cve">TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI&apos;s, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-478">DSA-478-1 tcpdump -- denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0017.html">http://www.rapid7.com/advisories/R7-0017.html</ref><ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt">http://www.tcpdump.org/tcpdump-changes.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1468">FEDORA-2004-1468</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-219.html">RHSA-2004:219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15680">tcpdump-isakmp-delete-bo(15680)</ref><ref source="BID" url="http://www.securityfocus.com/bid/10003">10003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval972.html">OVAL972</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240790">VU#240790</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009593">1009593</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11258">11258</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11320">11320</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0015">2004-0015</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972">oval:org.mitre.oval:def:972</ref></refs><vuln_soft><prod name="TCPDUMP" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0184" published="2004-05-04" seq="2004-0184" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-478">DSA-478-1 tcpdump -- denial of service</ref><ref adv="1" source="rapid7" url="http://www.rapid7.com/advisories/R7-0017.html">Rapid7 Advisory R7-0017</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15602">emil format string attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref><ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt">http://www.tcpdump.org/tcpdump-changes.txt</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1468">FEDORA-2004-1468</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-219.html">RHSA-2004:219</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/492558">VU#492558</ref><ref source="BID" url="http://www.securityfocus.com/bid/10004">10004</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval976.html">OVAL976</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15679">tcpdump-isakmp-integer-underflow(15679)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1009593">1009593</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11258">11258</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0015">2004-0015</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976">oval:org.mitre.oval:def:976</ref></refs><vuln_soft><prod name="TCPDUMP" vendor="LBL"><vers num="3.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0185" published="2004-03-15" seq="2004-0185" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</ref><ref adv="1" patch="1" source="Securiteam.com" url="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html">Wu-FTPd SKEY Stack Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/13518">WU-FTPD SKEY authentication buffer overflow</ref><ref patch="1" source="Ftpd.org" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-457">DSA-457-1 wu-ftpd -- several vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-096.html">Updated wu-ftpd package fixes security issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/8893">8893</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0186" published="2004-03-15" seq="2004-0186" severity="High" type="CVE"><desc><descript source="cve">smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2">Samba 3.x + kernel 2.6.x local root vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15131">Samba smbmnt allows elevated privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9619">bid 9619</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-463">DSA-463-1 samba -- privilege escalation</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3916">3916</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0"/><vers num="3.0.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2004-0187" published="2004-03-15" reject="1" seq="2004-0187" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0188" published="2004-03-15" seq="2004-0188" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2">Calife heap corrupt / potential local root exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9756">bid 9756</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15335">Calife long password buffer overflow</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-461">DSA-461-1 calife -- buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/9776">9776</ref></refs><vuln_soft><prod name="Calife" vendor="Calife"><vers num="2.8.4 c"/><vers num="2.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2004-0189" published="2004-03-15" seq="2004-0189" severity="High" type="CVE"><desc><descript source="cve">The &quot;%xx&quot; URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL (&quot;%00&quot;) characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Squid-cache.org" url="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt"> Squid Proxy Cache Security Update Advisory SQUID-2004:1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9778">bid 9778</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15366">Squid url_regex ACL bypass</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838">CLA-2004:838</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-474">DSA-474</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-11.xml">GLSA-200403-11</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025">MDKSA-2004:025</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-133.html">RHSA-2004:133</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-134.html">RHSA-2004:134</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt">SCOSA-2005.16</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</ref><ref source="OSVDB" url="http://www.osvdb.org/5916">5916</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877">oval:org.mitre.oval:def:877</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941">oval:org.mitre.oval:def:941</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.0 PATCH2"/><vers num="2.1 PATCH2"/><vers num="2.3 STABLE5"/><vers num="2.4 STABLE7"/><vers num="2.4"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0190" published="2004-03-15" seq="2004-0190" severity="High" type="CVE"><desc><descript source="cve">Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator&apos;s local system or in a proxy, which allows attackers to steal the password and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2004-February/017414.html">Symantec, Firewall/VPN Appliance, model 200 leak of security</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9784">bid 9784</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15212">Symantec Firewall/VPN caches administrative password in plain text</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2"> Symantec FireWall/VPN Appliance model 200 leak of security</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref><ref source="OSVDB" url="http://www.osvdb.org/4117">4117</ref></refs><vuln_soft><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="100"/><vers num="200"/><vers num="200R"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2004-0191" published="2004-03-15" seq="2004-0191" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Grou" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2">Sandblad #13: Cross-domain exploit on zombie document with event</ref><ref adv="1" source="Mozilla.org" url="http://bugzilla.mozilla.org/show_bug.cgi?id=227417">Cross-domain exploit on zombie document with event handlers</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9747">bid 9747</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15322">Mozilla event handler cross-site scripting</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-110.html">RHSA-2004:110</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-112.html">RHSA-2004:112</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2">SSRT4722</ref><ref source="OSVDB" url="http://www.osvdb.org/4062">4062</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874">oval:org.mitre.oval:def:874</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937">oval:org.mitre.oval:def:937</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="0.8"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.35"/><vers num="0.9.48"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0192" published="2004-03-15" seq="2004-0192" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2">Symantec Gateway Security Management Service Cross Site Scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9755">bid 9755</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15330">Symantec Gateway Security error page cross-site scripting</ref></refs><vuln_soft><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0193" published="2004-03-15" seq="2004-0193" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Eeye.com" url="http://www.eeye.com/html/Research/Upcoming/20040213.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/alerts/id/165">Vulnerability in SMB Parsing in ISS Products</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/150326">Internet Security Systems&apos; BlackICE and RealSecure contain a heap overflow in the processing of SMB packets</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040226.html">AD20040226</ref><ref source="BID" url="http://www.securityfocus.com/bid/9752">9752</ref><ref source="OSVDB" url="http://www.osvdb.org/4072">4072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10988">10988</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15207">pam-smb-protocol-bo(15207)</ref></refs><vuln_soft><prod name="Proventia" vendor="Internet Security Systems"><vers num="A Series XPU 20.15"/><vers num="G Series XPU 22.3"/><vers num="M Series XPU 1.3"/></prod><prod name="RealSecure Guard" vendor="Internet Security Systems"><vers num="3.6ecb"/></prod><prod name="RealSecure Server Sensor" vendor="Internet Security Systems"><vers num="7.0 XPU20.16"/></prod><prod name="RealSecure Desktop" vendor="Internet Security Systems"><vers num="3.6eca"/><vers num="7.0ebg"/><vers num="7.0epk"/><vers num="3.6ecf"/></prod><prod name="BlackICE Server Protection" vendor="Internet Security Systems"><vers num="3.6cbz"/></prod><prod name="RealSecure Sentry" vendor="Internet Security Systems"><vers num="3.6ecf"/></prod><prod name="RealSecure Network" vendor="Internet Security Systems"><vers num="7.0 XPU20.15"/></prod><prod name="BlackICE PC Protection" vendor="Internet Security Systems"><vers num="3.6cbd"/></prod><prod name="BlackICE Agent Server" vendor="Internet Security Systems"><vers num="3.6eca"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0194" published="2004-03-29" seq="2004-0194" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15384">Adobe Acrobat Reader XFDF buffer overflow</ref><ref adv="1" patch="1" source="NextGenss.com" url="http://www.nextgenss.com/advisories/adobexfdf.txt">Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9802">bid 9802</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/4135">4135</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0197" published="2004-06-01" seq="2004-0197" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-014.mspx">MS04-014</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-014.asp">MS04-014</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval968.html">OVAL968</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/740716">VU#740716</ref><ref source="BID" url="http://www.securityfocus.com/bid/10112">10112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15703">msjet-query-execute-code(15703)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968">oval:org.mitre.oval:def:968</ref></refs><vuln_soft><prod name="Jet" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0199" published="2004-06-14" seq="2004-0199" severity="Medium" type="CVE"><desc><descript source="cve">Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10321">bugtraq id 10321</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16095">win-hcp-code-execution(16095)</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/484814">VU#484814</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx">MS04-015</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437759930820&amp;w=2">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref><ref source="MISC" url="http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt">http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1008.html">OVAL1008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1032.html">OVAL1032</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108430407801825&amp;w=2">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008">oval:org.mitre.oval:def:1008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032">oval:org.mitre.oval:def:1032</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2004-0200" published="2004-09-28" seq="2004-0200" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IBM" url="http://www.microsoft.com/technet/security/bulletin/ms04-028.asp">Microsoft Security Bulletin MS04-028</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16304">Microsoft Windows JPEG buffer overflow</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-260A.html">TA04-260A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/297462">VU#297462</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1105.html">OVAL1105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1721.html">OVAL1721</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2706.html">OVAL2706</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3038.html">OVAL3038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3082.html">OVAL3082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3320.html">OVAL3320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3810.html">OVAL3810</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3881.html">OVAL3881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4003.html">OVAL4003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4216.html">OVAL4216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4307.html">OVAL4307</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524346729948&amp;w=2">20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105">oval:org.mitre.oval:def:1105</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721">oval:org.mitre.oval:def:1721</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706">oval:org.mitre.oval:def:2706</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038">oval:org.mitre.oval:def:3038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082">oval:org.mitre.oval:def:3082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320">oval:org.mitre.oval:def:3320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810">oval:org.mitre.oval:def:3810</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881">oval:org.mitre.oval:def:3881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003">oval:org.mitre.oval:def:4003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216">oval:org.mitre.oval:def:4216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307">oval:org.mitre.oval:def:4307</ref></refs><vuln_soft><prod name="OneNote" vendor="Microsoft"><vers num="2003"/></prod><prod name="Visual J#" vendor="Microsoft"><vers edition=".NET Standard" num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers edition="Student_Teacher" num="2003"/><vers num="XP SP3"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Producer" vendor="Microsoft"><vers edition="Office_PowerPoints" num="gold"/></prod><prod name="Picture It" vendor="Microsoft"><vers num="2002"/><vers num="7.0"/><vers num="9"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Gold" num="2002"/><vers edition="Gold" num="2003"/></prod><prod name="Word" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Project" vendor="Microsoft"><vers num="2002 SP1"/><vers num="2003"/></prod><prod name="InfoPath" vendor="Microsoft"><vers num="2003"/></prod><prod name="Digital Image Suite" vendor="Microsoft"><vers num="9"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Visual C#" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name=".NET Framework" vendor="Microsoft"><vers edition="SDK" num="1.0 SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="Tablet PC" num="SP1"/><vers edition="SP1" num="64-bit"/><vers num="64-bit Version 2003"/></prod><prod name="Visual C++" vendor="Microsoft"><vers edition=".NET Standard" num="2002"/><vers edition=".NET Standard" num="2003"/></prod><prod name="Digital Image Pro" vendor="Microsoft"><vers num="7.0"/><vers num="9"/></prod><prod name="Visio" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2003"/></prod><prod name="PowerPoint" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod><prod name="Greetings" vendor="Microsoft"><vers num="2002"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0201" published="2004-08-06" seq="2004-0201" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16586">Microsoft Windows HTML Help could allow execution of code</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/920060">Microsoft Windows HTML Help component fails to properly validate input data</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx">Vulnerability in HTML Help Could Allow Code Execution (840315)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10705">Microsoft Windows HTML Help Heap Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html">20040714 HtmlHelp - .CHM File Heap Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1503.html">OVAL1503</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1530.html">OVAL1530</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2155.html">OVAL2155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3179.html">OVAL3179</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503">oval:org.mitre.oval:def:1503</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530">oval:org.mitre.oval:def:1530</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155">oval:org.mitre.oval:def:2155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179">oval:org.mitre.oval:def:3179</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0202" published="2004-08-06" seq="2004-0202" severity="Medium" type="CVE"><desc><descript source="cve">IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-016.mspx">Microsoft Security Bulletin MS04-016</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10487">Microsoft DirectX DirectPlay Remote Malformed Packet Denial Of Service Vulnerability</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-016.asp">MS04-016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1027.html">OVAL1027</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2190.html">OVAL2190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2413.html">OVAL2413</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2516.html">OVAL2516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2705.html">OVAL2705</ref><ref source="OSVDB" url="http://www.osvdb.org/6742">6742</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11802">11802</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16306">ms-directx-directplay-dos(16306)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027">oval:org.mitre.oval:def:1027</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190">oval:org.mitre.oval:def:2190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413">oval:org.mitre.oval:def:2413</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516">oval:org.mitre.oval:def:2516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705">oval:org.mitre.oval:def:2705</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="DirectX" vendor="Microsoft"><vers num="7.0a"/><vers num="7.0"/><vers num="7.1"/><vers num="8.0a"/><vers num="8.0"/><vers num="8.1b"/><vers num="8.1a"/><vers num="8.1"/><vers num="8.2"/><vers num="9.0b"/><vers num="9.0a"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0203" published="2004-11-23" seq="2004-0203" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx">Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842436)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/948750">VU#948750</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2016.html">OVAL2016</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16583">exchange-owa-execute-code(16583)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016">oval:org.mitre.oval:def:2016</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5 SP4"/><vers num="5.5 SP3"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0204" published="2004-08-06" seq="2004-0204" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via &quot;..&quot; sequences in the dynamicimag argument to crystalimagehandler.aspx.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10260">Business Objects Crystal Reports Web Form Viewer Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16044">Crystal Reports file deletion</ref><ref source="CONFIRM" url="http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp">http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-017.asp">MS04-017</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1157.html">OVAL1157</ref><ref source="OSVDB" url="http://www.osvdb.org/6748">6748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11800">11800</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2">20040502 Crystal Reports Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157">oval:org.mitre.oval:def:1157</ref></refs><vuln_soft><prod name="Crystal Enterprise" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="Crystal Enterprise RAS for UNIX" vendor="businessobjects"><vers num="8.5"/></prod><prod name="Crystal Reports" vendor="businessobjects"><vers num="9.0"/><vers num="10.0"/></prod><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Gold" num="2003"/></prod><prod name="Outlook" vendor="Microsoft"><vers edition="Business Contact Manager" num="2003"/></prod><prod name="Business Solutions CRM" vendor="Microsoft"><vers num="1.2"/></prod><prod name="Crystal Enterprise Java SDK" vendor="businessobjects"><vers num="8.5"/></prod><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="J Builder" vendor="Borland Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0205" published="2004-08-06" seq="2004-0205" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10706/">Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/717748">Microsoft Internet Information Server (IIS) 4.0 contains a buffer overflow in the redirect function</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16578">Microsoft Internet Information Server (IIS) redirect buffer overflow</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-021.asp">MS04-021</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-179.shtml">O-179</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2204.html">OVAL2204</ref><ref source="BID" url="http://www.securityfocus.com/bid/10706">10706</ref><ref source="OSVDB" url="http://www.osvdb.org/7799">7799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12061">12061</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204">oval:org.mitre.oval:def:2204</ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0206" published="2004-11-03" seq="2004-0206" severity="High" type="CVE"><desc><descript source="cve">Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an &quot;unchecked buffer,&quot; possibly a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-031.asp">Vulnerability in NetDDE Could Allow Remote Code Execution (841533</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/640488">Microsoft Windows contains an unchecked buffer in the NetDDE services</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16556">Microsoft Windows NetDDE buffer overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17657">Microsoft Internet Information Server MS04-031 patch is not installed</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1852.html">OVAL1852</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2394.html">OVAL2394</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3120.html">OVAL3120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3242.html">OVAL3242</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4592.html">OVAL4592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5074.html">OVAL5074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6788.html">OVAL6788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12803/">12803</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786703930674&amp;w=2">20041013 Microsoft Windows NetDDE Service Buffer Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852">oval:org.mitre.oval:def:1852</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394">oval:org.mitre.oval:def:2394</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120">oval:org.mitre.oval:def:3120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242">oval:org.mitre.oval:def:3242</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592">oval:org.mitre.oval:def:4592</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074">oval:org.mitre.oval:def:5074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788">oval:org.mitre.oval:def:6788</ref><ref source="BID" url="http://www.securityfocus.com/bid/11372">11372</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0207" published="2004-11-03" seq="2004-0207" severity="Low" type="CVE"><desc><descript source="cve">&quot;Shatter&quot; style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16579">Microsoft Windows Window Management API allows elevated privileges</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/218526">Microsoft Windows contains vulnerability in Window Management API</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109777417922695&amp;w=2">20041013 SetWindowLong Shatter Attacks</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0208" published="2004-11-03" seq="2004-0208" severity="High" type="CVE"><desc><descript source="cve">The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16580">Microsoft Windows Virtual DOS Machine (VDM) allows elevated privileges</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/910998">Microsoft Windows kernel fails to properly handle invalid opcodes used in DOS emulation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1751.html">OVAL1751</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3161.html">OVAL3161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3953.html">OVAL3953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4316.html">OVAL4316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4762.html">OVAL4762</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109772135404427&amp;w=2">20041013 EEYE: Windows VDM #UD Local Privilege Escalation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751">oval:org.mitre.oval:def:1751</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161">oval:org.mitre.oval:def:3161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953">oval:org.mitre.oval:def:3953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316">oval:org.mitre.oval:def:4316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762">oval:org.mitre.oval:def:4762</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0209" published="2004-11-03" seq="2004-0209" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve &quot;an unchecked buffer.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829067325779&amp;w=2">[EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16581">Microsoft Windows Enhanced Metafile (EMF) buffer overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1872.html">OVAL1872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2114.html">OVAL2114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2428.html">OVAL2428</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/806278">VU#806278</ref><ref source="BID" url="http://www.securityfocus.com/bid/11375">11375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17658">win-ms04032-patch(17658)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872">oval:org.mitre.oval:def:1872</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114">oval:org.mitre.oval:def:2114</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428">oval:org.mitre.oval:def:2428</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0210" published="2004-08-06" seq="2004-0210" severity="High" type="CVE"><desc><descript source="cve">The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10710/">Microsoft Windows POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/647436">Microsoft Windows contains a buffer overflow in the POSIX subsystem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16590">Microsoft Windows POSIX buffer overflow allows local attacker to gain privileges</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-020.mspx">Vulnerability in POSIX Could Allow Code Execution (841872)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-020.asp">MS04-020</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2166.html">OVAL2166</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2847.html">OVAL2847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166">oval:org.mitre.oval:def:2166</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847">oval:org.mitre.oval:def:2847</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6 alpha"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Workstation 4.0 SP6a"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0211" published="2004-11-03" seq="2004-0211" severity="Low" type="CVE"><desc><descript source="cve">The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp">Security Update for Microsoft Windows (840987)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16582">Microsoft Windows Server 2003 kernel CPU denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17658">Microsoft Windows MS04-032 patch is not installed</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/119262">Microsoft Windows kernel fails to reset values in CPU data structures</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4893.html">OVAL4893</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893">oval:org.mitre.oval:def:4893</ref></refs><vuln_soft><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0212" published="2004-08-06" seq="2004-0212" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10708">Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16591">Microsoft Windows Task Scheduler buffer overflow</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-022.mspx">Vulnerability in Task Scheduler Could Allow Code Execution (841873)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/mstaskjob.txt">http://www.ngssoftware.com/advisories/mstaskjob.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981403025596&amp;w=2">20040714 Unchecked buffer in mstask.dll</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-022.asp">MS04-022</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/228028">VU#228028</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1344.html">OVAL1344</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1781.html">OVAL1781</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1964.html">OVAL1964</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3428.html">OVAL3428</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12060">12060</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981273009250&amp;w=2">20040714 Microsoft Windows Task Scheduler &apos;.job&apos; Stack Overflow</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344">oval:org.mitre.oval:def:1344</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781">oval:org.mitre.oval:def:1781</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964">oval:org.mitre.oval:def:1964</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428">oval:org.mitre.oval:def:3428</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Server 4.0 SP6a"/><vers num="Workstation 4.0 SP6a"/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2004-0213" published="2004-08-06" seq="2004-0213" severity="High" type="CVE"><desc><descript source="cve">Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a &quot;Shatter&quot; style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16592">Microsoft Windows Utility Manager gain privileges</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108975382413405&amp;w=2">Microsoft Window Utility Manager Local Elevation of Privileges</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-019.asp">Vulnerability in Utility Manager Could Allow Code Execution (842526)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10707/">Microsoft Windows Utility Manager Local Privilege Escalation Variant Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/868580">VU#868580</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2495.html">OVAL2495</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495">oval:org.mitre.oval:def:2495</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0214" published="2004-11-03" seq="2004-0214" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="seclists.org" url="http://seclists.org/lists/bugtraq/2004/Apr/0322.html">Bugtraq: Microsoft&apos;s Explorer and Internet Explorer long share name buffer overflow.</ref><ref adv="1" source="seclists.org" url="http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html">FullDisclosure: Microsoft&apos;s Explorer and Internet Explorer long share name buffer overflow.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15956">Microsoft Windows long file share name buffer overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17662">Microsoft Windows MS04-037 patch is not installed</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;en-us;322857">322857</ref><ref source="BID" url="http://www.securityfocus.com/bid/10213">10213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1601.html">OVAL1601</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1749.html">OVAL1749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2638.html">OVAL2638</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4345.html">OVAL4345</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5307.html">OVAL5307</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11482/">11482</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx">MS04-037</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/616200">VU#616200</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1011647">1011647</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html">http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html</ref><ref source="OSVDB" url="http://www.osvdb.org/5687">5687</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601">oval:org.mitre.oval:def:1601</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749">oval:org.mitre.oval:def:1749</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638">oval:org.mitre.oval:def:2638</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345">oval:org.mitre.oval:def:4345</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307">oval:org.mitre.oval:def:5307</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2900"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0215" published="2004-08-06" seq="2004-0215" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10711">Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16585">Microsoft Outlook Express malformed email header denial of service</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-018.mspx">Cumulative Security Update for Outlook Express (823353)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html">Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/869640">Microsoft Outlook Express fails to properly validate malformed e-mail headers</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms04-018.asp">MS04-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1950.html">OVAL1950</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2137.html">OVAL2137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2657.html">OVAL2657</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3376.html">OVAL3376</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950">oval:org.mitre.oval:def:1950</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137">oval:org.mitre.oval:def:2137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657">oval:org.mitre.oval:def:2657</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376">oval:org.mitre.oval:def:3376</ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="S3400"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0216" published="2004-11-03" seq="2004-0216" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="marc.theaimsgroup.com" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760693512754&amp;w=2">Microsoft Internet Explorer Install Engine Control Buffer Overflow</ref><ref adv="1" patch="1" source="microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp">Cumulative Security Update for Internet Explorer (834707)</ref><ref adv="1" patch="1" source="www.us-cert.gov" url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html">Multiple Vulnerabilities in Microsoft Internet Explorer</ref><ref adv="1" patch="1" source="www.kb.cert.org" url="http://www.kb.cert.org/vuls/id/637760">www.kb.cert.org</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/17620">Microsoft Internet Explorer InstallEngineCtl SetCifFile buffer overflow</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/msinsengfull.txt">http://www.ngssoftware.com/advisories/msinsengfull.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5316.html">OVAL5316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval5329.html">OVAL5329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6100.html">OVAL6100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval6600.html">OVAL6600</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7717.html">OVAL7717</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval7865.html">OVAL7865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17651">ie-ms04038-patch(17651)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616383332055&amp;w=2">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110619893620517&amp;w=2">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316">oval:org.mitre.oval:def:5316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329">oval:org.mitre.oval:def:5329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100">oval:org.mitre.oval:def:6100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600">oval:org.mitre.oval:def:6600</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717">oval:org.mitre.oval:def:7717</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865">oval:org.mitre.oval:def:7865</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2004-0217" published="2004-04-15" seq="2004-0217" severity="Low" type="CVE"><desc><descript source="cve">The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694800908164&amp;w=2">Possible race condition in Symantec AntiVirus Scan Engine for Red</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15215">Symantec Antivirus Scan Engine race condition</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9662">bid 9662</ref></refs><vuln_soft><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers edition="Red Hat Linux" num="4.0"/><vers edition="Red Hat Linux" num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0218" published="2004-05-04" seq="2004-0218" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15518">OpenBSD ISAKMP zero-length payload denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349113">VU#349113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11156">11156</ref><ref source="BID" url="http://www.securityfocus.com/bid/10028">10028</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0219" published="2004-05-04" seq="2004-0219" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15518">OpenBSD ISAKMP zero-length payload denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15628">OpenBSD ISAKMP IPSEC SA payload denial of service</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html">20040317 015: RELIABILITY FIX: March 17, 2004</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/785945">VU#785945</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2004-0220" published="2004-05-04" seq="2004-0220" severity="High" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via a an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15629">OpenBSD ISAKMP Cert Request payload integer underflow</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/223273">VU#223273</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0221" published="2004-05-04" seq="2004-0221" severity="Medium" type="CVE"><desc><descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref adv="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15630">OpenBSD ISAKMP delete payload denial of service</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/524497">VU#524497</ref><ref source="BID" url="http://www.securityfocus.com/bid/9907">9907</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0222" published="2004-05-04" seq="2004-0222" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="the aims group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2">R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OpenBSD 3.5 release errata</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15519">OpenBSD ISAKMP memory leak</ref><ref source="MISC" url="http://www.rapid7.com/advisories/R7-0018.html">http://www.rapid7.com/advisories/R7-0018.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/996177">VU#996177</ref><ref source="BID" url="http://www.securityfocus.com/bid/10032">10028</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html">1009468</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0224" published="2004-04-15" seq="2004-0224" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code &quot;when Unicode character is out of BMP range.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SourceForge" url="http://sourceforge.net/project/shownotes.php?release_id=5767">Courier Mail Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9845">bid 9845</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/11087/">Courier Japanese Codeset Conversion Buffer Overflow Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15434">courier-codeset-converter-bo(15434)</ref></refs><vuln_soft><prod name="SqWebMail" vendor="Double Precision Incorporated"><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.6 .0"/><vers num="3.6.1"/><vers num="3.6.2"/></prod><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Courier-IMAP" vendor="Inter7"><vers num="1.6"/><vers num="1.7"/><vers num="2.0.0"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2.0"/><vers num="2.2.1"/></prod><prod name="Courier MTA" vendor="Double Precision Incorporated"><vers num="0.43"/><vers num="0.43.1"/><vers num="0.43.2"/><vers num="0.44"/><vers num="0.44.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0226" published="2004-08-18" seq="2004-0226" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">Updated mc packages resolve several vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16016">Midnight Commander allows local elevation of privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-497">DSA-497</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-21.xml">GLSA-200405-21</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0227" published="2004-06-14" seq="2004-0227" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ZoneMinder" url="http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16136">zoneminder-zms-bo(16136)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10340">bugtraq 10340</ref></refs><vuln_soft><prod name="ZoneMinder" vendor="Triornis"><vers num="1.17.0"/><vers num="1.17.1"/><vers num="1.17.2"/><vers num="1.18.0"/><vers num="1.18.1"/><vers num="1.19.0"/><vers num="1.19.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0228" published="2004-08-18" seq="2004-0228" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/archives/fedora-announce-list/2004-April/msg00010.html">[SECURITY] Updated kernel packages fix security issues.</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:050">MDKSA-2004:050</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11429">11429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11486">11486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11491">11491</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11683">11683</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15951">linux-cpufreq-info-disclosure(15951)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-111.shtml">FEDORA-2004-111</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:050">MDKSA-2004:050</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0229" published="2004-08-18" seq="2004-0229" severity="Medium" type="CVE"><desc><descript source="cve">The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10211">Linux kernel Framebuffer Code Unspecified Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15974">Linux kernel framebuffer undisclosed issue</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200407-02.xml">Linux Kernel: Multiple vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html">SuSE-SA:2004:010</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852">CLA-2004:852</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037">MDKSA-2004:037</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0230" published="2004-08-18" seq="2004-0230" severity="Medium" type="CVE"><desc><descript source="cve">TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/10183">Multiple Vendor TCP Sequence Number Approximation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15886">TCP spoofed reset denial of service</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-111A.html">Vulnerabilities in TCP</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc">20040403-01-A</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml">20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco Products</ref><ref source="CONFIRM" url="http://www.juniper.net/support/alert.html">http://www.juniper.net/support/alert.html</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc">NetBSD-SA2004-006</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt">SCOSA-2005.3</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt">SCOSA-2005.9</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt">SCOSA-2005.14</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/415294">VU#415294</ref><ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/236929/index.htm">http://www.uniras.gov.uk/vuls/2004/236929/index.htm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108302060014745&amp;w=2">20040425 Perl code exploting TCP not checking RST ACK.</ref><ref source="OSVDB" url="http://www.osvdb.org/4030">4030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11440">11440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/11458">11458</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4791.html">OVAL4791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2689.html">OVAL2689</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3508.html">OVAL3508</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108506952116653&amp;w=2">SSRT4696</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx">MS06-064</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3983">ADV-2006-3983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22341">22341</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded">HPSBST02161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791">oval:org.mitre.oval:def:4791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689">oval:org.mitre.oval:def:2689</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508">oval:org.mitre.oval:def:3508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270">oval:org.mitre.oval:def:270</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0231" published="2004-08-18" seq="2004-0231" severity="Low" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to &quot;Insecure temporary file and directory creations.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200405-21.xml"> Gentoo Linux Security Advisory</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16020">Midnight Commander creates insecure files</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2004/dsa-497">DSA-497-1 mc -- several vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">RHSA-2004:172</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0232" published="2004-08-18" seq="2004-0232" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10242">Midnight Commander Multiple Unspecified Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16021">Midnight Commander format string</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:039">Updated mc packages fix vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-497">DSA-497</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_12_mc.html">SuSE-SA:2004:012</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-172.html">RHSA-2004:172</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-21.xml">GLSA-200405-21</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039">MDKSA-2004:039</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.40"/><vers num="4.5.41"/><vers num="4.5.42"/><vers num="4.5.43"/><vers num="4.5.44"/><vers num="4.5.45"/><vers num="4.5.46"/><vers num="4.5.47"/><vers num="4.5.48"/><vers num="4.5.49"/><vers num="4.5.50"/><vers num="4.5.51"/><vers num="4.5.52"/><vers num="4.5.55"/><vers num="4.6"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.3"/><vers num="2.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2004-0233" published="2004-08-18" seq="2004-0233" severity="Low" type="CVE"><desc><descript source="cve">Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10178">UTempter Multiple Local Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15904">Utempter symlink attack</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2004-174.html">Updated utempter package fixes vulnerability</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:031">MDKSA-2004:031</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-175.html">RHSA-2004:175</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-05.xml">GLSA-200405-05</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval979.html">OVAL979</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404389">SSA:2004-110</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979">oval:org.mitre.oval:def:979</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:031">MDKSA-2004:031</ref></refs><vuln_soft><prod name="utempter" vendor="utempter"><vers num="0.5.2"/><vers num="0.5.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2004-0234" published="2004-08-18" seq="2004-0234" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10243">Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16012">LHA multiple buffer overflows</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2">[Ulf Harnhammar]: LHA Advisory + Patch</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html">20040501 LHa buffer overflows and directory traversal problems</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html">20040502 Lha local stack overflow Proof Of Concept Code</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-515">DSA-515</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-178.html">RHSA-2004:178</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-179.html">RHSA-2004:179</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-02.xml">GLSA-200405-02</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html">FEDORA-2004-119</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval977.html">OVAL977</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840">CLA-2004:840</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html">20060403 Barracuda LHA archiver security bug leads to remote compromise</ref><ref source="" url="http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1220">ADV-2006-1220</ref><ref source="OSVDB" url="http://www.osvdb.org/5753">5753</ref><ref source="OSVDB" url="http://www.osvdb.org/5754">5754</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015866">1015866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19514">19514</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977">oval:org.mitre.oval:def:977</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.20"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2003"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers num="2003"/><vers num="2004"/><vers edition="Client Security" num="5.5"/><vers edition="Client Security" num="5.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Workstations" num="4.51"/><vers edition="Linux Workstations" num="4.52"/><vers edition="MIMESweeper" num="5.41"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MS Exchange" num="6.21"/><vers edition="Samba Servers" num="4.60"/><vers edition="Windows Servers" num="5.41"/><vers edition="Windows Servers" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Workstations" num="5.42"/></prod><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14"/><vers num="1.15"/><vers num="1.17"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod><prod name="Iha" vendor="Red Hat"><vers edition="i386" num="1.14i_9"/></prod><prod name="F-Secure for Firewalls" vendor="F-Secure"><vers num="6.20"/></prod><prod name="WinZip" vendor="WinZip"><vers num="9.0"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6 SP1"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/></prod><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.31"/><vers num="6.32"/></prod><prod name="CGPMcAfee" vendor="Stalker"><vers num="3.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2004-0235" published="2004-08-18" seq="2004-0235" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes (&quot;//absolute/path&quot;).</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/10243">Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/16013">LHA directory traversal</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2">[Ulf Harnhammar]: LHA Advisory + Patch</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html">20040501 LHa buffer overflows and directory traversal problems</ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-515">DSA-515</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=1833">FLSA:1833</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-178.html">RHSA-2004:178</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-179.html">RHSA-2004:179</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-02.xml">GLSA-200405-02</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html">FEDORA-2004-119</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval978.html">OVAL978</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840">CLA-2004:840</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978">oval:org.mitre.oval:def:978</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.20"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2003"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers num="2003"/><vers num="2004"/><vers edition="Client Security" num="5.5"/><vers edition="Client Security" num="5.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Workstations" num="4.51"/><vers edition="Linux Workstations" num="4.52"/><vers edition="MIMESweeper" num="5.41"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MS Exchange" num="6.21"/><vers edition="Samba Servers" num="4.60"/><vers edition="Windows Servers" num="5.41"/><vers edition="Windows Servers" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Workstations" num="5.42"/></prod><prod name="LHA" vendor="Tsugio Okamoto"><vers num="1.14"/><vers num="1.15"/><vers num="1.17"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod><prod name="Iha" vendor="Red Hat"><vers edition="i386" num="1.14i_9"/></prod><prod name="F-Secure for Firewalls" vendor="F-Secure"><vers num="6.20"/></prod><prod name="WinZip" vendor="WinZip"><vers num="9.0"/></prod><prod name="MailSweeper" vendor="Clearswift"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6 SP1"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.13"/></prod><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.31"/><vers num="6.32"/></prod><prod name="CGPMcAfee" vendor="Stalker"><vers num="3.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="2.4"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0236" published="2004-11-23" seq="2004-0236" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9884">SteelID thePhotoTool Login.ASP SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15007">thePHOTOtool login.asp script SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107576894019530&amp;w=2">thePHOTOtool SQL Injection Vulnerability</ref></refs><vuln_soft><prod name="thePhotoTool" vendor="SteelID"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0237" published="2004-11-23" seq="2004-0237" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9540">Aprox Portal File Disclosure Vulnerability</ref><ref adv="1" source="CERT" url="http://xforce.iss.net/xforce/xfdb/15014">Aprox Portal File Disclosure Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577555527321&amp;w=2"> Directory Traversal in Aprox PHP Portal.</ref><ref source="OSVDB" url="http://www.osvdb.org/10859">10859</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008915">1008915</ref></refs><vuln_soft><prod name="Aprox Portal" vendor="Aprox Portal"><vers num="3.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2004-0238" published="2004-11-23" seq="2004-0238" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9550">0verkill Game Client Multiple Local Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/14999">Overkill client has multiple buffer overflows</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577335424509&amp;w=2">0verkill - little simple vulnerability.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html">20040202 0verkill - little simple vulnerability.</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5AP010KC0C.html">http://www.securiteam.com/securitynews/5AP010KC0C.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15000">overkill-server-parsecommandline-bo(15000)</ref></refs><vuln_soft><prod name="0verkill" vendor="0verkill"><vers num="0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0239" published="2004-11-23" seq="2004-0239" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9557">All Enthusiast Photopost PHP Pro SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15008">PhotoPost PHP Pro SQL injection</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5KP010UC0W.html">http://www.securiteam.com/securitynews/5KP010UC0W.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582512023998&amp;w=2">20040202 ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0240" published="2004-11-23" seq="2004-0240" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15033">X-Cart &quot;dot dot&quot; directory traversal</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2"> X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0241" published="2004-11-23" seq="2004-0241" severity="High" type="CVE"><desc><descript source="cve">X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9560">Qualiteam X-Cart Remote Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15034">X-Cart perl_binary variable command execution</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2"> X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0242" published="2004-11-23" seq="2004-0242" severity="Medium" type="CVE"><desc><descript source="cve">X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.securityfocus.com/bid/9563">Qualiteam X-Cart Multiple Remote Information Disclosure Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15036">X-Cart general.php information disclosure</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2">X-Cart vulnerability</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.3.0"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.3"/><vers num="3.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0243" published="2004-11-23" seq="2004-0243" severity="Medium" type="CVE"><desc><descript source="cve">AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107583269206044&amp;w=2"> Re: sqwebmail web login</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html">20040206 AIX password enumeration possible</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15172">aix-password-enumeration(15172)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-20" name="CVE-2004-0244" published="2004-11-23" seq="2004-0244" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9562">Cisco IOS MSFC2 Malformed Layer 2 Frame Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15013">Cisco 6000, 6500, and 7600 series systems frame containing a packet denial of service</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml">Cisco Security Advisory: Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/810062">VU#810062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10780">10780</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1 E"/><vers num="12.2 ZA"/><vers num="12.2 SY"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0245" published="2004-11-23" seq="2004-0245" severity="Medium" type="CVE"><desc><descript source="cve">Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9576/">Web Crossing Web Server Component Remote Denial Of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586518120516&amp;w=2">Web Crossing 4.x/5.x Denial of Service Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/9576">9576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15022">webcrossing-contentlength-post-dos(15022)</ref></refs><vuln_soft><prod name="Web Crossing" vendor="Web Crossing Inc"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0246" published="2004-11-23" seq="2004-0246" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9536">Laurent Adda Les Commentaires PHP Script Multiple Module File Include Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15010">Les Commentaires multiple PHP file include</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584083719763&amp;w=2"> Les Commentaires (PHP) Include file</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10768/">10768</ref></refs><vuln_soft><prod name="Les Commentaires" vendor="Laurent Adda"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0247" published="2004-11-23" seq="2004-0247" severity="Medium" type="CVE"><desc><descript source="cve">The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9567">Cauldron Chaser Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15031">Chaser memory denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584109420084&amp;w=2">Remote crash of Chaser game &lt;= 1.50</ref></refs><vuln_soft><prod name="Chaser Server" vendor="Cauldron"><vers num="1.4.9"/><vers num="1.5"/></prod><prod name="Chaser Client" vendor="Cauldron"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0248" published="2004-11-23" seq="2004-0248" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
PHPX, PHPX, 3.2.4</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9569">PHPX Multiple Vulnerabilities</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15050">PHPX subject HTML injection</ref><ref patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15051">PHPX main.inc.php and help.inc.php cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2">Multiple Vulnerabilities in PHPX</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/10797/">10797</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0249" published="2004-11-23" seq="2004-0249" severity="High" type="CVE"><desc><descript source="cve">PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie&apos;s PXL variable to reference another userID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9569">PHPX Multiple Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15052">PHPX could allow an attacker to modify cookie to hijack another user&apos;s account</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2">   Multiple Vulnerabilities in PHPX</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html">20040316 PHPX 2.x - 3.2.4</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10797/">10797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15512">phpx-session-hijack(15512)</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2004-0250" published="2004-11-23" seq="2004-0250" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9557">All Enthusiast Photopost PHP Pro SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15008">PhotoPost PHP Pro SQL injection</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107593114909696&amp;w=2">ZH2004-04SA (security advisory): Multiple Sql Injection</ref><ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=3864/">http://www.zone-h.org/en/advisories/read/id=3864/</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0251" published="2004-11-23" seq="2004-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9575">RXGoogle.CGI Cross Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15043">RxGoogle query cross-site scripting</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107594183924958&amp;w=2"> rxgoogle.cgi XSS Vulnerability.</ref></refs><vuln_soft><prod name="rxgoogle.cgi" vendor="rxgoogle.cgi"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0252" published="2004-11-23" seq="2004-0252" severity="Medium" type="CVE"><desc><descript source="cve">TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9573">TYPSoft FTP Server Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15048">TYPSoft FTP Server empty username denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107591511716707&amp;w=2"> TYPSoft FTP Server 1.10 may be crashed</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2004/Feb/1008943.html">1008943</ref></refs><vuln_soft><prod name="TYPSoft FTP Server" vendor="TYPSoft"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0253" published="2004-11-23" seq="2004-0253" severity="High" type="CVE"><desc><descript source="cve">IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9583">IBM Cloudscape Database Remote Command Execution Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15067">IBM Cloudscape SQL injection</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604065819233&amp;w=2">IBM cloudscape SQL Database (DB2J) vulnerable to remote command</ref></refs><vuln_soft><prod name="Cloudscape" vendor="IBM"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0254" published="2004-11-23" seq="2004-0254" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9584">Crossday Discuz! Cross Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15066">Discuz! Board image tag cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107606726417150&amp;w=2">Possible Cross Site Scripting in Discuz! Board</ref></refs><vuln_soft><prod name="Discuz" vendor="Crosscom Olicom"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0255" published="2004-11-23" seq="2004-0255" severity="Medium" type="CVE"><desc><descript source="cve">Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9585">XLight FTP Server Long Directory Request Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15064">Xlight ftp server long string denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107605633904122&amp;w=2">Remote crash Xlight ftp server 1.52</ref></refs><vuln_soft><prod name="XLight FTP Server" vendor="XLight FTP Server"><vers num="1.25"/><vers num="1.41"/><vers num="1.45"/><vers num="1.52"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0256" published="2004-11-23" seq="2004-0256" severity="Low" type="CVE"><desc><descript source="cve">GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9530">GNU LibTool Local Insecure Temporary Directory Creation Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15017">GNU Libtool creates insecure temporary directory</ref><ref source="" url="http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/352333">20040130 Symlink Vulnerability in GNU libtool &lt;1.5.2</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000811">CLA-2004:811</ref><ref source="OSVDB" url="http://www.osvdb.org/3795">3795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10777">10777</ref></refs><vuln_soft><prod name="libtool" vendor="GNU"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0257" published="2004-11-23" seq="2004-0257" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.guninski.com/obsdmtu.html">http://www.guninski.com/obsdmtu.html</ref><ref source="CONFIRM" url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9577">BSD ICMPV6 Handling Routines Remote Denial Of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15044">OpenBSD IPv6 packet denial of service</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604603226564&amp;w=2">OpenBSD IPv6 remote kernel crash</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016704.html">20040204 Remote openbsd crash with ip6, yet still openbsd much better than windows</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-002.txt.asc">NetBSD-SA2004-002</ref><ref source="OSVDB" url="http://www.osvdb.org/3825">3825</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.6"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2004-0258" published="2004-11-23" seq="2004-0258" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9579">Multiple RealPlayer/RealOne Player Supported File Type Buffer Overrun Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15040">RealOne Player multiple file buffer overflows</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2"> Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/473814">Multiple Real media players vulnerable to buffer overflow when parsing crafted media files</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html">20040204 [VulnWatch] Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2">20040204 Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref><ref source="MISC" url="http://www.nextgenss.com/advisories/realone.txt">http://www.nextgenss.com/advisories/realone.txt</ref><ref source="CONFIRM" url="http://www.service.real.com/help/faq/security/040123_player/EN/">http://www.service.real.com/help/faq/security/040123_player/EN/</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-075.shtml">O-075</ref></refs><vuln_soft><prod name="RealOne Desktop Manager" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/><vers num="6.0.11.868"/><vers num="6.0.11.853"/><vers num="6.0.11.841"/><vers num="6.0.11.830"/><vers num="6.0.11.818"/><vers edition="Win" num="2.0"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Win32" num="8.0"/><vers edition="Unix" num="8.0"/><vers edition="Mac OS" num="8.0"/><vers num="10.0 beta"/></prod><prod name="RealOne Enterprise Desktop" vendor="RealNetworks"><vers num="6.0.11.774"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0259" published="2004-11-23" seq="2004-0259" severity="High" type="CVE"><desc><descript source="cve">The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9591">Joe Lumbroso Jack&amp;#39;s Formmail.php Unauthorized Remote File Upload Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15079">Jack&apos;s FormMail.php PHP file upload</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619109629629&amp;w=2">formmail (PHP) Upload file using CSS</ref></refs><vuln_soft><prod name="FormMail.php" vendor="Joe Lumbroso acks"><vers num="2.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0260" published="2004-11-23" seq="2004-0260" severity="Medium" type="CVE"><desc><descript source="cve">The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9589">Cactusoft CactuShop Lite Remote Arbitrary File Deletion Backdoor Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15063">CactuShop Lite contains a backdoor</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619501815888&amp;w=2">  CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref></refs><vuln_soft><prod name="CactuShop Lite" vendor="CactuSoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2004-0261" published="2004-11-23" seq="2004-0261" severity="High" type="CVE"><desc><descript source="cve">oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.grohol.com/downloads/oj/latest/changelog.txt">http://www.grohol.com/downloads/oj/latest/changelog.txt</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9598">OpenJournal Authentication Bypassing Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15069">OpenJournal uid could allow an attacker administrative access</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619136600713&amp;w=2">Open Journal Blog Authenticaion Bypassing Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3872">3872</ref></refs><vuln_soft><prod name="OpenJournal" vendor="OpenJournal"><vers num="2.0 5"/><vers num="2.0 4"/><vers num="2.0 3"/><vers num="2.0 2"/><vers num="2.0 1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0262" published="2004-11-23" seq="2004-0262" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9602">The Palace Graphical Chat Client Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15074">Palace long server address buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634556632195&amp;w=2">The Palace 3.x (Client) Stack Overflow Vulnerability</ref><ref source="MISC" url="http://www.elitehaven.net/thepalace.txt">http://www.elitehaven.net/thepalace.txt</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref></refs><vuln_soft><prod name="The Palace Client" vendor="The Palace"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0263" published="2004-11-23" seq="2004-0263" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9599">Apache mod_php Global Variables Information Disclosure Weakness</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15072">PHP virtual host information disclosure</ref><ref adv="1" source="Gentoo" url="http://security.gentoo.org/glsa/glsa-200402-01.xml">PHP setting leaks from .htaccess files on virtual hosts</ref><ref source="GENTOO" url="http://http://security.gentoo.org/glsa/glsa-200402-01.xml">GLSA-200402-01</ref><ref source="OSVDB" url="http://www.osvdb.org/3878">3878</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2"/><vers num="1.2.5"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.6"/><vers edition="Dev" num="1.3.7"/><vers num="1.3.9"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.14"/><vers num="1.3.17"/><vers num="1.3.18"/><vers num="1.3.19"/><vers num="1.3.20"/><vers num="1.3.22"/><vers num="1.3.23"/><vers num="1.3.24"/><vers num="1.3.25"/><vers num="1.3.26"/><vers num="1.3.27"/><vers num="1.3.28"/><vers num="1.3.29"/><vers num="2.0.9a"/><vers num="2.0"/><vers num="2.0.28 Beta"/><vers num="2.0.28"/><vers num="2.0.32"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.40"/><vers num="2.0.41"/><vers num="2.0.42"/><vers num="2.0.43"/><vers num="2.0.44"/><vers num="2.0.45"/><vers num="2.0.46"/><vers num="2.0.47"/><vers num="2.0.48"/></prod><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2004-0264" published="2004-11-23" seq="2004-0264" severity="Medium" type="CVE"><desc><descript source="cve">palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9608">Shaun2k2 Palmhttpd Server Remote Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15090">palmhttpd accept function buffer overflow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634638201570&amp;w=2">PalmOS httpd accept() queue overflow DoS vulnerability.</ref></refs><vuln_soft><prod name="palmhttpd" vendor="shaun2k2"><vers num="3.0"/></prod><prod name="Jim Rees httpd" vendor="Jim Rees"><vers num="PalmOS"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-02" name="CVE-2004-0265" published="2004-11-23" seq="2004-0265" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/9605">PHP-Nuke &apos;News&apos; Module Cross-Site Scripting Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/15076">PHP-Nuke News and Reviews modules cross-site scripting</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634727520936&amp;w=2">[waraxe-2004-SA#002] - Cross-Site Scripting (XSS) in Php-Nuke 7.1.0</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/9613">PHP-Nuke &apos;Reviews&apos; Module Cross-Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2004-0266" published="2004-11-23" seq="2004-0266" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the &quot;public message&quot; capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/9615">PHP-Nuke Public Message SQL Injection Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/